LeadGuard by UpWeb, Legal Centre
Security and Vulnerability Disclosure
- Responsible entity:
- UpWeb Pty Ltd
- Document:
- security, v1.0
- Effective:
- 2026-07-15
- Last updated:
- 2026-07-15
This page describes the security controls we operate and how to report a vulnerability in LeadGuard by UpWeb.
1. Overview
LeadGuard applies layered controls across transport, authentication, database access, storage, payments and abuse prevention. We do not claim independent certification against SOC 2, ISO 27001 or PCI DSS, and LeadGuard is not itself certified as a payment processor. Card payment handling is performed by Stripe.
2. Transport and hosting
Traffic to LeadGuard is served over HTTPS. The application runs on Cloudflare Workers edge infrastructure and connects to a managed Postgres database hosted in the Sydney (Oceania) region.
3. Authentication and access
Authentication is provided by our managed authentication service, which supports email and Google OAuth sign-in. Administrative roles are restricted and separated from ordinary user access.
4. Database controls
The Postgres database uses row-level security with distinct roles for anonymous, authenticated and service contexts. Application code uses the least-privileged role that satisfies each request.
5. Storage and attachments
Support attachments are stored in a private storage bucket and are accessible only via short-lived signed URLs generated by authorised server code.
6. Payments
Card payment fields are hosted directly by Stripe. LeadGuard does not receive or store payment-card numbers. Stripe webhooks are verified with a signing secret before any billing state is updated.
7. Abuse prevention
The public scan flow stores HMAC-SHA256 hashes of IP addresses, anonymous browser identifiers and user-agent strings for abuse-prevention and rate-limiting purposes. Plaintext IP addresses are not stored for public-scan abuse prevention.
8. Logging and monitoring
Application and security logs are used to detect and investigate issues. Logs are retained for 90 days. Logs are designed not to capture unnecessary personal information.
9. Incident response
UpWeb assesses incidents promptly and notifies affected customers, individuals and regulators where required by applicable law. Initial external communications about an incident are approved by David Adamson, Managing Director of UpWeb Pty Ltd.
10. Reporting a vulnerability
To report a potential security issue in LeadGuard, email team@upweb.com with a clear description, reproduction steps and any relevant evidence. Where reasonably possible, we aim to acknowledge reports within three business days. LeadGuard does not currently run a paid bug-bounty programme and cannot guarantee acknowledgement times as a service-level commitment.
11. Scope and safe-harbour
Please act in good faith
Contact
Questions about this document can be sent to the LeadGuard team.
- Entity: UpWeb Pty Ltd (ABN 85 613 036 918, ACN 613 036 918).
- Trading as: LeadGuard by UpWeb.
- Location: Central Coast, New South Wales, Australia.
- All enquiries (privacy, security, legal, support): team@upweb.com.
- Legal notices: may be sent electronically to team@upweb.com.
