Skip to main content
GetCallLeadMobile Sales CRM
Skip to security overview
Verified Security Architecture

Security, Workspace Isolation & Data Practices

GetCallLead is built around explicit, verified architecture principles. We state only what our systems actually implement.

Organization-Scoped Access

Every customer organization operates in its own logical workspace. All queries, lead updates, user assignments, and follow-up schedules are strictly partitioned by organization ID at the backend database layer.

Encryption in Transit

All communications between mobile applications, web dashboards, and our backend APIs are transmitted strictly over modern HTTPS with TLS 1.3 / TLS 1.2 cipher suites. Plain HTTP requests are rejected.

Native Dialler & No Audio Recording

GetCallLead initiates phone calls through your device’s native phone dialler. GetCallLead does not secretly record, intercept, or store phone audio. Call outcomes, notes, and callbacks are entered manually by sales reps.

HMAC Signed Service Integration

Public marketing inquiries are forwarded through authenticated server-to-server channels using HMAC-SHA256 signatures, nonce replay protection, and strict timestamp drift validation. Direct client ingestion is prohibited.

Role-Based Access Control (RBAC)

Workspaces enforce strict privilege boundaries: Owner, Manager, and Staff. Staff members only access leads assigned to them; managers view team-wide schedules; owners retain commercial and seat administration rights.

No Advertising Data Sales

We do not sell your organization’s lead records, client phone numbers, or conversation notes to advertising networks or data brokers. Your business records remain exclusively yours.

Questions or Security Reports?

If you have questions regarding our security controls or wish to report a security observation, please email our team at support@getcalllead.io.