Trust
Security
Last updated September 17, 2026
We are a two-owner company, both veterans, and we would rather tell you exactly how your data is handled than imply an audit we have not had. If your review needs something not covered here, email omar@leadmegaphone.com and you will get a straight answer.
What we hold
Your company and contact details, the prospect lists we work for you, the email we send and receive on your behalf, the facts you tell us so the work stays consistent, and a record of work performed and its cost.
We never hold payment card numbers, government identifiers, or health information. Card details go directly to Stripe and never touch our systems.
Where it lives
Your data is stored in a Postgres database hosted by Supabase in the United States (AWS us-east-2), encrypted at rest by the provider, with every connection over TLS. Backups are encrypted with AES-256 before they leave the database, and the key is never stored with them. Every machine that touches client data uses full-disk encryption.
Separation between clients
Every record carries a client identifier, and the database itself enforces the boundary: a connection scoped to one client cannot read or write another client’s rows. An automated test proves this every night against the live database, and it alerts us if it ever fails.
Who can reach it
The two owners of Lead Megaphone, and the service accounts that run the work. No subcontractors, no shared logins. Credentials are held in an encrypted store with the passphrase kept separately, and multi-factor authentication is on every account that supports it.
Backups and recovery
Your data is exported and encrypted nightly and kept for 14 days. Each backup is verified the moment it is written: it is decrypted and every table’s row count is checked against the live database, so a backup that cannot be restored is discarded and raises an alarm. If a night is missed, we are told. Our recovery target is one business day.
How long we keep it
For as long as we work together. When the engagement ends, or whenever you ask in writing, we delete your stored memory, email records and approvals within 30 days, and deleted data leaves our backups within 14 days after that. Invoices and an audit trail of actions taken are kept for seven years for accounting and legal reasons. We will hand you a full export of your data before deleting anything.
Sub-processors
These companies process client data on our behalf:
- Supabase— Database hosting (United States)
- Anthropic— Language model processing
- Google Workspace— Sending and receiving email
- Smartlead— Outbound email delivery
- Stripe— Payments
- MillionVerifier— Email address verification
- Vercel— Website hosting
- IONOS— Server hosting (encrypted backups)
Anthropic does not train its models on data submitted through its API. We tell clients in writing before adding a sub-processor that would touch their data.
If something goes wrong
We contain first and investigate second: the exposed credential is revoked and the affected job stopped before anything else. If your data was involved, you hear from Omar in writing within 72 hours of us confirming it, with what we know, what we do not yet know, and when you will hear from us next. Every incident gets a written account of what happened and what we changed.
Found a security problem in something of ours? Email omar@leadmegaphone.com. We will confirm within one business day and will not take legal action against anyone who reports a problem in good faith.
What we do not claim
We hold no SOC 2, ISO 27001 or HIPAA certification. We are a small company, and a certification badge we have not earned would tell you nothing true. What we will do is answer your questionnaire honestly, sign a data processing agreement, and put our practices in writing, as above.
Related: Privacy Policy and Terms.