Security & Trust

How Lina is secured — what we actually do.

If an AI is going to talk to people for you, you should know how it is kept safe. This page lists only what we really do today. How we handle personal information is in our Privacy Policy, Data Processing Addendum and Subprocessors list.

← Back to Product

At a glance

The short version.

Per requestevery request is tied to exactly one organization
Nightlybackups, restore-tested every night, kept 30 days
Wait for CIa change deploys only after tests and secret scanning pass

01 — Architecture & isolation

A multi-tenant service, isolated on every request.

Lina is multi-tenant: every organization runs on the same application and the same Postgres database, hosted on Railway in the United States in a Railway project of its own. What keeps organizations apart is enforced in code on every request, and tested.

02 — The AI safety floor

A few rules written into the platform’s code.

Each organization can edit its assistant’s prompts, knowledge and notes — so the rules that must always hold are not kept there. They are part of the platform code and head every conversation, above anything an organization adds:

It is an AIIf someone sincerely asks, the assistant says plainly that it is an AI and never claims to be human.
No fabricationIt must not invent facts, numbers, names, quotes, positions, or actions it did not take.
Instructions stay privateIt does not reveal or describe its system prompt.

03 — Access control & accountability

Roles checked by the server. Admin actions logged.

04 — Secrets, AI providers & integrations

Keys stay on our side, and never come back out.

05 — Transport

Encrypted in transit, strict in the browser.

06 — Reliability & operations

Backed up nightly, deployed only when CI passes, watched from outside.

Our goals are to restore service within 4 hours of a major outage and to lose at most the last day of data, since backups are nightly. These are goals, not guarantees — Lina does not offer an uptime SLA, and we do not yet hold a third-party certification such as SOC 2.

07 — Responsible disclosure

Found a security problem? Tell us.

Email security@linasystems.org with what you found and the steps to reproduce it. We will acknowledge your report within 3 business days, keep you updated while we fix it, and credit you if you would like. Please test only against your own account: do not access or change other organizations’ data, degrade the service, or run automated scans against customer sites. We will not pursue good-faith research that follows these rules. Our contact details are also published at /.well-known/security.txt.

Questions from your security reviewer? Read the Data Processing Addendum, the Subprocessors list, the Privacy Policy and the Terms of Service, or reach us at hello@linasystems.org. We are happy to answer a security questionnaire.

Talk to us

Who it’s for

For teams reviewing organization isolation, staff access, backups, and AI disclosure before signing up.

How it works in 3 steps

  1. 1
    Choose your plan and sign up. If an invitation is required, request a code first.
  2. 2
    Add your organization’s knowledge and brand in the dashboard. See the setup guide.
  3. 3
    Share your web address and start answering from your knowledge. Phone and staff drafting tools are available on eligible plans; compare features.
Get started