generated: '2026-08-13' method: searched probe: true url: https://www.leadspace.com/platform/security-and-compliance description: >- Leadspace runs no dedicated trust portal (trust.leadspace.com and security.leadspace.com do not resolve; /trust, /security and /compliance 404). It does publish a first-party Security and Compliance page on the product site naming specific certifications and regulatory regimes, plus a long-standing General Statement of Information Security and Privacy in the help center. Those two pages are the trust surface, and they are recorded here rather than claimed as a trust center that does not exist. trust_portal: present: false probed: - url: https://trust.leadspace.com/ status: 000 note: DNS does not resolve - url: https://security.leadspace.com/ status: 000 note: DNS does not resolve - url: https://www.leadspace.com/trust status: 404 - url: https://www.leadspace.com/security status: 404 - url: https://www.leadspace.com/compliance status: 404 certifications: - SOC 2 Type II - ISO 27001 regulations: - GDPR - CCPA - Texas Data Broker registration controls_published: - Secure cloud architecture - Encrypted data storage and transfer - Continuous vulnerability monitoring - Role-based access control - Multi-layer authentication - Robust incident management - Data minimization best practices - Purpose-driven data use - Consent-aware processing - Strict retention and deletion standards - Automated system checks and security alerts - Real-time anomaly detection - Continuous compliance audits - Regular penetration testing privacy_rights: do_not_sell: https://www.leadspace.com/do-not-sell-form texas_data_broker_notice: https://www.leadspace.com/texas-data-broker-notice privacy_notice: https://www.leadspace.com/privacy-notice cookie_notice: https://www.leadspace.com/cookie-notice data_processing_addendum: https://www.leadspace.com/leadspace-data-processing-addendum/ note: >- Material for a B2B data provider: Leadspace sells identity data about individuals, so the Do Not Sell form and the Texas data-broker notice are part of its compliance posture, not boilerplate. vulnerability_disclosure: security/leadspace-vulnerability-disclosure.yml evidence: - source: https://www.leadspace.com/platform/security-and-compliance status: 200 keywords: - SOC 2 Type II - GDPR - CCPA - penetration testing - role-based access control - encrypted data storage and transfer fetched: '2026-08-13' - source: https://support.leadspace.com/hc/en-us/articles/360012276859-General-Statement-of-Information-Security-and-Privacy kind: help-center-security-statement note: >- Cited from the 2026-07-19 pass (ISO 27001 certified, SOC 2 Type II audited). Re-probe on 2026-08-13 returned 403 — the Zendesk help center now blocks automated fetches, so this URL is retained as previously verified rather than re-verified. gaps: - No trust portal with downloadable, current audit reports or a subprocessor list; certifications are asserted in marketing prose rather than evidenced by a report request flow. - The Security and Compliance page names SOC 2 Type II but does not state the audit period or the auditor.