Security overview

What is true about how Adapt protects accounts and data, and what it does not claim.

GuideAdminChecked 2026-10-10

Adapt describes its practices as they are and claims no accreditation it does not hold. It has no ISO 27001 or SOC 2 certification.

What is in place

Control Detail
Encryption in transit HTTPS everywhere.
Passwords Stored hashed with bcrypt, never in plain text. You can change yours under Settings, Security (8 characters minimum).
Organisation isolation The organisation comes from your signed-in session and is checked against your membership on every request. A request cannot name a different one.
Roles Owner, admin and member. See Roles: what an owner, admin and member can do.
Audit Changes to people are logged. See The audit log.
Export tracing Every export has an id and the exporting account in it, so a leaked file can be traced.
Cards Changes made through Ask need your approval.
Mailbox passwords Sealed with encryption before storage.
LinkedIn Runs in your own browser. Adapt does not log in to LinkedIn from its servers.
Card details Held by Stripe, never by Adapt.

What Adapt does not claim

No certification, no penetration-test report published here, and no uptime promise.

Sessions

Settings, Security has Sign out, which ends your session in this browser. Closing the account from the Danger zone stops sign-in straight away.

Reporting a problem

Email hello@adaptleads.co.uk.