Trust Center

Security & Compliance

Your links, your data — protected by design.

Linkly is built privacy-first on Google Cloud and Cloudflare, with AES-256 encryption, GDPR-aligned data handling, and privacy-conscious analytics that 100,000+ marketing teams worldwide rely on every day.

AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
2024
Independent penetration test
ZC174597
UK ICO registration
Standards & assurance

Where we stand — stated plainly

No badge theatre: these are the frameworks and independent checks that actually apply to Linkly today.

UK GDPR
UK-registered data controller, ICO reference ZC174597
Pen tested
Independent application & network test, October 2024 — all findings remediated
PCI DSS
All card data handled by Stripe (PCI DSS Level 1) — it never touches Linkly
Data transfers
UK–US Data Privacy Framework extension or SCCs with our processors
How we protect you

Four pillars of Linkly security

Built on enterprise-grade cloud infrastructure, defended at the edge, and operated with a privacy-first mindset.

Encrypted everywhere

All data is encrypted at rest with AES-256 and rotating keys, and in transit with Google-managed TLS certificates. Account credentials are stored as one-way encrypted hashes.

Resilient infrastructure

Linkly runs on Google Cloud with automated database backups and deletion protection enabled at every level. Public short-link domains are served from Cloudflare's global edge.

Edge-layer defense

Cloudflare DDoS protection, bot mitigation and WAF rules front our public endpoints. Accounts engaged in DDoS or credential-stuffing activity are suspended on detection.

Privacy-first analytics

The analytics customers see contain no personally identifiable information. IP addresses are used to derive geolocation and ISP, held internally for security and abuse prevention only, and are never exposed to customers or included in exports.

Data & Privacy

GDPR-compliant, by a European company

Linkly is registered in England & Wales. Our data handling is built to satisfy European privacy expectations from day one.

What we do

  • Appropriate transfer safeguards (UK–US DPF extension or SCCs) with all processors
  • Signable Data Processing Agreement available on request
  • A short, published sub-processor list — see the full table below
  • Right to access, export and delete your data at any time
  • Account data purged 30 days after account deletion

What we don't do

  • Expose personally identifiable click data in analytics or exports
  • Sell or rent customer data to third parties
  • Use customer click data to train external ML models
  • Mix customer data across tenants
  • Give anyone outside Linkly access to raw IP data — internal, security-only use
Compliance

Compliance posture

Where we stand today, and what we're actively working toward.

Today

UK GDPR

UK-registered data controller (ICO ZC174597) with a signable DPA and a full data-subject-rights workflow.

Today

PCI DSS (via Stripe)

All payment data is handled by Stripe — Linkly never sees or stores card numbers.

Today

Anti-spam & abuse

Strict anti-spam policy with automated and manual review, plus rapid takedown of malicious links.

Today

Transfer safeguards

International transfers rely on the UK–US Data Privacy Framework extension or Standard Contractual Clauses, per processor.

Today

Independent pen test

Gray-box application and external network penetration test (October 2024); all findings remediated. Report available under NDA.

Today

Signable DPA

A standard Data Processing Agreement is available on request for customers who need one countersigned.

Today

Privacy-first analytics

Customer-facing analytics contain no personally identifiable data; raw IPs are internal-only, used solely for security and abuse prevention.

Not yet certified

SOC 2 / ISO 27001

We're not SOC 2 or ISO 27001 certified, and we won't claim otherwise. Our controls are documented in a due-diligence pack available under NDA — we're happy to complete your security questionnaire.

Transparency

Sub-processors

The handful of trusted vendors that help us deliver Linkly. We update this list whenever it changes.

VendorPurpose
Google CloudPrimary hosting, database (Cloud SQL), analytics (BigQuery)
GigalixirApplication platform (runs on Google Cloud)
CloudflareCDN, DDoS protection, TLS for custom short-link domains
StripePayment processing — card data never touches Linkly
Amazon SESTransactional email delivery
CrispCustomer support conversations
Google AnalyticsWebsite analytics (marketing site)
Better StackUptime monitoring and logging
AnthropicAI-assisted admin and anti-abuse tooling
VercelMarketing website hosting (no customer data)

Report a vulnerability

We take security disclosures seriously. If you've discovered a vulnerability or have a security question, our team will respond within one business day.

FAQ

Frequently asked questions

Where is my data stored?+

Primary data is stored on Google Cloud, with automated backups and deletion protection enabled. Public short-link traffic is served from Cloudflare's global edge. If you have specific data residency requirements, contact our team and we can talk through options.

Do you sign DPAs?+

Yes. A standard Data Processing Agreement is available — see our DPA page or contact our team to countersign.

Do you support SSO?+

SAML single sign-on is not offered as standard today. We build enterprise capabilities like SSO on request as part of enterprise engagements — talk to sales about your requirements.

How long do you keep click data?+

Aggregated, anonymous click analytics are retained for 5 years by default. Account-level data is deleted 30 days after account closure.

How do I report a security issue?+

Email security@linklyhq.com. We acknowledge reports within one business day and work with reporters in good faith on disclosure.

Need more detail for your security review?

We're happy to walk through our architecture, complete vendor questionnaires, and provide our latest documentation under NDA.

Contact our security team