Leadkaun

Legal

Security

Leadkaun holds your leads, contacts and pipeline, so this page sets out how that data is protected — in plain language, including the certifications we do not hold.

Last updated 13 August 20268 clauses

01

Encryption in transit and at rest

All traffic to Leadkaun is served over HTTPS/TLS. Your data is stored on managed cloud infrastructure that encrypts data at rest by default.

02

Payments never touch our servers

Payments are processed by Razorpay, a PCI-DSS Level 1 certified provider. Leadkaun never sees or stores your card details — Razorpay handles them end to end.

03

Role-based access

Team and admin controls let you decide who sees and does what: Admin, Manager and Rep roles, per-workspace data separation, and a full audit export. Each account's data is kept separate.

04

Managed, resilient infrastructure

Leadkaun runs on managed cloud platforms — edge delivery via Cloudflare, managed databases for application data — which maintain their own physical and network security and durability.

05

Data you control

Your lead data is yours. You can export it at any time, and we will delete it on request when you close your account. We do not sell your data.

06

Privacy by design

We collect what the product needs to work and no more. The Privacy Policy and Terms of Service set out how data is handled, retained and processed.

07

What we do not claim

Leadkaun is not currently ISO 27001 certified and does not hold a SOC 2 Type I or Type II report. We would rather say that plainly than let a procurement team assume otherwise.

Where a specific control matters to your assessment, ask and we will describe exactly how it is implemented today. The Compliance page covers data residency, sub-processors and the Data Processing Agreement.

08

Responsible disclosure

If you believe you have found a security vulnerability in Leadkaun, tell us before you tell anyone else and we will work with you.

Email: team@leadkaun.com with "Security" in the subject line.

Please include the steps to reproduce, the impact as you understand it, and anything we need to see it ourselves. We acknowledge reports within 24 hours and will keep you updated until it is resolved. We will not pursue action against researchers who report in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosing it.