Trust & Security
Security you can trust
Your data is encrypted, isolated, and never used for AI training. Built on Google Cloud with healthcare privacy at the core.
AES-256 — Encryption at rest
TLS 1.3 — Encryption in transit
HIPAA — Conscious design
Zero — AI training on your data
How we protect your data
Every layer of Linkd is designed with security and privacy in mind.
1.1 Data Encryption
All data is encrypted using industry-standard algorithms at rest and in transit.
At rest — AES-256-GCM via Google Cloud
In transit — TLS 1.3 with forward secrecy
Deletion — Secure deletion via Google Cloud
1.2 Rate Limiting
Configurable per-agent rate limits protect against abuse. Set max messages per time window with custom messaging.
1.3 Tenant Isolation
Every organization's data is logically isolated. No clinic can access another clinic's data, conversations, or settings.
1.4 Access Controls
Role-based permissions, MFA support via Clerk, session timeouts, and email-based OTP verification for staff access.
Your data never trains AI
Conversations disappear by default
When a session ends it's gone. No database, no record, no trace. Nothing is ever stored unless you choose it.
No selling, ever
Your data is never sold, rented, shared, or monetized. It exists solely to power your chatbot.
You own your data
Export or permanently delete all your data at any time from your dashboard. Deletion completed within 30 days.
Conversation history — your choice
Conversations are never stored by default. If you choose to enable conversation history, sensitive information is automatically detected and removed before anything reaches storage. All logs permanently delete after 30 days.
Signed agreements across the entire data chain
Google Cloud, OpenAI, and Clerk all operate under signed HIPAA Business Associate Agreements. Every subprocessor that touches your data is contractually bound to protect it.
Infrastructure
Built on Google Cloud Platform — the same infrastructure trusted by healthcare organizations worldwide.
Google Cloud Platform
- Google Cloud holds SOC 2, ISO 27001, ISO 27017, and ISO 27018 certifications covering the infrastructure Linkd runs on
- HIPAA-eligible infrastructure with BAA signed
- Physical security — 24/7 guards, biometric access
- Redundant power, cooling, fire suppression
Pinecone
Vector database for knowledge base search. Stores mathematical representations of Customer Content only. No patient or conversation data.
Data Residency
All data stored in Google Cloud US regions by default. Canadian and UK customers are covered under appropriate data transfer agreements including PIPEDA adequacy and UK IDTA clauses.
Compliance
Designed for regulated industries. Documentation available upon request.
HIPAA-Conscious Design — Active
Technical safeguards aligned with 45 CFR § 164.312. Business Associate Agreement included at signup for all plans. No separate request needed.
PHIPA Support (Ontario) — Supported
Agent Agreement available for Ontario healthcare providers. Breach notification per PHIPA requirements.
UK GDPR — Supported
Data Processing Agreement with UK International Data Transfer Addendum available. ICO-aligned data handling for all UK customers.
GDPR (EU/EEA) — Supported
Data Processing Agreement with Standard Contractual Clauses available. Data subject rights assistance and subprocessor transparency.
Quebec Law 25 — Supported
Explicit consent mechanisms, 72-hour breach notification to CAI, privacy impact assessment support for Quebec customers.
Documentation available
- Business Associate Agreement (BAA) — included at signup
- Data Processing Agreement (DPA)
- Security questionnaire responses
- Vendor risk assessment
- Incident response procedures
- Attestation letters
Shared responsibility
Security is a partnership between Linkd and our customers.
Linkd secures the platform
- Infrastructure and application security
- Data encryption at rest and in transit
- Access controls and authentication
- Monitoring and incident response
- Backup and availability
- Compliance documentation
You control your content
- What content is uploaded and published
- Who has access and user permissions
- Public vs. private chatbot settings
- Compliance with your own regulations
- Staff training and appropriate use
- Obtaining necessary patient consents
Incident response
In the unlikely event of a security incident, we respond swiftly and transparently.
15 min — Detection. Our team identifies and triages security events.
1 hour — Assessment. Severity classification and scope determination.
4 hours — Containment. Stop unauthorized access, preserve evidence.
24 hours — Notification. Notify affected customers with full details.
7 days — Remediation. Fix vulnerability, verify resolution, update controls.
Breach notification: Affected customers within 24 hours. Regulatory authorities per jurisdiction — HIPAA: 60 days, GDPR: 72 hours, UK GDPR: 72 hours, PHIPA: without undue delay, Quebec Law 25: 72 hours.
Security incidents to date: 0
Responsible disclosure
Found a security issue? We welcome responsible disclosure. Email us and we commit to:
Acknowledgment — Within 24 hours
Status updates — Every 5 business days
Critical fixes — Within 7 days
No legal action against good-faith security researchers.
Have security questions?
For compliance documentation, BAA requests, vulnerability reports, or questions about how we protect your data.