Trust & Security
How ExtraSpecial protects your data, the subprocessors we rely on to run the service, and how to reach our security team. We don’t sell your data and we don’t train AI on it. Everything below is generated from our canonical, version-controlled security documentation.
Compliance posture
We are working toward SOC 2 as we grow to support enterprise customers. We already run the security practices a SOC 2 program expects — least-privilege access, MFA, automated security scanning, audit logging, and documented incident response — and we describe them as practices we follow today, not as a certification we hold. We display no compliance badge we have not earned, and we will publish our SOC 2 status here once there is something independently verifiable to share.
Published policies & explainers
- Acceptable Use Policy
- Customer Data Flow (Public)
- How we handle your data (60-second explainer)
- Guide for Admins: Handling End-User Privacy Compliance
- Privacy Policy
- Subprocessors and Infrastructure Vendors
- Terms of Service
Report a vulnerability
Found a security issue? Email security@hyperlinked.io. We commit to a 24-hour acknowledgment and triage within 5 business days. Canonical machine-readable contact info lives at /.well-known/security.txt per RFC 9116.
Access & identity
Customer access is protected by multi-factor authentication (TOTP) with customer-configurable per-organization enforcement, role-based access control with hard per-tenant data isolation, and member deprovisioning / off-boarding. Operator access uses least-privilege IAM, MFA, and short-lived federated credentials (no static keys). Tenant administrative actions are recorded in a hash-chained audit trail; AWS-level actions are captured in immutable CloudTrail. See the data-handling explainer for details.
Data processing agreement
A DPA (with SCCs where applicable) is available on request — email legal@hyperlinked.io.