Enterprise-grade security

Your DM data. Your business. Fully protected.

LeadsBox connects through official provider APIs. Tenant-scoped access controls, HTTPS, selected field encryption, and reviewed subprocessors protect your CRM data.

Field encryption
Selected credentials & settings
HTTPS/TLS
Encryption in transit
GDPR rights
Request workflows supported
NDPA
Privacy controls documented
Security OverviewControls monitored
Storage protection
Managed controls + selected field encryption
Transport encryption
HTTPS/TLS
Social credentials stored
OAuth tokens — never account passwords
Privacy controls
Data deletion workflow + DPA template
Data-subject requests
Access, correction, deletion, and objection
OAuth 2.0 state validation
CSRF attack prevention
Official APIs only:
Security features

Built secure from the ground up

Layered storage protection

Managed database and object-storage controls protect stored records. LeadsBox also applies field-level encryption to selected OAuth credentials and settings.

HTTPS/TLS in transit

LeadsBox application and API traffic is served over HTTPS/TLS. Provider callbacks and outbound integrations use their official HTTPS endpoints.

No social credentials stored

LeadsBox connects through official provider APIs. Your social-account passwords are never sent to LeadsBox; provider OAuth or bot access tokens are stored when needed to keep a channel connected.

bcrypt password hashing

User passwords are hashed with bcrypt at cost factor 12. We never store plaintext passwords and cannot recover them — only reset them.

OAuth CSRF protection

State parameters in all OAuth flows are cryptographically signed and verified server-side, preventing CSRF attacks during social account connection.

Organisation-level data isolation

Every organisation gets a scoped data namespace. Multi-tenancy isolation means your data is structurally separated from all other LeadsBox accounts.

Audit log

LeadsBox logs all team member actions — logins, lead updates, invoice sends, and setting changes — with timestamps. Pro plan feature.

Rate limiting & abuse prevention

API rate limits, failed-login protection, and security monitoring reduce brute-force and credential-stuffing risk.

Official APIs only

We never scrape, never store your passwords

LeadsBox connects to Instagram, WhatsApp, Facebook, and Telegram through their official developer APIs. We use OAuth 2.0 for authentication — your passwords are never sent to LeadsBox and we cannot access your account beyond what you explicitly grant.

Meta Messaging API — Instagram + Facebook
WhatsApp Business API (Cloud)
Telegram Bot API
Revoke access anytime from social settings
Connection flow
1
You click "Connect Instagram"
LeadsBox redirects to Instagram's OAuth page
2
You log in on Instagram
Your credentials go to Instagram — never to LeadsBox
3
Instagram grants a token
Scoped access token sent to LeadsBox. No password ever touches our server.
4
LeadsBox uses the token
Read-only access to DMs. Token encrypted with your org key.
Compliance

Privacy regulations we comply with

🇪🇺
GDPR
EU General Data Protection Regulation
Access, correction, deletion, and objection request workflows
Data Processing Agreement template available for review
Cookie consent before optional tracking
Data minimisation controls
Privacy Policy in plain language
🇳🇬
NDPR
Nigeria Data Protection Regulation
Nigeria Data Protection Act considerations
Incident and breach-response process
Data-subject request workflow
Current subprocessor disclosure

Need a Data Processing Agreement? Download our DPA here · Questions? Contact us

Responsible disclosure

Found a security vulnerability? We take all reports seriously and commit to responding within 48 hours. Please do not publish vulnerabilities before giving us time to fix them.

security@leadsboxapp.com

Secure DM CRM. Try it free.

7-day free trial. No credit card. Your data stays yours.

Security & Privacy — How LeadsBox Protects Your Data | LeadsBox