Signed browser sessions
Session cookies are HTTP-only and use same-site protection. Secure-cookie mode is enabled when the service runs over HTTPS.
Lead Gatherer separates customer workspaces, uses signed sessions, and applies scoped permissions to API and MCP connections.
Illustrative product preview
Clear search statuses
Completed or timed out
Records
Structured
Contacts
When found
Export
CSV
Current controls
This page describes implemented application controls. It does not claim an independent certification or external audit.
Session cookies are HTTP-only and use same-site protection. Secure-cookie mode is enabled when the service runs over HTTPS.
API keys carry read or write permissions, have per-minute request limits, can be revoked, and require password confirmation before reveal.
Access to account activity, search history, campaigns, lead organization, and integrations is checked against the authenticated user and workspace. Public business details may be shared through the lead library.
Operational settings, cross-workspace search review, and system checks are limited to platform administrators.
Integration boundaries
Security information
These application controls are not an independent security certification. Use the information here to assess the service for your organization.
Growth and Professional include scoped API keys. Review permissions and revoke unused keys from API & integrations.