Security Policy
An overview of the technical and organizational safeguards AiLeadMs applies to protect tenant, campaign, lead, and call data.
Last updated: September 17, 20261. Our Approach to Security
AiLeadMs handles sensitive information — tenant credentials, lead data, campaign budgets, and IVR call recordings — and we design the platform with security as a core requirement, not an afterthought. This page summarizes the safeguards we apply; it is not an exhaustive technical specification.
2. Tenant Data Isolation
AiLeadMs is built on a multi-tenant architecture where each organization's leads, campaigns, and analytics are logically isolated from every other tenant, with access controlled by tenant-scoped permissions.
3. Encryption
- Data in transit between your browser, our dashboard, and our APIs is encrypted using industry-standard TLS.
- Sensitive data at rest, including call recordings and transcripts, is encrypted using industry-standard encryption.
4. Access Controls
- Role-based access control (RBAC) lets tenants restrict what each team member can view or do.
- Internal access to production systems and customer data is limited to authorized personnel on a need-to-know basis, and is logged.
- We support strong authentication practices for tenant accounts and encourage the use of unique, strong passwords.
5. IVR Call Recording Security
Call recordings and AI-generated transcripts are stored with the same access controls and encryption standards as other sensitive tenant data, and are retained according to our data retention practices described in the Privacy Policy.
6. Sub-processors & Infrastructure
We rely on reputable cloud infrastructure, telephony/IVR, and AI-processing providers to deliver the Service. These providers are selected based on their own security and data-protection commitments, and are bound by contractual confidentiality obligations.
7. Incident Response
We maintain an internal process to detect, assess, and respond to security incidents, including notifying affected tenants in accordance with our Privacy Policy and applicable law where a personal data breach occurs.
8. Responsible Disclosure
If you believe you have discovered a security vulnerability in AiLeadMs, please report it responsibly through our Contact page rather than disclosing it publicly. We will acknowledge reports and work to address valid issues promptly.