Skip to content
LeadingPilot

Security

Last updated 18 September 2026

Short version: lead data travels encrypted, is stored in the EU, is deleted after 30 days by default, and your card number never reaches our servers. The detail is below, including the things we don't do yet.

01Data in transit

Every connection to leadingpilot.com runs over TLS 1.3. We send an HSTS header with a two-year max-age, and the domain is on the browser preload list, so browsers refuse to talk to us over plain HTTP before they make the first request. There is no unencrypted path to the product.

02Where your data is stored

Lead conversations, account records and billing references are processed and stored inside the European Union and the United Kingdom. We make no third-country transfer without Standard Contractual Clauses in place. The full statement is in the Privacy Policy.

03How long we keep it

Lead transcripts are kept 30 days by default and the window is configurable on your account. Ask us to delete your account and the account data goes within 30 days.

Billing records are the exception: UK accounting law requires us to keep order amounts and dates for 7 years, so those survive a deletion request. That is a legal obligation, not a preference.

04We never see your card

There is no card field anywhere on leadingpilot.com. Checkout hands you to our payment provider's own page, and what comes back to us is an order reference and a token. A card number never touches our servers, so it cannot leak from them.

Saving a card is opt-in and unchecked by default. It stores a token for one-click repurchase and nothing else: no subscription, no recurring charge, no automatic top-up. Every purchase is one you start. Refunds follow the Refund Policy.

05Account access

Passwords are stored as bcrypt hashes, never as text we could read back. Your session is a signed token in an httpOnly, SameSite cookie, so scripts on the page cannot read it and it is only sent over HTTPS in production. A password reset link is single-use and expires 30 minutes after we send it.

06Who else can touch the data

Each processor below is covered by a written data processing agreement. We do not sell data and we do not share it for third-party advertising.

  • AI inference and lead qualification processing
  • Payment processing and card tokenisation
  • Transactional email delivery
  • Hosting and database infrastructure
  • Booking-link delivery

Need the name of the processor behind a specific transaction or data request? Email [email protected] with your account email and we'll tell you.

07What we don't claim

A security page that lists only strengths is not much use to you, so here is the other half.

  • We do not offer two-factor authentication at login yet. Email verification is required to activate an account, but that is not the same thing.
  • We hold no SOC 2 or ISO 27001 certification. If a procurement form asks, the honest answer is no.
  • We are a small company. Treat the controls above as what we do, not as an audited guarantee of what we will never get wrong.

08Reporting a vulnerability

Email [email protected] with the word SECURITY in the subject and we will route it to an engineer the same working day. Please test against your own account only, and please don't run automated scanners at the live service. We don't run a paid bounty, but we will credit you if you want the credit. Postal address for formal notice: 27 Crofton Road, No. 6, 1st Floor, Liverpool, England, L13 5UJ.

09Your rights over the data

Under GDPR and UK GDPR you can ask for access, rectification, erasure, portability or restriction of your data. Email [email protected] and we respond within 30 days. The Privacy Policy sets out the lawful basis for each thing we do.