Infrastructure and hosting
LeadQuasar runs on dedicated infrastructure we control, not shared hosting. The application and its PostgreSQL database sit on a private network; the database is not exposed to the public internet and accepts connections only from the application host.
Encryption
All traffic to and from leadquasar.com is served over HTTPS (TLS), and HTTP requests are redirected to HTTPS. Passwords are never stored in readable form — they are hashed with a slow, salted algorithm, so even we cannot recover them. Credentials for any mailbox you connect are encrypted at rest with AES-256-GCM.
Payments
Card details never touch our servers. Payments run through Stripe, a PCI-DSS Level 1 service provider, using their hosted checkout. We store only a customer reference and subscription status — never a card number, expiry, or CVC.
Access control
Contact details are hidden until you unlock a lead, and that masking is enforced on the server, not in the browser — a locked record’s email, phone and address are never sent to the page in the first place. Exports contain only records you have unlocked. Administrative access is restricted to the operator account and is not available to customers.
Backups and recovery
The full database is backed up automatically every night and retained on a rolling seven-day window, so any given day within the last week can be restored. Backups are stored on the same provider as the application.
Abuse and rate limiting
Unlocking is rate limited per account, per minute and per hour, and free accounts have a daily cap. An automated job runs nightly to flag unusual patterns — unusual volume, requests from many addresses at once, or non-browser clients — and can suspend an account. These controls exist to stop bulk extraction of the database, which protects both us and the people whose details are in it.
Where our contact data comes from
Our B2B records are aggregated from public and commercially licensed sources: business listings, company websites, and professional data providers. The records are business contact details — company names, business email addresses, business phone numbers and roles — not consumer or private data.
We do not sell your customer data, and we do not add the people you contact to our database.
Your data and what we do with it
Your account data (email, saved lists, unlocked records) is yours. We do not sell it, and we do not share it with other customers. Content you send to the AI assistant is processed by our AI provider to generate a response and is not used to train their models. See the Privacy Policy for the full detail and the DPA for the contractual terms.
Sub-processors
We rely on a small number of providers to operate the service: Stripe (payments), OpenAI (the AI assistant), Resend (transactional email), and our hosting provider. The current list, and what each one processes, is maintained in the DPA.
Removal requests
If you are listed in our database and want your details removed, email support@leadquasar.com from the address in question or with enough detail to identify the record. We will remove it and suppress it from future imports so it does not reappear. You do not need an account to make this request, and there is no charge.
What we don’t claim
We are a small team and we would rather be straight with you than imply more than is true:
- We are not SOC 2, ISO 27001 or HIPAA certified, and we do not claim to be.
- We have not undergone a third-party penetration test. If your procurement process requires one, tell us and we will discuss it honestly rather than send you a document that doesn’t exist.
- No provider can guarantee that every record is current. Every lead carries a 0–100 quality score so you can judge completeness before you unlock it.
Reporting a vulnerability
If you believe you have found a security issue, email support@leadquasar.com with the details and steps to reproduce. We will acknowledge it, and we will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other people’s data while doing so.