Security you can build a business on.
Lynkist handles your customers’ conversations — so protecting that data is foundational, not an afterthought. Here is exactly how we keep your workspace, your customers, and your business safe.
Tenant isolation by design
Every workspace gets its own isolated database schema. Your contacts, conversations, templates, and campaigns are never co-mingled with another customer’s data — isolation is enforced at the data layer, not just in application code.
Encryption in transit
All traffic to Lynkist — the dashboard, the public API, and webhooks — is served exclusively over TLS (HTTPS). Credentials and access tokens are never transmitted in clear text.
Scoped API keys
API access uses keys you create and revoke yourself. Keys are shown once at creation, stored as one-way hashes, and can be rotated at any time without downtime. Webhook payloads are signed so you can verify they came from Lynkist.
Role-based access
Invite teammates with the least privilege they need. Roles control who can send campaigns, manage billing, edit templates, or administer the workspace — so day-to-day agents never touch sensitive settings.
Official WhatsApp Business API
Lynkist connects through Meta’s official WhatsApp Business Platform. Messages flow through Meta’s end-to-end encrypted infrastructure — we never use unofficial or grey-route gateways that put your number at risk.
Payments stay with the processor
Card and payment details are handled directly by our PCI-DSS compliant payment partners. Lynkist never stores raw card numbers — we only keep the tokens and metadata needed to manage your subscription.
Audit logging
Sensitive actions — sign-ins, API key creation, member and role changes, data exports, and billing events — are recorded with the teammate who did it, when, and what changed. Admins can read the full activity log in Settings, and it is kept for 365 days.
Isolated cloud infrastructure
Lynkist runs on managed Kubernetes in Oracle Cloud. Public traffic terminates TLS at the load balancer, and the database and cache are reachable only from inside the cluster — never from the public internet. Storage volumes are encrypted at rest by the cloud provider.
Data ownership & control
Your data is yours. You can export your contacts and conversation history, and you can delete your workspace at any time. When you delete an account, we remove your workspace data on the schedule described in our Privacy Policy, subject to any legal retention we are required to honour.
Where we are today
We would rather be specific than impressive. Everything described on this page is in place today. We are equally clear about what is not: we hold no formal certification yet, we do not publish a live status page, and we have not completed a third-party penetration test. Platform alerting is live — on-call is paged on error-rate, availability and certificate-expiry conditions. Off-site database backups are still being built out. We will list things here when they ship, not before.
If you need a vendor security questionnaire or DPA completed today, our team is happy to work through it with you directly — including the parts still on our roadmap.
Responsible disclosure
Found a vulnerability? We want to hear about it. Report it privately to security@lynkist.io and give us a reasonable window to investigate and fix before any public disclosure. We will not pursue action against good-faith researchers who follow this process.
