Security & compliance

Built to pass a security review, not skirt one.

Mahleon sells to regulated firms, so it's engineered for the questions their compliance and security teams actually ask. Here's how it holds up.

No credentials stored

Mahleon runs through your own logged-in LinkedIn and Salesforce sessions in your own browser. We never see or store your passwords. The CRM check runs against your instance without a credential ever leaving your machine.

Lawful first contact

Every opener states where you found the person: the GDPR Article 14 disclosure, built into the message, not left to the user to remember.

Signed lawful basis

Before Mahleon finds anyone, you sign a Legitimate Interest Assessment. We provide the template and record your signature and version.

CRM screening gate

With a CRM connected, every lead is checked against it before outreach. Existing clients, leads and open-opportunity companies are held back, enforced server-side, not just flagged.

Approval workflow

Templates route through your compliance sign-off. Only approved copy can be used in a campaign; supervisors get oversight of what goes out.

Tamper-proof audit trail

Every planned and executed action is written to a hash-chained, exportable log of who was contacted, when, with what, and who approved it.

Data residency

SOQL runs against your own Salesforce instance; EU editions keep data in the EU. Retention is configurable on Enterprise.

Per-user isolation

Every user's connections, data and results are scoped to their own organisation and enforced in the database, so one firm's data is never visible to another.

Account-safe by design

Human-paced sending, conservative daily caps while an account warms up, and a hard stop the moment someone replies, engineered to protect the account, not risk it.

The data-room answer

“Do you store our CRM credentials?” No.

It's the question every regulated firm's security review asks, and Mahleon's answer stays clean: the CRM check runs through the adviser's own authenticated session, the same way they'd use Salesforce themselves. Nothing to store, nothing to leak, nothing to breach.

Where a firm's own settings can't allow that, an encrypted, per-user, revocable fallback exists, used only by exception and disclosed plainly. The default keeps the answer simple.

If compliance asks

You can answer every question.

  • “What's our lawful basis?” A signed LIA on file.
  • “Did we disclose where we found them?” Yes, in every first message.
  • “Who approved this copy?” Named, dated, logged.
  • “Did we contact an existing client?” The CRM gate prevents it.
  • “Show me everything we sent.” One export.
Compliance-first, genuinely

Outreach your firm can defend.

Start a free trial, or send this page to your compliance team first. That's rather the point.