Security and trust

    Security built into every layer

    Linkence connects to sensitive systems, so trust is the product.

    Talk to the team

    Independent security testing

    Independent VAPT completed · April 2026 · CodeTechLab

    • Web application vulnerability assessment and penetration testing of linkence.ai, conducted 17 April 2026 by CodeTechLab (certificate CTL-17042026-02).
    • No critical vulnerabilities were identified; the application was assessed as suitable for production deployment.
    • VAPT is a point-in-time assessment, not a standing certification. Findings after 17 April 2026 fall outside the assessment scope, and we plan to re-test periodically.
    Request the executive report under NDA

    Compliance roadmap

    ISO 27001In progress
    SOC 2In progress

    We will publish the certificates and report scopes here once each audit completes.

    Company facts: Linkence Private Limited is DPIIT recognized (Government of India startup recognition) and registered in Bhavnagar, Gujarat, India. DPIIT recognition is a company credential, not a security attestation.

    Encryption, exactly scoped

    • In transit: TLS 1.2 or higher for every connection, with TLS 1.3 preferred where the client supports it.
    • At rest: AES-256 storage encryption on the primary database and file stores.
    • Credentials: connector OAuth tokens and API keys are sealed with AES-256-GCM application-layer encryption before they touch storage.
    • Key management: encryption keys are held in environment-scoped secrets, separate from the data they protect, and can be rotated without downtime.

    Access and governance

    • Role-based access control across every workspace.
    • Granular, per-connector permissions with per-tenant data isolation.
    • Permission-aware retrieval respects each source system's access controls.
    • Human-in-the-loop approval on every external write action.
    • Your data is never used to train models. Provider-side retention is disabled wherever the provider supports it.

    Deletion matrix

    What happens to your data when you disconnect a source or ask for deletion.

    DataTimelineDetail
    Connector disconnect or deletion requestImmediateContent is removed from the active index and primary stores as part of the disconnect flow.
    Encrypted backupsWithin 30 daysDeleted data ages out of rolling, encrypted backups on the standard expiry cycle.
    Audit records30 to 90 daysRetention depends on plan. Audit records are kept for accountability, then expire.

    Model providers

    Prompts and retrieved snippets are sent to these providers to generate responses. None of them train on our API traffic, and enterprise customers can bring their own model keys for full control.

    ProviderRoleTraining policyRetentionRegion
    OpenRouterModel gatewayNot used for trainingPrompt logging disabledUnited States
    OpenAIModel providerAPI data not used for trainingProvider abuse-monitoring window, then deletedUnited States
    AnthropicModel providerAPI data not used for trainingProvider abuse-monitoring window, then deletedUnited States
    GoogleModel providerPaid API data not used for trainingProvider abuse-monitoring window, then deletedUnited States

    Deployment options

    • Managed SaaS, hosted and operated by Linkence. This is the standard offering, available today.
    • Customer-cloud or VPC deployment is offered on enterprise engagements: the stack is containerized, and scope, timelines, and operations are agreed per contract before we commit.
    • Bring your own model keys to route inference through your own provider accounts.

    Reporting and incident response

    Vulnerability reports

    Email soham@linkence.ai with the subject "Security vulnerability report". We acknowledge reports within 2 business days and keep you informed through remediation.

    Incident response

    If a breach affects customer data, we notify affected customers without undue delay and supervisory authorities where required by law, within 72 hours where GDPR applies.

    Data Processing Agreement

    Our DPA covers processing roles, subprocessors, transfers, and deletion. Request the DPA and we send the signable document the same business day.

    Running a vendor review?

    Download the security overview to share internally, or email soham@linkence.ai and we will help with questionnaires, the DPA, and deployment questions.