Skip to content

Trust center

Your research. Handled with care.

See the current safeguards for LeadRx, the limits of the private beta, and how to report a security concern.

Current security direction.

These are operating safeguards and design intentions for the private beta. They are not a substitute for a customer-specific security review.

Identity and sessions

LeadRx uses authenticated product access and is designed to keep browser sessions separate from privileged server credentials.

Workspace boundaries

Database access is designed around owner and workspace scope. Access-control changes are reviewed alongside the queries and product flows they affect.

Secret handling

Provider keys and privileged credentials belong in managed server environments, not browser bundles, screenshots, or product responses.

Controlled communication

Email features are designed with suppression checks, unsubscribe handling, sending limits, approval gates, and narrow provider scopes.

Evidence provenance

Important research output keeps source and confidence context so customers can inspect and correct the record.

Change verification

High-impact releases are expected to pass automated checks and browser review before production promotion.

Shared responsibility

Good habits matter, too.

Customers remain responsible for account access, lawful data use, recipient permissions, exported files, downstream systems, and reviewing evidence before acting.

Protect access

Use unique credentials, limit workspace membership, and remove access when responsibilities change.

Verify the record

Public business data can be incomplete or stale. Review evidence before outreach, export, or a consequential decision.

Respect communication rules

Use suppression controls, honor opt-outs, and follow applicable marketing, privacy, and provider requirements.

Report concerns safely

Do not access data beyond what is needed to demonstrate an issue. Share a concise reproduction path through the security contact route.

What we are not claiming.

LeadRx does not currently claim an independent security certification. Read the current limits and reporting guidance below.

No certification claim

LeadRx does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or another independent security certification on this site. A certification will only be displayed after the relevant audit or attestation is complete and its scope can be stated accurately.

How do I report a vulnerability?
Use the security topic on the contact page. Include the affected route or component, the observed behavior, the minimum steps needed to reproduce it, and a safe way to reach you. Do not include secrets or unrelated personal data.
Should I test production accounts or data?
No. Do not disrupt service, access another user's data, run denial-of-service testing, use social engineering, or retain data you encounter. Ask for a coordinated test path first.
Does LeadRx sell personal information?
The privacy draft describes the intended handling of information. LeadRx does not present itself as a data broker or promise a legal classification without a fact-specific review.
Where can I request a security review?
Use the contact page and choose Security. During private beta, reviews are handled individually and no public response-time commitment is advertised.

Ready when you are

Found something we should know?

Send a responsible report with enough context to reproduce the concern safely.