Alpha: the Chrome Web Store listing is still in review. Download the extension and load it unpacked. Download for Chrome
Trust · security

Security & reliability in plain terms.

This is a technical overview, not a certification pack. Pair it with the privacy policy and your own review process.
01

Infrastructure

The marketing site and API routes run on Vercel over HTTPS. Primary application data for signed-in users is stored in Postgres (hosted on Neon or equivalent per your deployment). Access to production credentials is operator-controlled — follow least privilege on your Vercel and database projects.

Encryption at rest and in transit: Data we persist in Postgres — including web sign-in session records (Auth.js session tokens and related rows) and operational metadata — is stored on volumes that Neon encrypts at rest as part of their managed service. Connections from our application to the database use TLS. LinkedIn authentication data stays in the browser and is not written to Postgres. The server stores an HMAC of a browser-derived member-id hash.

02

Extension & session model

The extension executes LinkedIn fetches in your browser using the cookies already present for linkedin.com. Authentication data stays in the browser. LinkedIn result payloads are sent to Listful only to build the export you requested.

The data boundary and retention policy are described in /privacy. Privacy-preserving member identity is covered under session identity.

03

What we optimize for

  • Read-only positioning — no automated messaging or connection requests from Listful.
  • Jittered requests and conservative pacing when walking LinkedIn’s APIs — LinkedIn use still carries inherent account risk.
  • Webhook payloads signed with HMAC when configured; verify signatures on your receiver before trusting ingress.
04

Reporting

Suspected vulnerability or abuse? Email support@listful.so with reproduction steps and prefix the subject with [security].

Related: Privacy · Terms