Trust
Trust Centre
Everything your security, privacy and procurement teams need to evaluate LeakIQ, in one place. LeakIQ connects to your financial systems using read-only credentials, encrypts everything sensitive, and stores your data at rest in the EU. If you need something that is not here, a completed security questionnaire, a signed DPA, or a technical review call, email security@leakiq.io.
Data residency
EU, AWS eu-west-1, Ireland
Encryption
AES-256-GCM at rest · TLS 1.2+ in transit
Data protection
UK GDPR · ICO reg. ZC187738
Connectors
Read-only, no write-back
Penetration testing
CREST-accredited test being commissioned
SOC 2 Type II
Planned, not yet under audit
Security
Security overview
How LeakIQ keeps your financial systems safe to connect.
Technical documentation
Architecture, connectors, encryption, RBAC, MFA and audit for technical reviewers.
Information Security Policy
The umbrella policy governing how we protect data and systems.
Vulnerability Disclosure Policy
How to report a security issue, and our safe-harbour commitment.
Resilience & operations
Data & privacy
A word on AI
How we use AI, and where we deliberately do not. Your numbers are deterministic, not AI-generated.
Privacy Policy
What personal data we process and your rights.
Data Processing Agreement
Our Article 28 processor terms, also Schedule 1 of the Master Subscription Agreement.
International Data Transfers
Where data is stored and processed, and the safeguards for any transfer.
Data Retention & Deletion Policy
How long we keep each data category, and how deletion works.
Sub-processors
The third parties we use, what they handle, and change notifications.
Legal
Running a vendor review?
We are happy to complete your security questionnaire, provide a signed Data Processing Agreement, or join a technical review call before you connect any systems. We respond within one business day.