Home/Platform/Security

Platform security

The safest patient data is the kind we never see.

An integration engine moves the whole patient record before anyone has redacted it. So Grid is built so that we never see it. Our engineers diagnose from structure, metadata and error codes. Here is exactly what we do, what we've certified, and what we haven't.

In progress

SOC 2 Type II

Gap assessment complete, controls implemented, observation window running with an independent auditor.

Aligned · BAA ready

HIPAA

Administrative, physical and technical safeguards mapped to the Security Rule. We sign BAAs.

Aligned

PIPEDA & PHIPA

Canadian federal and Ontario health privacy law. Grid runs in your infrastructure, so your data stays where you put it.

By design

We never see PHI

Our engineers diagnose from structure, metadata and error codes. We don't ask for patient data, and we advise you not to send it, to us or to anyone.

We'd rather lose a deal on a checkbox than win one on a misleading badge. Every claim on this page can be evidenced on request.

Compliance status

Where each framework actually stands.

Updated as things change, not as things are hoped for.

FrameworkStatusWhat that means for you
SOC 2 Type II
Security, Availability, Confidentiality
Observation windowControls are live and being tested by an independent auditor. We can share the readiness assessment and control matrix under NDA today, and the report when issued.
HIPAAAligned · BAAControls mapped to 45 CFR §164 Subparts C and E. We execute Business Associate Agreements as a matter of course, not as an escalation.
PIPEDAAlignedCanadian federal private-sector privacy law. Consent, accountability, safeguards and breach reporting practices documented.
PHIPA (Ontario)AlignedWe operate as a service provider / agent to health information custodians, with the logging and access records that role requires.
GDPR / UK GDPRDPA availableStandard Contractual Clauses and a Data Processing Addendum available for EU and UK deployments.
Penetration testAnnual, third partyIndependent external test at least annually plus after any material architecture change. Executive summary shared under NDA.
Controls

What protects the message.

Encryption

  • TLS 1.2 minimum in transit, TLS 1.3 preferred; mTLS available on any HTTPS node
  • AES-256 at rest for message archives, configuration and backups
  • Customer-managed keys via AWS KMS, Azure Key Vault or GCP KMS
  • Secrets held in a vault, never in workflow config or Lua source
  • MLLP over TLS for legacy HL7 links that will accept it, and honest advice when they won't

Access control

  • Role-based access scoped to project, workflow and action
  • MFA enforced for every console user, no exceptions for admins
  • SAML 2.0 SSO and SCIM provisioning, included
  • Message-body viewing is a separate permission from operating a workflow
  • Break-glass access is time-boxed, approved, and loudly logged

Auditability

  • Append-only audit log of every login, config change, replay and message view
  • Message archive with configurable retention and legal hold
  • Export to your SIEM: Splunk, Sentinel, Elastic, S3
  • Agent actions carry a signed record of proposal, approver and outcome
  • PHI masking in logs on by default, so our engineers work from structure rather than patient data

Network & infrastructure

  • Private networking by default; no public ingress unless you ask for it
  • VPN, PrivateLink / Private Endpoint or site-to-site tunnels to on-prem
  • Nothing is multi-tenant: your deployment is yours, and no message store is shared
  • Grid runs in your infrastructure, so your data never leaves it
  • Fully air-gapped installs supported for customers who need them

Product security

  • Peer review required on every change; no direct commits to release branches
  • Dependency and container scanning in CI, with an SBOM per release
  • Lua transforms execute sandboxed, without host filesystem or shell access
  • Signed release artifacts and reproducible container images
  • Responsible disclosure welcome, with a reply from an engineer

security@linkiir.com

Resilience

  • Active/active high-availability topology with automatic failover
  • Message-level durability: nothing is acknowledged until it is persisted
  • Encrypted backups, with restores tested rather than assumed
Questions we get asked

Security FAQ

Will you sign a BAA?

Yes, as standard, wherever Grid handles protected health information. We'll also sign a DPA with Standard Contractual Clauses for EU and UK data, and we don't treat either as a negotiation of last resort.

Can we keep everything inside our own cloud tenancy?

Yes. Managed-in-your-cloud runs Grid in your AWS, Azure or GCP account: you own the keys, the network boundary and the data, and our engineers operate it under scoped, audited, time-boxed access. Fully air-gapped installations are supported too, with offline licensing and update bundles.

Does Linkiir staff see our PHI?

No. Our engineers work from message structure, metadata, headers and error codes, never patient data, and the support model is designed so that reading a record is never the path to a fix. PHI masking is on by default.

We also don't want you to send it to us. If a diagnosis seems to need a real message, de-identify it first; if you share PHI anyway, we'd rather tell you plainly that you shouldn't have. Nothing about the way we support you depends on you handing over patient data.

How long do you retain messages?

You set it, per project. The default is 90 days of full message archive plus 13 months of metadata, and both are configurable up or down. Legal hold suspends deletion for a named scope. Deletion is verified, not just scheduled.

What happens to our data if we leave?

You get a full export of workflows, transforms, schemas, variables and the message archive, in open formats, plus 30 days to verify it. Then we delete, and confirm the deletion in writing. Your Lua transforms and schemas are yours; there is no licence trap on the artifacts you built.

Do you use customer data or PHI to train AI models?

No. The AI-assisted mapping features operate on the message you give them at the moment you ask, and nothing from your traffic is retained for model training, by us or by a subprocessor. This is contractual, not a preference.

Send us the questionnaire

We'll answer it properly.

CAIQ, HECVAT, your own 300-row spreadsheet. An engineer fills it in, not a marketing team. Usually back within two business days.