最終更新 · 24 August 2026

セキュリティとコンプライアンス

現時点のLINKの状況を率直に示します。導入済みの項目、進行中の項目、未提供の項目を明記し、正確に評価いただけるようにしています。

本ページは英語で公開されています。本サイトの翻訳は参考用であり、法的効力を持つのは英語版です。

Compliance status — current and honest

We do not currently hold a SOC 2 Type II attestation, a HIPAA certification (no such certification exists), or an ISO 27001 certificate. LINK is designed to support the control objectives associated with SOC 2, HIPAA and FERPA, and independent penetration testing and audit work is planned. We will publish reports here when they exist. Any claim on this site that is not backed by a report is described as a design goal, not an achieved certification.

Agreements available to regulated customers

  • Data Processing Agreement (DPA) with EU Standard Contractual Clauses and the UK International Data Transfer Addendum, for customers transferring EEA or UK personal data.
  • Business Associate Agreement (BAA) — available on request for healthcare customers. LINK must not be used to process protected health information until a BAA is signed.
  • FERPA data agreement — available on request for educational institutions, designating LINK as a school official with a legitimate educational interest.

Request any of these from compliance@linkprivacy.app.

Subprocessors

  • Supabase — application database hosting.
  • Cloudflare — edge hosting and content delivery for this website.
  • Lovable — build and deployment platform for this website.

We will give customers advance notice of any new subprocessor and the opportunity to object, as set out in the DPA.

Data location and transfers

Website application data is stored in our managed database. Customers with EEA or UK data residency requirements can request the current hosting region in writing before signing; cross-border transfers are covered by the SCCs and UK IDTA annexed to the DPA.

Client and device security commitments

  • Push notifications: APNs and FCM payloads are contentless. No message text, sender name, group name or attachment metadata is sent through Apple or Google servers; the notification is a wake signal and content is decrypted on the device.
  • One-time access codes: codes expire after a short, fixed window, are single-use, and are bound to a limited number of attempts. Exceeding the attempt limit invalidates the code and locks further attempts from that origin. Codes are never reusable and never recoverable after expiry.
  • Local storage: message data held on a device is encrypted at rest with keys held in the platform secure enclave or keystore. The local database is excluded from iCloud and Google Drive backups, so no unencrypted message cache leaves the device.
  • Authentication: accounts are provisioned by an administrator, sessions expire and can be revoked centrally, and authentication endpoints are rate limited. Secrets are stored hashed; we never store recoverable passwords or access codes.

These are the commitments we contract to. Where a control is a design goal rather than an independently verified one, it is described as such in the compliance status above.

Breach notification

We commit contractually to notifying affected customers of a personal data breach without undue delay and within 72 hours of becoming aware of it, including the nature of the breach, likely consequences and remediation steps taken.

Reporting a vulnerability

Email security@linkprivacy.app. We aim to acknowledge within two business days. Please do not test against production data or access data belonging to others; we will not pursue good-faith research that follows this guidance.

Contact compliance

Procurement, security questionnaires, DPAs, BAAs and FERPA agreements: compliance@linkprivacy.app. Privacy and data subject requests: privacy@linkprivacy.app.