Back to LeadMighty

Trust / Security

Security at LeadMighty

How we keep your organisation's data private, isolated and accountable — from tenant isolation to encryption and least-privilege access.

Last updated · 18 July 2026

01

Our approach

You're trusting LeadMighty with some of your most sensitive records — salaries, identity documents, health-related leave. We design the product so that data stays private, access is earned, and every action is accountable.

02

Tenant isolation

Every organisation's data is scoped to its own workspace and separated from every other tenant. Enterprise customers can go further with a dedicated, single-tenant deployment on their own database and domain.

03

Access control

Inside a workspace, role-based permissions decide exactly what each person can see and do. Sensitive fields — compensation and payslips — are gated to the people who should see them, enforced on the server, not just hidden in the interface.

  • Granular roles and permissions, configurable per organisation.
  • Server-side enforcement on every request, so the rules can't be bypassed from the client.
  • Least-privilege access for LeadMighty staff, granted only when needed for support.
04

Encryption

Data is encrypted in transit using modern TLS, and encrypted at rest by our infrastructure providers. Files you upload are stored in access-controlled object storage.

05

Infrastructure and reliability

We build on reputable cloud infrastructure with managed backups and redundancy. Our providers maintain recognised security certifications; details are available to customers under NDA.

06

Operational practices

  • Changes go through review and automated checks before release.
  • Secrets and credentials are kept out of source code and rotated when needed.
  • We monitor for unusual activity and keep audit trails of sensitive actions.
07

Your part

Security is shared. Use strong, unique credentials for your admins, review who has access regularly, and off-board people promptly. The product gives you the controls; you decide how tightly to set them.

08

Reporting a vulnerability

Found something? We want to hear from you. Email security@leadmighty.com with the details and steps to reproduce, and we'll respond quickly. Please give us reasonable time to fix an issue before disclosing it publicly.

Questions about this document? Email legal@leadmighty.com.