LeadsBox connects through official provider APIs. Tenant-scoped access controls, HTTPS, selected field encryption, and reviewed subprocessors protect your CRM data.
Managed database and object-storage controls protect stored records. LeadsBox also applies field-level encryption to selected OAuth credentials and settings.
LeadsBox application and API traffic is served over HTTPS/TLS. Provider callbacks and outbound integrations use their official HTTPS endpoints.
LeadsBox connects through official provider APIs. Your social-account passwords are never sent to LeadsBox; provider OAuth or bot access tokens are stored when needed to keep a channel connected.
User passwords are hashed with bcrypt at cost factor 12. We never store plaintext passwords and cannot recover them — only reset them.
State parameters in all OAuth flows are cryptographically signed and verified server-side, preventing CSRF attacks during social account connection.
Every organisation gets a scoped data namespace. Multi-tenancy isolation means your data is structurally separated from all other LeadsBox accounts.
LeadsBox logs all team member actions — logins, lead updates, invoice sends, and setting changes — with timestamps. Pro plan feature.
API rate limits, failed-login protection, and security monitoring reduce brute-force and credential-stuffing risk.
LeadsBox connects to Instagram, WhatsApp, Facebook, and Telegram through their official developer APIs. We use OAuth 2.0 for authentication — your passwords are never sent to LeadsBox and we cannot access your account beyond what you explicitly grant.
Need a Data Processing Agreement? Download our DPA here · Questions? Contact us
Found a security vulnerability? We take all reports seriously and commit to responding within 48 hours. Please do not publish vulnerabilities before giving us time to fix them.
security@leadsboxapp.com7-day free trial. No credit card. Your data stays yours.