Enterprise security

Sensitive process data, protected by design.

Linc protects operational knowledge for regulated industries from capture through deployment—with privacy, isolation, encryption, and governance built into the architecture.

Security commitments

Three principles anchor every architectural decision.

Layered data isolation

Projects are separated across object storage, database queries, vector namespaces, background workers, and agent workspaces.

PII/PHI protection by default

Automated detection and redaction runs before content reaches any generative AI model, including permanent video blurring.

Zero AI training exposure

Customer content is never used to train AI models. Provider agreements prohibit retention, reuse, and training.

Need full data sovereignty?Run every component on your infrastructure so customer data never leaves your network.
Data protection

Raw identity data never reaches a generative model.

Every data flow enforces redaction before content reaches an external AI service.

01

Upload

Documents, audio, video, and recordings enter over HTTPS.

02

Encrypted storage

Original files remain encrypted at rest in isolated storage.

03

PII/PHI redaction

Names, IDs, health data, and other sensitive entities are detected and replaced.

04

Redacted context

Models receive tokenized text or permanently blurred video—not raw identity data.

05

AI analysis

Linc generates process maps, SOPs, opportunities, and transformation insights.

Sanitized contextModels receive
  • PII/PHI-redacted text
  • Permanently blurred video
  • Opaque tokens instead of real identifiers
Protected source dataModels never receive
  • Unredacted personal data or PHI
  • Original recordings or raw files
  • Database contents or user identities
Encryption architecture

Three layers protect data at every stage.

In transitTLS 1.2+

HSTS enforcement, disabled legacy protocols, certificate verification, and server-to-server provider calls.

At restAES-256

Databases, object storage, vector stores, and task queues use encrypted storage with managed key rotation.

Sensitive fieldsAES-256-GCM

Per-organization keys protect sensitive columns, OAuth tokens, and PII vault entries.

Identity & accountability

Access is scoped. Every sensitive action is traceable.

Enterprise identity & RBAC

  • Microsoft Entra ID and Google Workspace OIDC SSO
  • SAML 2.0 and additional OIDC providers for self-hosted deployments
  • MFA and conditional-access policies enforced through your identity provider
  • Organization-scoped roles for admins, members, viewers, and auditors

Append-only audit trail

  • Authentication and failed access attempts
  • File upload, download, deletion, and viewing
  • PII detections, redaction policy changes, and vault access
  • Role changes, invitations, settings, and administrative actions

Audit records are organization-scoped, tamper-resistant, and exportable to CSV or JSON for your SIEM.

Deployment flexibility

Match the deployment to your risk profile.

Use Linc’s managed environment or run the complete platform inside infrastructure you control.

Managed SaaS

We manage the infrastructure. You control the data lifecycle.

  • Hosted on AWS in the United States
  • AES-256 at rest and TLS 1.2+ in transit
  • PII/PHI redacted before model calls
  • Full tenant isolation and managed maintenance

Self-hosted / on-prem

Everything runs on your infrastructure and inside your boundary.

  • Kubernetes or Docker deployment
  • Your Azure OpenAI, AWS Bedrock, or Vertex AI endpoint
  • No telemetry, phone-home, or shared infrastructure
  • Air-gapped deployment and local models available
  • Full control over residency and retention
Compliance posture

Designed for regulated enterprise environments.

Current safeguards, independently verified controls, and a transparent roadmap for formal certification.

HIPAA
Safeguards in place · BAA available
SOC 2 Type II
Architecture aligned · audit in progress
GDPR
DPA and SCCs in place
Independent penetration test
Verified June 2026
NIST 800-53
Controls aligned
ISO 27001 / 42001
Roadmap
0reportable security incidents
0critical/high pen-test findings
AES-256encryption standard
1 hrcritical response SLA

Bring your security team into the conversation early.

We can walk through architecture, data flows, provider controls, deployment options, DPAs, BAAs, and the documentation your review requires.

Schedule a security review