Security overview
What is true about how Adapt protects accounts and data, and what it does not claim.
Adapt describes its practices as they are and claims no accreditation it does not hold. It has no ISO 27001 or SOC 2 certification.
What is in place
| Control | Detail |
|---|---|
| Encryption in transit | HTTPS everywhere. |
| Passwords | Stored hashed with bcrypt, never in plain text. You can change yours under Settings, Security (8 characters minimum). |
| Organisation isolation | The organisation comes from your signed-in session and is checked against your membership on every request. A request cannot name a different one. |
| Roles | Owner, admin and member. See Roles: what an owner, admin and member can do. |
| Audit | Changes to people are logged. See The audit log. |
| Export tracing | Every export has an id and the exporting account in it, so a leaked file can be traced. |
| Cards | Changes made through Ask need your approval. |
| Mailbox passwords | Sealed with encryption before storage. |
| Runs in your own browser. Adapt does not log in to LinkedIn from its servers. | |
| Card details | Held by Stripe, never by Adapt. |
What Adapt does not claim
No certification, no penetration-test report published here, and no uptime promise.
Sessions
Settings, Security has Sign out, which ends your session in this browser. Closing the account from the Danger zone stops sign-in straight away.
Reporting a problem
Email hello@adaptleads.co.uk.