Trust
Security
LeadsRefer moves affiliate payouts, tax identifiers, and inbound call recordings. This page describes the mechanisms that protect them — not as a marketing summary, but as what an advertiser or affiliate’s own diligence review typically asks for before signing up.
Account access
Passwords require 12+ characters, are checked against known-breached password data before being accepted, and are never stored — only a bcrypt hash.
Repeated failed sign-ins lock the account temporarily, with the lock window escalating on further attempts.
Two-factor authentication (TOTP, any standard authenticator app) is available on every account and required for staff accounts with administrative access.
Sessions expire on a fixed schedule regardless of activity, and are invalidated immediately on password reset — a session token from before the reset stops working rather than remaining valid until it naturally expires.
Payout and tax data
Tax identifiers (SSN/EIN) collected for 1099 reporting are encrypted at rest with AES-256-GCM before they reach the database. The encryption key is held separately from the database itself.
Payout and conversion changes — approvals, rejections, refunds, payout runs — are written to an append-only audit log recording who made the change and when.
Conversion recording and advertiser billing run inside database transactions, so a conversion can never be created without its billing effect being applied, or vice versa, even under concurrent requests.
Call recording
Call recording is off by default for every campaign and is enabled only per-offer, deliberately — roughly a dozen U.S. states require all parties to consent to a recorded call, and recording without notice is a criminal offense in those states.
When recording is enabled, the caller hears a spoken disclosure before the call connects.
Affiliates see a masked version of the caller’s number on their own dashboard — enough to match a call against their own records, not enough to reconstruct a callable list. Full numbers are visible only to network staff.
Tracking and traffic
Every click and conversion is checked against per-offer IP allow/block lists, geography, and device rules before it is recorded or billed.
Conversion caps (daily, weekly, monthly) and a minimum click-to-conversion window are enforced at the database level, not just in application logic, so they hold even under concurrent or automated traffic.
Public forms (signup, applications) carry a signed, time-bound token proving the form was actually loaded before it was submitted, alongside a honeypot field — the combination stops blind, scripted submissions without a CAPTCHA’s cost to real applicants.
Infrastructure
All traffic is served over HTTPS with HSTS enabled; the site does not accept plain HTTP.
A Content-Security-Policy and standard hardening headers (X-Frame-Options, X-Content-Type-Options, a locked-down Permissions-Policy) are set on every response.
The database is backed up nightly, with retention, and every backup installation is verified with an actual restore before being trusted.
Reporting a vulnerability
If you find a security issue, we want to hear about it before anyone else does. Email security@leadsrefer.com with steps to reproduce and the affected URL or endpoint. Full disclosure terms are published at /.well-known/security.txt. Please do not run automated scans that degrade service for other users, and do not access, modify, or exfiltrate data belonging to an account that is not your own.
