Trust Center

Security, privacy, compliance documented in one place.

We treat trust as an engineering concern, not a marketing surface. Below is what we run, what we promise, and where the documents live so a procurement review can finish in twenty minutes instead of two weeks.

Pillars

Four controls we will not negotiate.

Encryption everywhere

TLS 1.2+ in transit. Encrypted at rest, backups included. Field-level encryption on contact email and phone, sender credentials, and integration tokens. Every query is scoped to a single workspace so one customer cannot read another’s rows.

Access by default zero

MFA is required for owner and admin operations, after a short onboarding grace window. Production access is restricted to a small named set of engineers, and staff actions inside the product are written to the audit log. Customer support never reads workspace data without explicit consent.

Data in the European Union

Primary storage in Frankfurt (eu-central-1). Backups within the same region. International transfers happen only through Standard Contractual Clauses with supplementary measures.

Compliance as engine

Suppression, approved LIA records, opt-out, and audit history are built into the workspace. These controls support your legal process; they do not certify a campaign.

Compliance posture

Where we stand on every regime that matters.

GDPR · UK-GDPR

EU + UK data subject rights honoured, DSARs answered inside the one-month statutory window, SCCs in place for non-EU transfers.

Compliant

KVKK · Türkiye

Leafer has no verified production IYS contract. Türkiye outbound remains unavailable.

Outbound blocked

CCPA · CPRA · California

No sale / no share posture. Right to know, delete, correct, and limit sensitive PI honoured.

Compliant

CASL · Canada

Country router blocks sends to Canadian addresses by default unless prior consent is documented.

Compliant

SOC 2 Type I

A target window, not an achieved certification. No report has been issued, and we will say so plainly until one is.

Planned · Q3 2026

ISO 27001

Roadmapped after SOC 2. Will be pursued in parallel with the next funding milestone.

Planned · 2027

Operational

The day-to-day controls behind the policy.

Real-time status

A live check that the application can reach its database, re-run on every load. Planned maintenance and open service notices are posted there.

View status page

Audit log

Append-only trail of every suppression, opt-out, consent record and admin action. Rows are never rewritten. Queryable in-app for the last twelve months, longer extracts on request.

Breach notification

We commit to notifying the supervisory authority within 72 hours of becoming aware of a reportable personal-data breach, and affected customers without undue delay.

Backups + recovery

Encrypted at rest and in transit, with point-in-time recovery through our managed database provider. We have not yet run a documented restore drill, so we publish no RTO or RPO figure.

Procurement security review

Need a security questionnaire, an architecture review, or a signed DPA?

Email security@leafer.io with what you need. We reply within one business day with the documents, the answers, and a redline if you have one. No NDA required for the first call.

Trust Center — Leafer · Leafer