Security

Agency boundaries are product boundaries.

LeadDecide separates agency accounts, client workspaces, users, provider credentials, and AI keys so a convenient portfolio view never becomes cross-client exposure.

Core controls

Built for client-facing operational data.

Tenant isolation

Agency administrators can access only workspaces owned by their agency account. Client users see only explicit memberships.

Encrypted secrets

CTM, CallRail, OpenAI, Anthropic, webhook destinations, and signing secrets are encrypted before storage.

Invite-only access

There is no open registration page. Administrators issue expiring setup links and can revoke access without deleting history.

Signed delivery

Outbound webhook payloads are signed, retryable, and can exclude personally identifiable contact data.

Audit trail

Lead actions, qualification changes, AI attempts, provider deliveries, and review decisions remain attributable.

Budget-safe AI

Managed AI requests reserve budget before execution; BYOK credentials remain agency-scoped and are never shown back to reviewers.

Responsible defaults

A failed integration should stop safely, not invent success.

Unavailable providers, missing AI credentials, conflicts, exhausted budgets, and failed outbound webhooks remain visible for human action. Provider shared fields remain import-only, and LeadDecide does not silently turn infrastructure failure into a lead decision.

Review the fit

Walk through access, credentials, outbound delivery, and AI controls with us.

Book an agency walkthrough