Trust Center · Security
Service security
Leadstar combines an operational security baseline with controls adapted to each enterprise deployment.
- Primary region
- Clever Cloud Paris
- PostgreSQL backups
- Daily · 7 days
- Infrastructure logs
- 7 days
- Production access
- Named and limited
- Hosting account
- 2FA enabled
- Secrets
- Outside source code
Web, API, PostgreSQL, Redis and Cellar.
Three copies are maintained by Clever Cloud in the Paris region.
Standard retention documented by Clever Cloud.
Access is granted only to authorised persons.
Two-factor authentication verified on Clever Cloud.
Dedicated environment variables and secrets management.
Application controls
- Communications encrypted in transit using HTTPS/TLS.
- Authentication and sessions managed through Auth0.
- Development and production environments separated.
- Automated conversation deletion after 30 days.
- OpenAI API call logging disabled and
store: falseapplied to compatible calls. - Seven-contributor threshold for collective reporting.
End of contract
Account and client data is deleted or returned no later than 60 days after the contract ends, subject to legal obligations and the residual seven-day backup cycle.
Incident management
Incidents are assessed, contained and documented. Where an incident concerns data processed for a client, Leadstar informs the client without undue delay so it can meet its own regulatory obligations.
Enterprise deployment framework
- DPA and security schedule included in the contract.
- Access list, subprocessors and regions validated.
- Retention settings adapted to client requirements.
- Security questionnaire and evidence provided during due diligence.