Trust

Security

Last updated September 17, 2026

We are a two-owner company, both veterans, and we would rather tell you exactly how your data is handled than imply an audit we have not had. If your review needs something not covered here, email omar@leadmegaphone.com and you will get a straight answer.

What we hold

Your company and contact details, the prospect lists we work for you, the email we send and receive on your behalf, the facts you tell us so the work stays consistent, and a record of work performed and its cost.

We never hold payment card numbers, government identifiers, or health information. Card details go directly to Stripe and never touch our systems.

Where it lives

Your data is stored in a Postgres database hosted by Supabase in the United States (AWS us-east-2), encrypted at rest by the provider, with every connection over TLS. Backups are encrypted with AES-256 before they leave the database, and the key is never stored with them. Every machine that touches client data uses full-disk encryption.

Separation between clients

Every record carries a client identifier, and the database itself enforces the boundary: a connection scoped to one client cannot read or write another client’s rows. An automated test proves this every night against the live database, and it alerts us if it ever fails.

Who can reach it

The two owners of Lead Megaphone, and the service accounts that run the work. No subcontractors, no shared logins. Credentials are held in an encrypted store with the passphrase kept separately, and multi-factor authentication is on every account that supports it.

Backups and recovery

Your data is exported and encrypted nightly and kept for 14 days. Each backup is verified the moment it is written: it is decrypted and every table’s row count is checked against the live database, so a backup that cannot be restored is discarded and raises an alarm. If a night is missed, we are told. Our recovery target is one business day.

How long we keep it

For as long as we work together. When the engagement ends, or whenever you ask in writing, we delete your stored memory, email records and approvals within 30 days, and deleted data leaves our backups within 14 days after that. Invoices and an audit trail of actions taken are kept for seven years for accounting and legal reasons. We will hand you a full export of your data before deleting anything.

Sub-processors

These companies process client data on our behalf:

  • SupabaseDatabase hosting (United States)
  • AnthropicLanguage model processing
  • Google WorkspaceSending and receiving email
  • SmartleadOutbound email delivery
  • StripePayments
  • MillionVerifierEmail address verification
  • VercelWebsite hosting
  • IONOSServer hosting (encrypted backups)

Anthropic does not train its models on data submitted through its API. We tell clients in writing before adding a sub-processor that would touch their data.

If something goes wrong

We contain first and investigate second: the exposed credential is revoked and the affected job stopped before anything else. If your data was involved, you hear from Omar in writing within 72 hours of us confirming it, with what we know, what we do not yet know, and when you will hear from us next. Every incident gets a written account of what happened and what we changed.

Found a security problem in something of ours? Email omar@leadmegaphone.com. We will confirm within one business day and will not take legal action against anyone who reports a problem in good faith.

What we do not claim

We hold no SOC 2, ISO 27001 or HIPAA certification. We are a small company, and a certification badge we have not earned would tell you nothing true. What we will do is answer your questionnaire honestly, sign a data processing agreement, and put our practices in writing, as above.

Related: Privacy Policy and Terms.

Cookies & privacy

We save your display and privacy choices in this browser. Optional usage analytics help us improve the site. Forms work either way. Privacy policy