Skip to content

Security and privacy

Security and privacy basics for LeadSnap AI.

The website handles business setup requests and demo submissions. Live SMS and phone features depend on provider credentials and verified webhook routes.

WordPress-native forms

Public forms use nonces, honeypot spam protection, server-side sanitisation and escaped output.

Secret fields

Provider API keys are stored server-side in WordPress options and are not printed on public pages. Admin fields are masked where practical.

Webhook verification

Telnyx and Twilio integrations include signature verification placeholders/routes that should be enabled before live traffic.

Data minimisation

The site should collect only the lead and setup details needed to respond, qualify and deliver the requested service.

Legal review needed

Privacy, terms, cookie and acceptable-use pages are UK-style placeholders and should be reviewed before paid launch.

Emergency wording

The service must not be positioned as an emergency response system or substitute for professional/emergency services.

Next step

Use the system with a careful setup path.

Configure provider credentials, email delivery and legal pages before live customer traffic.