Trust
Read-only access, by connector
LeakIQ connects to your systems with read-only credentials, scoped to the minimum needed to detect revenue leakage. It never writes back, never changes a record, and never moves money. Here is exactly what each connector can read.
| Connector | Access | What LeakIQ reads |
|---|---|---|
| Stripe | OAuth (Stripe App), read-only | Invoices and payment intents, including failed collections |
| Xero | OAuth 2.0, read-only | Invoices and payments |
| QuickBooks Online | OAuth 2.0, read-only | Invoices and payments |
| Salesforce | OAuth 2.0, read-only | Opportunities and contract renewals |
| GoCardless | Read-only API access token | Mandates, payments and payment failures |
| CSV / JSON import | Signed file upload | Only the invoice, payment or subscription rows you export and upload |
For OAuth connectors, the exact scopes requested are shown on the provider's own consent screen when you authorise the connection, and you can revoke access at any time from the source system. Removing a connection deletes its stored credential immediately, after which LeakIQ makes no further calls to that system.
PCI DSS
LeakIQ reads transaction metadata (amounts, statuses, references) to detect leakage. It does not store, process or transmit cardholder data (primary account numbers); card processing stays with the payment provider. On that basis LeakIQ is out of direct PCI DSS scope.
Regulatory perimeter (FCA)
LeakIQ detects at-risk revenue on a read-only basis and never moves money, initiates payments, or provides regulated payment or credit services. On that basis it sits outside FCA authorisation requirements. This is a plain description of how the product works, not legal advice.
Reviewing connector access?
For the full technical detail, see the technical documentation, or email security@leakiq.io.