Skip to main content

Trust and security

How we handle your data

leadmaps is privacy-first analytics. That is only credible if the infrastructure behind it earns the claim. This page is the shorter-than-the-DPA, longer-than-marketing version of what we actually do.

For the practical walkthrough of running analytics under GDPR, read GDPR-compliant analytics, enforced at the server.

Last reviewed 2026-05-17.

Security highlights

Sub-processors

Vendors we use to deliver the service. Sub-processors maintain independent security programs, including SOC 2 Type II or equivalent where applicable. The live sub-processor list is available in the dashboard DPA at app.leadmaps.nl/settings/legal (sign-in required).

VendorPurposeRegion
VercelDashboard hosting and edge functionsGlobal
Fly.ioCollector and Postgres (event storage)EU (ams, fra)
SupabaseDashboard auth and control-plane databaseEU (Paris)
PaddleSubscription billingGlobal
ResendTransactional emailUS
SentryError reporting (PII-scrubbed)EU (Frankfurt)
Backblaze B2Encrypted off-site database backupsEU (eu-central-003)
HostingerLogin email delivery (magic links)EU
AWS S3Conditional: only when you configure an S3 export destination, so data flows to the bucket and region you chooseCustomer-chosen

Certifications

SOC 2 Type II report

SOC 2 Type II readiness is underway internally. There is no completed report yet, and we make no claim of certification. The download link appears here once a report is delivered. In the meantime, enterprise customers under NDA can request our current security evidence pack via security@leadmaps.nl.

Reporting a vulnerability

Email security@leadmaps.nl. Include reproduction steps, the affected surface (dashboard, collector, SDK, or API), an impact estimate, and your preferred disclosure timeline. We respond within 48 hours.

Our default disclosure window is 90 days for non-critical findings. Active-exploit reports are treated as S0 incidents with immediate mitigation.

Need more detail?

Enterprise customers can request our full security policy, incident-response playbook, and SOC 2 evidence pack under NDA. Reach security@leadmaps.nl.