🎉 Leadquora 3.0 is live — new AI-powered checkout optimizer See what's new →
Certifications

Audited by the best. Verified annually.

Third-party certifications that matter — renewed every year with independent auditors.

PCI DSS Level 1

The highest level of Payment Card Industry Data Security Standard compliance. Audited annually by a Qualified Security Assessor. Zero cardholder data ever touches merchant servers.

SOC 2 Type II

Continuous, independently audited controls over security, availability, confidentiality, processing integrity and privacy. Reports available under NDA to Enterprise customers.

ISO 27001

ISO 27001:2022 certified for information security management systems. Our ISMS covers every employee, process and system that touches customer data.

GDPR & CCPA

Compliant with EU General Data Protection Regulation and California Consumer Privacy Act. DPAs, SCCs, and Data Subject Rights tooling built-in.

HIPAA-ready

BAAs available for healthcare and wellness merchants handling PHI. Built on HIPAA-compliant infrastructure with end-to-end controls.

CSA STAR

Cloud Security Alliance STAR Level 2 attestation. Our cloud security posture is continuously monitored and externally verified.

How we protect data

Defense in depth

Layered controls at every level — from physical infrastructure up to the application layer.

Encryption

Encrypted everywhere, always

Every byte of customer data is encrypted at rest and in transit, with modern algorithms and hardware-backed key management.

  • AES-256 encryption at rest using AWS KMS with HSM-backed key storage
  • TLS 1.3 for all in-transit data, with HSTS enforced and weak ciphers disabled
  • Per-merchant data encryption keys rotated automatically every 90 days
  • Application-level encryption for all PII fields — keys isolated from database
AES-256 at restAll customer data + PII fields
TLS 1.3 in transitHSTS + modern ciphers only
HSM-backed KMSFIPS 140-2 Level 3 validated
Testing

Adversarial by design

We try to break our own software before anyone else does. Then we pay other people to try again.

Continuous red team

In-house red team runs weekly adversarial exercises. Findings tracked as P0 regardless of source.

External pen tests

Independent penetration tests every 6 months by two different top-tier firms. Reports available to Enterprise customers.

Public bug bounty

Rewards up to $50,000 for critical vulnerabilities. Runs continuously via HackerOne with 300+ researchers.

Automated scanning

SAST, DAST, SCA and IaC scanners run on every commit. Critical findings block merges.

24/7 SOC monitoring

In-house security operations center monitors every production system around the clock. Average alert-to-action time: 90 seconds.

Employee security

Every employee completes annual security training. Background checks on all US hires. Hardware keys required for all infrastructure access.

Need detailed documentation?

SOC 2 reports, penetration test summaries, architecture diagrams, DPAs — available under NDA to Enterprise customers. Our security team is one click away.

security@leadquora.com Talk to security