Your leads are your business
You are about to put your entire customer list into someone else’s software. That deserves a straight explanation of how it is protected — not a page of badges.
Four things that actually matter
Complete separation between companies
Every workspace is isolated. Each company’s leads, users, settings and reports are scoped to that company on every single read and write — enforced in the data layer itself, not left to individual screens to remember. There is no feature, anywhere in the product, that lets one company see another’s data.
Two-factor authentication
Turn on TOTP-based 2FA using Google Authenticator or any similar app, with recovery codes in case you lose your phone. Accounts also lock automatically after repeated failed login attempts, and every login attempt is recorded.
API keys you can actually control
API keys are scoped to specific modules, rate limited per minute, and can be restricted to an IP whitelist. Only a hash of each key is ever stored — the raw key is shown once, at creation, and never again. Revoke any key instantly.
Locked-down landing page scripts
Each landing page script only accepts submissions from the domain you registered — and optionally from one exact page URL. Every landing page also has its own per-minute rate limit, so a bot cannot flood your pipeline with junk.
What we do with lead data
Lead and customer data you collect belongs to you. We access it only to operate, support and secure the service. We do not sell it, we do not use one company’s data to benefit another, and we do not train anything on it.
The one time data leaves the platform is when you explicitly connect Google Ads or Meta and map a pipeline stage to a conversion action. At that point, and only for workspaces that have set this up, the conversion event you configured is sent to that platform — the original click ID, the conversion name and optionally a value.
You can export your data at any time, and cancelling is a button in your billing screen, not an email negotiation.
Being honest about our size
We are a young product, not a multinational with a compliance department. We are not going to put logos of certifications we do not hold on this page, because you would find out eventually and rightly stop trusting everything else we said.
What we will do is answer specific security questions directly. If your business has requirements we need to meet, ask us and you will get a real answer — including “not yet” where that is the truth.
Ready when you are
Start free, keep full control of your data, and leave whenever you like.