Skip to main content
This page summarizes Linkup’s security controls and compliance posture for security reviews.

Trust Center

SOC 2 Type II report and related compliance documentation.

Certifications and compliance

  • SOC 2 Type II
  • ISO 27001
  • HIPAA compliant

Configurable options

The following can be configured as needed:
  • Zero Data Retention (ZDR) — available on request (book a call)
  • Single Sign-On (SSO) — enterprise
  • Guaranteed local query processing — enterprise
  • Multi-routing across geographies — enterprise
  • IP whitelisting and role-based access configurations — enterprise
Contact contact@linkup.so for configuration details.

Encryption and key management

  • In transit: TLS 1.2+ for all API communications
  • At rest: AES-256 for stored data
  • Key management: centrally managed with restricted access

Infrastructure security

  • Network segmentation and multi-layer traffic controls
  • Hardened service baselines and patch management
  • Continuous monitoring and alerting
  • No public database endpoints
Provider-specific cloud details may change over time and are documented in the Trust Center where applicable.

Privileged access management

  • Privileged and administrative access requires multi-factor authentication with role-based access control (RBAC)
  • Privileged access is logged, monitored, and reviewed
  • Access follows least-privilege principles, with just-in-time elevation where applicable

Vulnerability management and secure development

  • Regular independent vulnerability scanning with tracked remediation
  • Annual independent penetration testing
  • Automated threat detection and alerting across infrastructure and applications
  • Severity-based remediation timelines
  • Secure development practices including design reviews, code scanning, dependency checks, and secure API patterns
  • Regular security awareness training for staff

Incident notification

Linkup notifies affected clients within 72 hours of confirming a security incident that impacts client data, with 24-hour capability for critical incidents. Escalation procedures and response timelines are defined in Linkup’s Security Incident Management Policy.

Custom security requirements

On contracted plans, Linkup can accommodate custom breach notification timelines, tailored remediation SLAs, dedicated security reviews, and bespoke compliance reporting. Contact contact@linkup.so.

Bring Your Own Cloud (BYOC)

BYOC is available for selected high-tier partner deployments with strict data sovereignty requirements. In a BYOC deployment, the search index and processing run inside the customer’s environment, and queries do not leave that environment. BYOC is scoped on a case-by-case basis under custom agreements.