> ## Documentation Index
> Fetch the complete documentation index at: https://docs.linkup.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and compliance

> Security controls, certifications, encryption, access management, and vulnerability practices.

This page summarizes Linkup's security controls and compliance posture for security reviews.

<Card title="Trust Center" icon="shield" href="https://trust.linkup.so/" horizontal="True">
  SOC 2 Type II report and related compliance documentation.
</Card>

## Certifications and compliance

* **SOC 2 Type II**
* **ISO 27001**
* **HIPAA compliant**

## Configurable options

The following can be configured as needed:

* **Zero Data Retention (ZDR)** — available on request ([book a call](https://calendly.com/d/dtn3-wsq-5vn/book-a-demo))
* **Single Sign-On (SSO)** — enterprise
* **Guaranteed local query processing** — enterprise
* **Multi-routing across geographies** — enterprise
* **IP whitelisting** and role-based access configurations — enterprise

Contact `contact@linkup.so` for configuration details.

## Encryption and key management

* **In transit**: TLS 1.2+ for all API communications
* **At rest**: AES-256 for stored data
* **Key management**: centrally managed with restricted access

## Infrastructure security

* Network segmentation and multi-layer traffic controls
* Hardened service baselines and patch management
* Continuous monitoring and alerting
* No public database endpoints

Provider-specific cloud details may change over time and are documented in the Trust Center where applicable.

## Privileged access management

* Privileged and administrative access requires multi-factor authentication with role-based access control (RBAC)
* Privileged access is logged, monitored, and reviewed
* Access follows least-privilege principles, with just-in-time elevation where applicable

## Vulnerability management and secure development

* Regular independent vulnerability scanning with tracked remediation
* Annual independent penetration testing
* Automated threat detection and alerting across infrastructure and applications
* Severity-based remediation timelines
* Secure development practices including design reviews, code scanning, dependency checks, and secure API patterns
* Regular security awareness training for staff

## Incident notification

Linkup notifies affected clients within 72 hours of confirming a security incident that impacts client data, with 24-hour capability for critical incidents. Escalation procedures and response timelines are defined in Linkup's Security Incident Management Policy.

## Custom security requirements

On contracted plans, Linkup can accommodate custom breach notification timelines, tailored remediation SLAs, dedicated security reviews, and bespoke compliance reporting. Contact `contact@linkup.so`.

## Bring Your Own Cloud (BYOC)

BYOC is available for selected high-tier partner deployments with strict data sovereignty requirements. In a BYOC deployment, the search index and processing run inside the customer's environment, and queries do not leave that environment. BYOC is scoped on a case-by-case basis under custom agreements.
