Identity and sessions
LeadRx uses authenticated product access and is designed to keep browser sessions separate from privileged server credentials.
Trust center
See the current safeguards for LeadRx, the limits of the private beta, and how to report a security concern.
These are operating safeguards and design intentions for the private beta. They are not a substitute for a customer-specific security review.
LeadRx uses authenticated product access and is designed to keep browser sessions separate from privileged server credentials.
Database access is designed around owner and workspace scope. Access-control changes are reviewed alongside the queries and product flows they affect.
Provider keys and privileged credentials belong in managed server environments, not browser bundles, screenshots, or product responses.
Email features are designed with suppression checks, unsubscribe handling, sending limits, approval gates, and narrow provider scopes.
Important research output keeps source and confidence context so customers can inspect and correct the record.
High-impact releases are expected to pass automated checks and browser review before production promotion.
Shared responsibility
Customers remain responsible for account access, lawful data use, recipient permissions, exported files, downstream systems, and reviewing evidence before acting.
Use unique credentials, limit workspace membership, and remove access when responsibilities change.
Public business data can be incomplete or stale. Review evidence before outreach, export, or a consequential decision.
Use suppression controls, honor opt-outs, and follow applicable marketing, privacy, and provider requirements.
Do not access data beyond what is needed to demonstrate an issue. Share a concise reproduction path through the security contact route.
LeadRx does not currently claim an independent security certification. Read the current limits and reporting guidance below.
LeadRx does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or another independent security certification on this site. A certification will only be displayed after the relevant audit or attestation is complete and its scope can be stated accurately.
Ready when you are
Send a responsible report with enough context to reproduce the concern safely.