[dynamic_help_sidebar root="leads"]

Summary of LeadSquared Security Features

1. Feature Overview

LeadSquared is ISO 27001:2022 certified and HIPAA compliant. LeadSquared was built to deliver a robust and secure experience. In addition to our process and infrastructure-level safeguards, the LeadSquared application itself has a number of security-related features. This article summarizes the list of available features and describes how you can use them to protect your account.

Note: You can also download a pdf version of our security features.

 

2. Prerequisites

  • All security-related features (except user-level two-factor authentication) must be set up by the LeadSquared administrator user.
  • Some features listed in the article are not available on all plans. Please contact us at support@leadsquared.com for more details.

 

3. User Access

These features let you configure the level of access available to your users.

Feature Description Help Documentation
User Roles Each LeadSquared user role comes with its own set of restrictions for accessing features and data. Assigning roles based on how you want users to access your account. User Roles and Access Rights
Sales Groups By default, sales users can only view their own leads. However, you can give certain sales users (team leads, managers, etc.) special privileges through sales groups. Managing Lead and Account Access to Sales Users – Sales Groups
Permission Templates Permission templates give you granular level control over leads, activities and tasks. In addition, they let you control access to features like imports, exports, API, dashboards and reports.
IP Whitelisting You can whitelist the IP addresses that can access LeadSquared. Logins through suspect IPs (tors/anonymous proxies) will be automatically disabled. Restrict User Access to LeadSquared using IP Whitelisting

 

4. Login and Session Security

These features help secure your account by providing additional security capabilities.

Feature Description Help Documentation
Password Encryption When enabled, passwords will be encrypted and sent from the browser to the server. Users will not be able to ‘Remember Password’ and the password won’t be stored anywhere in the browser cache. LeadSquared Login Security Settings
Enable Dynamic Token for Mobile App Lets you enable an additional layer of security for communicating between the app and server.
Two Factor Authentication Two-factor authentication can be mandated for all users or configured at the individual user level. LeadSquared Security Settings – Two Factor Authentication
Authentication Provider As an alternative to logging in with your LeadSquared credentials, you can configure your account to enable log-in through the following third-party authentication providers –

  • Google
  • Active Directory Federation Services (ADFS)
  • API
LeadSquared Security Settings – Authentication Provider
Trusted Device Users can log into their LeadSquared account without verifying themselves through Two-Factor Authentication (2FA) each time Authentication – Trusted Device
Session Management Login Expiration Time –
When enabled, users will be required to log in again, after the configured time elapses. Session Timeout –
When enabled, a user who remains idle for the configured time will be automatically logged out.
LeadSquared Security Settings – Session Management
Force Logout All Users You may want to force logout users from your account for a number of possible reasons –

  • LeadSquared may have added new features/enhancements or you may have opted for additional features or a change of plan. Sometimes, this requires users to log back in.
  • If you suspect that your account has been compromised, you can force log-out all users as the first safety precaution.
  • Some users prefer not to log out of their accounts which may pose security risks.
LeadSquared Security Settings – Login Settings
Set Password Policy for users Customize the password policy of your LeadSquared account (e.g., minimum password length allowed, minimum special characters allowed, etc.) to comply with your organization’s policies. LeadSquared Security Settings – Set password Policy

 

5. Landing Page Security

The following security feature help secure landing pages you create using LeadSquared –

  • Google reCAPTCHA
    reCAPTCHA protects your landing pages against malicious software and spam. To learn how to embed them in your landing page forms, see Google reCAPTCHA on Landing Pages.
  • Allow submissions from registered domains only
    You can restrict the domains on which form submissions will be accepted.

 

6. Audit Logs

Audit logs provide numerous benefits including better transparency, record integrity and accuracy, and security of sensitive or vital information. A weekly review of audit log reports in LeadSquared will keep you on top of any activity in your account.

  • Audit Log Reports
    List of reports that help you track changes made to users, leads, automations, etc.
  • Request History
    Monitor all bulk requests such as import, export and delete, and also the history of support access requests.

 

7. API Security

LeadSquared APIs support Transport Layer Security (TLS) encryption. TLS is a standard that keeps an internet connection private and checks that the data sent between two systems (a server and a server, or a server and a client) is encrypted and unmodified. While using our APIs, we recommend following these best practices –
  • Keep your API keys secret
    We use access keys and secret keys (unique for each user) for authentication. These keys give you access to LeadSquared functionality and data, so they should always be kept secret.
  • IP Whitelisting
    With IP whitelisting, only requests made from specified IPs will be accepted. Whitelist the IPs you’ll be making API calls from. To learn more, see Restrict User Access to LeadSquared using IP Whitelisting.
  • Restricting API access through permission templates
    For users who don’t need access to API, we recommend disabling API access through permission templates. To learn more, see How to Create a Permission Template.
  • Reviewing API Logs
    View your API logs to check for unauthorized access. For details, see API Logs.

 

8. Data Protection and Privacy

These features were created with GDPR in mind. They enable you to provide transparency to your leads in relation to their data and privacy.

Feature Description Help Documentation
Cookie Consent As part of the privacy settings, you can allow end-users to control whether or not they would like to enable cookies on your website (where the LeadSquared Tracking Script has been installed) Data Protection and Privacy Settings
Email Opt-in By using the email opt-in setting together with the email opt-in automation action, you can let your leads decide whether or not they want to receive emails from your organization.
Personal Data Protection When enabled, it automatically creates a landing page in your account, that you can publish to existing leads and present them with the following options –

  • View their data
  • Remove their data
  • Update their data
  • Do Not Track

 

Any Questions?

We hope this article was helpful. Please leave us a comment below if you have more questions.

Check-in/Check-out Location and Time Restrictions

1. Feature Overview

You can restrict users from checking-in and checking-out from the mobile app based on location and time preferences. The feature is available on both Android and iOS.

  • Allow users to check-in/out within a defined radius around a particular latitude and longitude.
  • Prevent users from checking-in/out before a certain time or before a certain duration.
  • Use combinations of location and time to meet nuanced use cases.

Using these features, you can enable your users to check-in/out from their specific office locations at the appropriate office timings.

Note: If you’re new to the Check-in/out features, see How to Check-in/out.

LeadSquared Attendance Management

 

2. Prerequisites

  • This feature is not available by default. Contact us at support@leadsquared.com to enable it for your account.
  • Admins must configure and update the user custom fields that will be used to set location and time restrictions.

 

3. How It Works

You can set location restrictions (latitude, longitude, and radius), time restrictions (duration, specific time) or a combination of both. The restrictions are applied on the basis of defined user custom fields. These fields are mapped to location and time restriction as follows –

3.1 Location Restrictions

All location restrictions are user-specific. They can be applied in one of two ways –

  • Lat-Long-Radius geo-fencing – Users can check-in/out only within the defined latitude, longitude and radius (in meters).
    Or
  • ZipCode geo-fencing – Users can check-in/out only within the list of defined Zip Codes.

3.2 Time Restrictions

Time restrictions can either be user-specific or a general setting implemented for all users. They can be applied as any one or as a combination of both duration and fixed-time –

  • Duration – Once checked-in, users can only check-out after the defined duration has elapsed.
    For example, if the duration restriction = 8 hours, the user will be restricted from checking out before 8 hours have passed. So, if the user has checked-in at 8 AM they will be able to check-out only after 8 hours (after 4 PM).
  • After Fixed Time -Users are only allowed to check-in after a fixed time. For example, if this value is set to 10 AM, users can check-in after 10 AM (users won’t be allowed to check-in before the specified time).
  • Before Fixed Time – Users must check-in before a fixed time. For example, if this value is set to 9 AM, the user must check-in before 9AM (users won’t be allowed to check-in after the specified time).

You can allow users to check-in within a certain time frame by using both before and after fixed time restrictions (e.g., users can check-in after 7 AM but before 10 AM).

3.3 Combining Location and Time Restrictions

You can combine both location and time restrictions. For example, you can –

  • Restrict users from checking-in/out outside the office location (using lat-long-radius) and from checking-out before completing their office hours (using duration).
  • Ensure users check-in/out from one of multiple office/client locations (using zip-codes) and after a particular time (using fixed time).

According to your use case, you have the flexibility to set multiple restrictions with the option to respect “All” or “Any” conditions during check-in or check-out.

 

4. Set Up

Here’s the procedure you need to follow –

  1. Configure the user custom fields in your account.
  2. Populate the fields with values for each user.
  3. Contact us at support@leadsquared.com and let us know the schema names of the custom fields you want to map for the location and time restrictions.

4.1 Configure Custom Field Data Types

Here are the accepted data types for each restriction –

Restriction  Field Data Type Example Notes
Location Latitude Text or Number 12.9121
Longitude Text or Number 77.6446
Radius Text or Number 500 Radius is measured in meters (m).
ZipCodes Text 560001 | 560005 | 560017 You can enter multiple Zip Codes separated by pipes “|”
Time Duration Text or Number 8 Number of hours
Time Text 21:30 Format must be HH:MM

To configure user custom fields –

  1. Navigate to My Profile>Settings>Leads>Users>Custom Fields.
  2. Click Edit.
  3. Enter the display name (e.g., latitude, longitude, radius, etc.) and select the appropriate data type.
  4. Click Save.

user custom fields for check-in

4.2 Populate Values for Users

Next, update the values of the custom fields for the users you want to apply the check-in/out restrictions to. You can update the users manually or in bulk through CSV. For details, see

4.3 Contact Us

After completing the steps listed under sections 3.1 and 3.2, contact us at support@leadsquared.com. Let us know which fields you want to map. For example, Latitude (mx_custom_1), Longitude (mx_custom_2), etc.

 

5. Points to Note

  • Users will not be able to check-in/out while offline.
  • None of the restrictions in this article are supported in auto check-in/out.

5.1 Single Restriction

When only a single restriction is applied to an account and –

  • If the restriction field is blank for a particular user, check-in/out will work as normal (no restrictions will be enforced).
  • If the restriction field contains an invalid value for a user, a configuration error message will be displayed.

5.2 Multiple Restrictions

If multiple restrictions are applied on an account and –

  • If any one restriction field is blank for a user, that particular restriction will not apply to the user. The restriction check will be applied to “All” or “Any” of the remaining non-blank restrictions.
  • If all restriction fields are blank for a user, check-in/out will work as normal (no restrictions will be enforced).
  • If any of the restriction fields have an invalid value for a user, a configuration error will be displayed, but the user will be able to check-in if “Any” other condition is satisfied. In case, the “And” condition is configured, the user will be blocked from checking-in/out.
  • If all the restriction fields have invalid values for a user, a configuration error message will be shown and the user will be blocked from checking-in/out.

 

6. FAQs

Issue: How can I change the default check-in time for users on the LeadSquared mobile app?

Resolution:

  1. Log in to your LeadSquared account.
  2. Navigate to Settings>Mobile App>Additional Settings>Check-in/Check-out Location and Time Restriction.
  3. The textbox here allows you to enter a JSON that controls the default check-in and check-out time on the mobile app.
    1. If no data is available in the column, contact us at support@leadsquared.com to get the necessary JSON.
    2. If data is available, edit the parameter “After Fixed Time” and enter the new check-in time as needed.

 

Any Questions?

Was this helpful? Feel free to leave us a comment below.

How to Do Time Comparisons in Automation?

You can set up time comparison conditions through LeadSquared automation. This will help you solve a variety of use cases, like –

  • Distribute leads to users within their working hours. If the time is later than their working hours, add the leads to a list for the next day.
  • Let’s say an appointment is scheduled for today. Do a time comparison to check whether the appointment time has passed and create follow up tasks or notify users about the appointment accordingly.

Note: If you’re new to the automation feature, see Automation Home.

Here’s how to do it –

  1. In your automation, select the Compare condition. For more details see, Lead Automation Conditions – Compare.
  2. In the textbox on the left, enter the date/time you want to use as the basis for your comparison.
  3. In the text box on the right, type ‘@’ and select the date, date & time, or time field you want to compare the value on the left with.
  4. Click Save.
  5. Proceed to defining the action required based on the evaluation of the compare card.

compare in automation

In the example above, the current time in the account/UTC will be compared with the value we provided.

compare card details