Security
How the LynkSuite products protect your organization's data. Last updated: August 2026
One Platform, One Posture
LynkPilot, LynkLearn, and LynkCrew run on one platform built by LynkPilot, Inc. That means one security posture, reviewed continuously, applies to all three products. This page describes the controls and practices we maintain across the suite.
Infrastructure Security
The platform runs on enterprise-grade cloud infrastructure with established security certifications and global availability. We build on major cloud providers that maintain SOC 2 compliance, physical security standards, and incident response capabilities. We do not operate our own data centers; we rely on providers whose security posture is independently audited.
Data Encryption
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted at the storage layer by our infrastructure providers. Sensitive HR fields such as compensation carry an additional layer of application-level encryption. Files and documents uploaded to the platform are stored with encryption at rest and are only accessible via time-limited, authenticated download links.
Authentication & Access
Authentication is handled by a dedicated identity platform that supports multi-factor authentication (MFA), secure session management, and credential protection. We do not store or handle raw passwords. One account works across all three products, which also means one place to secure it and one switch to revoke it.
Within the platform, access is controlled by role-based permissions. Users can only access data and actions appropriate to their assigned role. Organization data is strictly isolated: users from one organization cannot access another organization's data under any circumstances.
Internal Access Controls
Access to production systems is restricted to authorized personnel only, following the principle of least privilege. No broad standing access to customer data is granted, internal access is reviewed periodically, and administrative actions are logged for accountability.
Monitoring & Incident Response
Our infrastructure is monitored continuously for anomalies, errors, and availability, with alerting for unexpected access patterns and system health degradation. In the event of a confirmed security incident affecting customer data, we will notify affected organizations promptly with clear information on scope, impact, and remediation.
Data Backups
Customer data is backed up automatically by our infrastructure providers, with backups retained and encrypted. Data durability is a core infrastructure requirement across the suite.
Rate Limiting & Abuse Prevention
The platform enforces rate limits on authentication attempts, API requests, and sensitive operations to protect against brute-force and abuse. File uploads are validated for type and size before being accepted.
Vulnerability Disclosure
If you discover a potential security issue in any LynkSuite product, please report it responsibly to support@lynkpilot.com. We will acknowledge your report within 2 business days and work to resolve confirmed issues promptly. We ask that you do not publicly disclose issues before we have had a reasonable opportunity to address them.