Security, privacy, compliance documented in one place.
We treat trust as an engineering concern, not a marketing surface. Below is what we run, what we promise, and where the documents live so a procurement review can finish in twenty minutes instead of two weeks.
Pillars
Four controls we will not negotiate.
Encryption everywhere
TLS 1.2+ in transit. Encrypted at rest, backups included. Field-level encryption on contact email and phone, sender credentials, and integration tokens. Every query is scoped to a single workspace so one customer cannot read another’s rows.
Access by default zero
MFA is required for owner and admin operations, after a short onboarding grace window. Production access is restricted to a small named set of engineers, and staff actions inside the product are written to the audit log. Customer support never reads workspace data without explicit consent.
Data in the European Union
Primary storage in Frankfurt (eu-central-1). Backups within the same region. International transfers happen only through Standard Contractual Clauses with supplementary measures.
Compliance as engine
Suppression, approved LIA records, opt-out, and audit history are built into the workspace. These controls support your legal process; they do not certify a campaign.
Compliance posture
Where we stand on every regime that matters.
GDPR · UK-GDPR
EU + UK data subject rights honoured, DSARs answered inside the one-month statutory window, SCCs in place for non-EU transfers.
Compliant
KVKK · Türkiye
Leafer has no verified production IYS contract. Türkiye outbound remains unavailable.
Outbound blocked
CCPA · CPRA · California
No sale / no share posture. Right to know, delete, correct, and limit sensitive PI honoured.
Compliant
CASL · Canada
Country router blocks sends to Canadian addresses by default unless prior consent is documented.
Compliant
SOC 2 Type I
A target window, not an achieved certification. No report has been issued, and we will say so plainly until one is.
Planned · Q3 2026
ISO 27001
Roadmapped after SOC 2. Will be pursued in parallel with the next funding milestone.
Planned · 2027
Documents
Everything procurement will ask for, before they ask.
Operational
The day-to-day controls behind the policy.
Real-time status
A live check that the application can reach its database, re-run on every load. Planned maintenance and open service notices are posted there.
View status pageAudit log
Append-only trail of every suppression, opt-out, consent record and admin action. Rows are never rewritten. Queryable in-app for the last twelve months, longer extracts on request.
Breach notification
We commit to notifying the supervisory authority within 72 hours of becoming aware of a reportable personal-data breach, and affected customers without undue delay.
Backups + recovery
Encrypted at rest and in transit, with point-in-time recovery through our managed database provider. We have not yet run a documented restore drill, so we publish no RTO or RPO figure.
Procurement security review
Need a security questionnaire, an architecture review, or a signed DPA?
Email security@leafer.io with what you need. We reply within one business day with the documents, the answers, and a redline if you have one. No NDA required for the first call.
