LeadProof Security
LeadProof uses server-side sessions, CSRF protection for state-changing authenticated requests, role-aware authorization, tenant-scoped resource queries, hashed webhook credentials, and masked sensitive payload values.
Production controls
Production startup requires PostgreSQL, a unique webhook secret, HTTPS cookies, an HTTPS public URL, and alert encryption configuration. Security headers are applied by the application, while TLS termination and network controls must be configured by the deployment platform.
Responsible disclosure
Please report suspected security issues privately to hello.tynovate@gmail.com. Do not include customer payloads, credentials, or tokens in the report.