Legal
Security Policy
Last updated: July 24, 2026
LocalRadar takes security seriously. This page summarizes our approach for customers evaluating the product for agency and enterprise use. It is not a formal certification claim.
1. Principles
- Least privilege access to production systems
- Encryption in transit (TLS) for application traffic
- Encryption at rest for sensitive data stores where the platform is configured to do so
- Secure authentication for user accounts
- Separation of customer workspaces by account/organization controls
2. Application security
- Authenticated API routes for protected resources
- Input validation and server-side authorization checks
- Dependency and platform updates as part of ongoing maintenance
- Secrets and API keys stored via environment configuration / encrypted storage patterns (not committed to source control)
3. Authentication & sessions
User authentication is provided through our configured auth provider. Sessions are protected according to provider best practices. Users should enable strong passwords and protect their email accounts.
4. Payments
Card payments are handled by PCI-compliant payment processors. LocalRadar does not store full payment card numbers.
5. Third parties
We rely on reputable infrastructure, database, and AI providers. Vendor access is limited to what is required to operate the Services. Review our Privacy Policy for processing details.
6. Customer responsibilities
- Protect account credentials and team access
- Use BYOK / API keys carefully and rotate when needed
- Review AI-generated content before sending to clients or prospects
- Comply with marketing and privacy laws in your outreach
7. Incident response
If we become aware of a security incident affecting customer personal data, we will investigate and notify affected customers and regulators as required by applicable law.
8. Vulnerability reporting
If you believe you have found a vulnerability, email security@localradar.io with details and reproduction steps. Please avoid privacy-invasive testing and give us reasonable time to respond before public disclosure.
9. No false certifications
We do not claim SOC 2, ISO, or similar certifications on this site unless we have completed and can evidence them. When certifications are obtained, this page will be updated.