Skip to main content
Security

Access controls that follow the workspace.

Lead Gatherer separates customer workspaces, uses signed sessions, and applies scoped permissions to API and MCP connections.

Illustrative product preview

Clear search statuses

Ready
queued → running

Completed or timed out

Records

Structured

Contacts

When found

Export

CSV

Status explainedReady
Partial results retainedReview
Download when availableReview

Current controls

Security features already enforced by the product.

This page describes implemented application controls. It does not claim an independent certification or external audit.

Signed browser sessions

Session cookies are HTTP-only and use same-site protection. Secure-cookie mode is enabled when the service runs over HTTPS.

Scoped integration keys

API keys carry read or write permissions, have per-minute request limits, can be revoked, and require password confirmation before reveal.

Workspace boundaries

Access to account activity, search history, campaigns, lead organization, and integrations is checked against the authenticated user and workspace. Public business details may be shared through the lead library.

Restricted administration

Operational settings, cross-workspace search review, and system checks are limited to platform administrators.

Integration boundaries

Remote integrations receive only the access granted to their key.

Cannot switch to another workspace
Cannot read infrastructure credentials
Cannot access administrator diagnostics
Cannot create or reveal API keys
Cannot change billing or team roles
Receives bounded result previews

Security information

Understand the limits of these controls.

These application controls are not an independent security certification. Use the information here to assess the service for your organization.

Lead Gatherer does not claim SOC 2 or ISO 27001 certification, HIPAA compliance, or an independent penetration test. Multi-factor authentication is not currently available. Use a unique password, review account activity, and grant API keys only the permissions they need.
Ready when you are

Choose the permissions your integration needs.

Growth and Professional include scoped API keys. Review permissions and revoke unused keys from API & integrations.

Security and access controls | Lead Gatherer