Security
Last updated 5 October 2026
What is true today, with nothing claimed that is not already running. The four commitments on the About page are kept by what follows.
Where things live
The application runs on Vercel. Data, uploaded files and sign-in are held by Supabase, in a Postgres database in the United States (AWS us-east-1), with everything encrypted on the way to you and at rest by those providers. Email leaves through Resend. A badge or card photographed in Connect is read by Anthropic’s Claude, is never stored, and goes with nothing from People. The full list of who handles data, and why, is section 8 of the privacy policy.
There is no SOC 2 or ISO 27001 report yet. This page is the current substitute, and it will say so until that changes.
Who can read what
Every public page is read through a function that decides what to emit, never by reading tables directly: a contact detail you have not turned on is not hidden by the page, it is never sent. Row-level security is on for every table that holds something of yours. The tables that hold reports and feedback can be read by no role at all, so a report is a thing that can be filed and acted on and not a list of who accused whom. The browser’s key cannot write an analytics row about anyone but the person using it.
A visitor to a page is anonymous. They become a person in your People only by registering for an event or exchanging details with you, which are acts they choose.
Signing in
Members sign in by email, with a link or a six-digit code, and there are no passwords to leak. A link is spent by pressing a button on the page it opens, never by being opened, so a mailbox that scans links on your behalf cannot use one up. Settings lists every session on your account with the device it was started from and lets you end any of them; signing out ends the browser you pressed it in and nothing else.
Staff work in a separate console on its own host, behind a password and an authenticator code, with a capability for each queue they can see. Granting a permanent address to a member asks for a fresh code and the address typed back. Every decision is recorded with a code, and nobody can grant another operator a capability they do not hold.
In the browser
Every page carries a Content Security Policy that only runs scripts minted for that request, no page may be framed by another site, and the headers that enforce both are checked by a script before every release. Forms that strangers can send, registration and the exchange, carry a bot check, a honeypot and a rate limit per sender; a refused sender is told nothing.
Your data, yours
People exports as a spreadsheet or as contact cards. Deleting your account from Settings removes your page, your events, your people, your notes and every file you uploaded, the files first. Your notes are readable by you and by nobody else, staff included.
What is watched
The three public hosts are fetched every five minutes from inside the database and the result is kept. That monitor cannot see an outage of the database it runs in, which is said here rather than implied.
Reporting a problem
Write to hello@lynkur.com. It is the address that answers. A page that misrepresents somebody is reported from the report form.