Trust & Security
LeaGen separates public presentation, communications, payment processing, and the proprietary referral ledger so no supporting service becomes the system of record for referral or commission data.
System boundaries
Specialized services support authentication, communications, and payments. LeaGen Core owns referral attribution, lifecycle history, commission rules, and audit evidence.
Protective controls
- OIDC-based authentication and role-scoped authorization
- Encrypted prospect information and controlled disclosure
- Idempotent provider webhooks and replay-safe integration jobs
- Tamper-evident audit events for critical referral, acceptance, commission, and payout actions
- Administrative review queues for exceptions, disputes, payout restrictions, and integration failures
- Provider-hosted identity and banking onboarding so LeaGen does not collect raw banking credentials
Responsible disclosure
If you believe you found a vulnerability, use our contact form, select Security concern, and provide a description and reproducible steps. Do not access data that is not yours, disrupt service, or publicly disclose an issue before we have had a reasonable opportunity to investigate.
Security is ongoing
No system can promise absolute security. LeaGen uses layered controls, monitoring, review, and continuous improvement to reduce risk and respond to issues.