LeadCo.Cloud
A LEADCO-INSURECO MARKETING CO.
EST. 2005
LeadCo.Cloud · Legal & trust

Security

Effective July 13, 2026 · Leadco-Insureco Marketing LLC · Questions: stacy@leadco.biz

How LeadCo.Cloud is engineered and operated — encryption, isolation, access control, payments, and backups. Written to be checked, not to impress.

Infrastructure

LeadCo.Cloud runs on hardened Linux infrastructure hosted in the United States (DigitalOcean). Services run under least-privilege service accounts; administrative access is limited and logged.

Encryption in transit

Every site, portal, and API endpoint is served exclusively over HTTPS with modern TLS. Certificates are provisioned and renewed automatically; plain HTTP redirects to HTTPS.

Customer data isolation

Each business runs against its own isolated database and file store. There are no shared data tables between customers and no cross-tenant queries in the platform's data path.

Payments

Card and bank payments are processed by PCI-DSS compliant processors — Square, Stripe, and CSG Forte. Payment methods are tokenized end-to-end: full card numbers never touch or persist on LeadCo servers. Inbound payment webhooks are verified with HMAC signatures before they touch any ledger.

Access control

Role-based access separates owners, staff, and client/resident portals. Sessions use signed tokens; portal users can only reach their own records. Financial records cannot be created or altered from non-administrative sessions.

Auditability

Each account keeps a system log of administrative and financial events — payments, refunds, configuration changes, and outbound email — reviewable by the account owner.

Backups and resilience

Backups are automated, encrypted, versioned, and replicated off-site (Amazon Web Services). Restore procedures are exercised as part of normal operations, and point-in-time restore points are retained for production accounts.

Email

Business email sends from each customer's own authenticated mailbox — there is no shared platform sender that could be spoofed across customers.

Responsible disclosure

If you believe you have found a security issue on leadco.cloud or a hosted platform, email stacy@leadco.biz. We investigate all good-faith reports promptly and appreciate coordinated disclosure.

About the company

LeadCo.Cloud is engineered and operated in-house by Leadco-Insureco Marketing LLC, in business since 2005. One engineering standard, one security posture, one company accountable for all of it.