Infrastructure
The marketing site and API routes run on Vercel over HTTPS. Primary application data for signed-in users is stored in Postgres (hosted on Neon or equivalent per your deployment). Access to production credentials is operator-controlled — follow least privilege on your Vercel and database projects.
Encryption at rest and in transit: Data we persist in Postgres — including web sign-in session records (Auth.js session tokens and related rows) and operational metadata — is stored on volumes that Neon encrypts at rest as part of their managed service. Connections from our application to the database use TLS. LinkedIn authentication data stays in the browser and is not written to Postgres. The server stores an HMAC of a browser-derived member-id hash.
Extension & session model
The extension executes LinkedIn fetches in your browser using the cookies already present for linkedin.com. Authentication data stays in the browser. LinkedIn result payloads are sent to Listful only to build the export you requested.
The data boundary and retention policy are described in /privacy. Privacy-preserving member identity is covered under session identity.
What we optimize for
- Read-only positioning — no automated messaging or connection requests from Listful.
- Jittered requests and conservative pacing when walking LinkedIn’s APIs — LinkedIn use still carries inherent account risk.
- Webhook payloads signed with HMAC when configured; verify signatures on your receiver before trusting ingress.
Reporting
Suspected vulnerability or abuse? Email support@listful.so with reproduction steps and prefix the subject with [security].