Security & Compliance
Your links, your data — protected by design.
Linkly is built privacy-first on Google Cloud and Cloudflare, with AES-256 encryption, GDPR-aligned data handling, and privacy-conscious analytics that 100,000+ marketing teams worldwide rely on every day.
Where we stand — stated plainly
No badge theatre: these are the frameworks and independent checks that actually apply to Linkly today.
Four pillars of Linkly security
Built on enterprise-grade cloud infrastructure, defended at the edge, and operated with a privacy-first mindset.
Encrypted everywhere
All data is encrypted at rest with AES-256 and rotating keys, and in transit with Google-managed TLS certificates. Account credentials are stored as one-way encrypted hashes.
Resilient infrastructure
Linkly runs on Google Cloud with automated database backups and deletion protection enabled at every level. Public short-link domains are served from Cloudflare's global edge.
Edge-layer defense
Cloudflare DDoS protection, bot mitigation and WAF rules front our public endpoints. Accounts engaged in DDoS or credential-stuffing activity are suspended on detection.
Privacy-first analytics
The analytics customers see contain no personally identifiable information. IP addresses are used to derive geolocation and ISP, held internally for security and abuse prevention only, and are never exposed to customers or included in exports.
GDPR-compliant, by a European company
Linkly is registered in England & Wales. Our data handling is built to satisfy European privacy expectations from day one.
What we do
- Appropriate transfer safeguards (UK–US DPF extension or SCCs) with all processors
- Signable Data Processing Agreement available on request
- A short, published sub-processor list — see the full table below
- Right to access, export and delete your data at any time
- Account data purged 30 days after account deletion
What we don't do
- Expose personally identifiable click data in analytics or exports
- Sell or rent customer data to third parties
- Use customer click data to train external ML models
- Mix customer data across tenants
- Give anyone outside Linkly access to raw IP data — internal, security-only use
Compliance posture
Where we stand today, and what we're actively working toward.
UK GDPR
UK-registered data controller (ICO ZC174597) with a signable DPA and a full data-subject-rights workflow.
PCI DSS (via Stripe)
All payment data is handled by Stripe — Linkly never sees or stores card numbers.
Anti-spam & abuse
Strict anti-spam policy with automated and manual review, plus rapid takedown of malicious links.
Transfer safeguards
International transfers rely on the UK–US Data Privacy Framework extension or Standard Contractual Clauses, per processor.
Independent pen test
Gray-box application and external network penetration test (October 2024); all findings remediated. Report available under NDA.
Signable DPA
A standard Data Processing Agreement is available on request for customers who need one countersigned.
Privacy-first analytics
Customer-facing analytics contain no personally identifiable data; raw IPs are internal-only, used solely for security and abuse prevention.
SOC 2 / ISO 27001
We're not SOC 2 or ISO 27001 certified, and we won't claim otherwise. Our controls are documented in a due-diligence pack available under NDA — we're happy to complete your security questionnaire.
Sub-processors
The handful of trusted vendors that help us deliver Linkly. We update this list whenever it changes.
| Vendor | Purpose |
|---|---|
| Google Cloud | Primary hosting, database (Cloud SQL), analytics (BigQuery) |
| Gigalixir | Application platform (runs on Google Cloud) |
| Cloudflare | CDN, DDoS protection, TLS for custom short-link domains |
| Stripe | Payment processing — card data never touches Linkly |
| Amazon SES | Transactional email delivery |
| Crisp | Customer support conversations |
| Google Analytics | Website analytics (marketing site) |
| Better Stack | Uptime monitoring and logging |
| Anthropic | AI-assisted admin and anti-abuse tooling |
| Vercel | Marketing website hosting (no customer data) |
Report a vulnerability
We take security disclosures seriously. If you've discovered a vulnerability or have a security question, our team will respond within one business day.
Frequently asked questions
Where is my data stored?+
Primary data is stored on Google Cloud, with automated backups and deletion protection enabled. Public short-link traffic is served from Cloudflare's global edge. If you have specific data residency requirements, contact our team and we can talk through options.
Do you sign DPAs?+
Yes. A standard Data Processing Agreement is available — see our DPA page or contact our team to countersign.
Do you support SSO?+
SAML single sign-on is not offered as standard today. We build enterprise capabilities like SSO on request as part of enterprise engagements — talk to sales about your requirements.
How long do you keep click data?+
Aggregated, anonymous click analytics are retained for 5 years by default. Account-level data is deleted 30 days after account closure.
How do I report a security issue?+
Email security@linklyhq.com. We acknowledge reports within one business day and work with reporters in good faith on disclosure.
Need more detail for your security review?
We're happy to walk through our architecture, complete vendor questionnaires, and provide our latest documentation under NDA.
Contact our security team