Skip to main content

    Security and trust

    Security evidence, controls and deployment boundaries.

    Review how Linkence protects connected data, limits access, handles model providers and verifies its security programme, with dates and scope attached.

    Independent testing · Dated controls · Contract-aware deployment

    Assurance status

    Current facts, not badge claims.

    In-progress work is labelled plainly and dated testing remains scoped to the assessment performed.

    Independent application security test

    VAPT completed 17 April 2026 by CodeTechLab.

    Point-in-time assessment of the tested scope, not a standing certification.
    VerifiedReviewed
    ISO 27001

    Certification programme underway.

    No certification badge or certificate is published while work is in progress.
    In progressReviewed
    SOC 2

    Assurance programme underway.

    No assurance report is represented as complete.
    In progressReviewed
    New tenant runtime

    New tenant deployments use isolated Linkence application and data stacks behind tenant-specific hostnames.

    The Linkence control plane continues to provide landing, tenant directory, billing and provisioning services during migration.
    VerifiedReviewed
    Deployment

    Managed SaaS is the standard public deployment. Customer-cloud or VPC delivery is scoped for selected enterprise engagements.

    Scope, security boundaries and operating responsibility must be agreed before deployment.
    Contract dependentReviewed

    Control ledger

    Controls tied to the path data takes.

    Encrypted connections and storage

    TLS protects supported service connections. Stored credentials use application-layer protection in the managed deployment.

    Permission-scoped retrieval

    Tenant and source permissions are enforced when connected content is retrieved and used.

    Policy-controlled actions

    Sensitive writes pause for review when the configured action policy requires approval.

    Isolated tenant runtime

    New tenant deployments use separate Linkence application and data stacks behind tenant-specific hostnames.

    Data path

    Seven inspectable stages from authorization to deletion.

    1. Step 1

      Connector authorization

    2. Step 2

      Encrypted credential storage

    3. Step 3

      Permission-scoped retrieval

    4. Step 4

      Controlled model request

    5. Step 5

      Response and evidence handling

    6. Step 6

      Action approval and result

    7. Step 7

      Audit and deletion lifecycle

    Providers and retention

    Model routing and subprocessors stay separate.

    Model providers generate responses under the configured route. The legal subprocessor register separately identifies entities that may process customer content.

    Model routing

    • OpenRouter may operate as the model gateway.
    • OpenAI, Anthropic and Google models may be available under configured routing.
    • Training, logging, retention and region claims are reviewed against the selected provider and contract.

    Retention and deletion

    • Connector disconnect and customer deletion requests begin active-system removal.
    • Backup, audit, billing and legal records follow their applicable retention schedules and exceptions.
    • Exact timelines must remain aligned with the Privacy Policy and customer terms.

    Independent testing

    The assessment date stays visible.

    CodeTechLab completed a vulnerability assessment and penetration test of the assessed Linkence application scope on 17 April 2026. This was a point-in-time assessment, not a standing certification.

    REVIEW SECURITY ON YOUR DATA

    Review the controls behind one real process.

    Bring the systems, data boundary and approval requirements your team needs to assess.