Private communication, without the exposure.

LINK is a closed-source, invitation-only platform for organisations that handle sensitive communication. Safeguarding and privacy are built in — no leaked phone numbers, no exposed email addresses, no shared contact details.

Access is reviewed and granted on approval.

A calm workspace with a laptop and notebook
No exposed contact details
Consent-gated identity
Reviewed on approval

The problem we solve

Open messengers and email weren't designed for safeguarding.

Organisations responsible for vulnerable people need more than encryption. They need controlled identity, controlled access, and an accountable record of every action.

Contact details leak

Email threads and consumer messengers expose personal phone numbers and addresses to anyone in the conversation — and to anyone they later forward it to.

Identities are exposed by default

There is no consent gate on who sees what. A single reply-all, a screenshot, or a stolen device can reveal who someone is to people they never intended.

No oversight, no audit trail

Sensitive decisions happen in private inboxes with no record, no second pair of eyes, and no way to review what was said when something goes wrong.

Abstract rounded cards floating on a soft background
The platform

A closed-source, proprietary platform — not a public app.

LINK is not on a public app store. It is not open source. There is no anonymous sign-up. Access is provisioned by approved administrators inside each organisation we work with.

This controlled model is intentional. By keeping the platform closed and the user base vetted, LINK supports a level of identity assurance, oversight, and safeguarding that an open network simply cannot.

Controlled access is the feature, not a limitation.

Distribution
Provisioned only
Onboarding
Approved admin
Identity
Verified in-org
Notifications
In-app only

Safeguards

Privacy and oversight, built into the platform.

Each of these controls is part of LINK by default. There is nothing to enable, nothing to configure, and nothing for an end user to accidentally turn off.

No exposed contact details

Users communicate without ever revealing their phone number or email. Personal contact data is never shared, displayed, or harvested.

Consent-gated identity reveal

A person's identity is only revealed with their explicit consent. Requests expire after 72 hours and auto-decline if not accepted.

Dual-administrator override

Sensitive actions require two administrators, preventing any single person from acting unilaterally on another user's account or data.

Immutable audit trail

Every action is logged in a tamper-evident record so organisations have accountability and a complete history for review.

In-app-only notifications

Alerts stay inside the platform. Nothing is pushed to personal email or SMS where it could leak, be forwarded, or be intercepted.

Privacy upgrades built in

Data minimisation, controlled access, and privacy protections are integrated into the platform — not bolted on after the fact.

How access works

Reviewed and granted on approval. Always.

We review every request and grant access on a case-by-case basis. There is no instant sign-up and no automatic approval.

  1. Submit a request

    Tell us about your organisation, your role, and how you intend to use LINK. There is no public sign-up — every applicant starts here.

  2. We review

    Our team assesses each request individually for suitability and safeguarding fit. Approval is discretionary and made case by case.

  3. Access granted on approval

    Approved organisations are provisioned and onboarded by our team. We respond to every request, whether approved or declined.