Security

Security at Lineman

Lineman handles code and tool output for engineering teams, so security is part of the product, not a page we update once a year. Below is what we run today, what is audited by independent third parties, and which formal certifications we are working towards.

Not even we can see your data

The most common question we get is "where does my code go?" The short answer: nowhere we can look at. The processing is automated and isolated, and there is no human in the loop. We would rather answer the long version too, so we publish the complete list of what the plugin sends, field by field, along with what we keep and for how long.

See exactly what Lineman sends, or switch the compression off in your dashboard and nothing you write or run is transmitted at all.

  1. 1

    Lives on your machine

    Your repository and files stay on your own disk. The only thing Lineman ever receives is the specific tool output it has been asked to compress.

  2. 2

    Processed in memory

    That content is held only in memory, in an automated processing path, for the moment it takes to produce a response. No engineer steps into that path to read it.

  3. 3

    Discarded after the response

    Once the response is returned, your file contents and command output are gone. They are never written to a database. The one exception is Smart Compaction, which holds conversation segments for 24 hours so your agent can retrieve the detail it set aside, and then deletes them. You can switch the whole thing off in your dashboard.

Usage and billing data is stored separately, and by design it never contains your code or file contents.

Independent security audit

Lineman is continuously assessed by Aikido Security, an external platform covering code scanning, dependency vulnerabilities, secrets detection, cloud-posture, and container image analysis across our production infrastructure. Our live audit report is published and can be requested below.

Secured by Aikido, view security audit report

Certifications in progress

Our internal security programme is built around the frameworks below, and we are actively engaged with our auditors to obtain formal attestation against each one. We'll update this page as each certification is awarded.

  • ISO/IEC 27001

    In progress

    International standard for information security management, the controls covering how we identify, treat, and monitor risk to customer data.

  • ISO/IEC 27701

    In progress

    Privacy extension to ISO 27001, extends our information-security programme to cover personal data and the obligations of a data processor.

  • SOC 2 Type II

    In progress

    AICPA attestation covering security, availability, and confidentiality of the Lineman service over a continuous observation window.

ISO/IEC 27001 and ISO/IEC 27701 are trademarks of the International Organization for Standardization. SOC 2 is a trademark of the American Institute of Certified Public Accountants. Official certification marks will appear on this page once each audit concludes; Lineman makes no claim to current certification under these schemes.

How we protect your data

  • Encryption in transit and at rest

    All traffic to and from the Lineman API is TLS-encrypted. Customer data at rest is encrypted using cloud-provider managed keys.

  • Least-privilege access

    Engineer access to production systems is limited, role-scoped, audit-logged, and reviewed regularly.

  • Code kept out of logs and telemetry

    Usage and telemetry are stored separately from anything you process, so your source code and file contents never appear in our logs or analytics.

  • No training on customer data

    Code and prompts that pass through Lineman are not used to train any model. See our privacy policy for the full data-handling terms.

  • Continuous vulnerability monitoring

    Dependencies, container images, infrastructure, and source code are continuously scanned by Aikido. Findings flow into our triage process with documented response targets.

  • Secure development

    Every change is security-scanned before it can merge, on top of code review and change-management controls, so issues are caught before they reach production.

  • Incident response

    We maintain a documented incident-response process for security and personal-data events, with defined roles, containment steps, and notification obligations.

Payments

We never see or store your card details. All card data is handled by Stripe, our PCI-DSS compliant payments provider. Lineman only ever receives a token and the status of a charge, so your card number never touches our systems.

Authentication and access

Accounts are secured by our managed identity provider on a dedicated login domain. Access to production systems is restricted to a small number of engineers, scoped by role, and audit-logged, and we re-verify your session rather than holding long-lived credentials in the product.

Data residency and sub-processors

We rely on a short, vetted list of infrastructure providers, and we publish exactly who they are and what they handle. The full sub-processor list and the technical and organisational measures each one is held to are set out in our Data Processing Agreement.

Your data rights

You can access, correct, export, or delete your account data at any time, and we act on deletion requests promptly. Business customers can sign our Data Processing Agreement. The binding detail lives in our Privacy Policy and Terms.

Security FAQ

Is my code or data stored on Lineman's servers?

Your file contents and command output are held only in memory for the moment it takes to produce a response, then discarded. They are never written to a database. The one exception is Smart Compaction, which holds conversation segments for 24 hours so your agent can retrieve the detail it set aside, and then deletes them automatically. Everything we transmit, and how long we keep it, is listed field by field on our data transparency page, and you can switch the whole thing off from your dashboard.

Can Lineman staff read my code?

No. Because nothing is stored, there is no copy for anyone to read later, and the processing path is automated rather than something an engineer steps into. Your code is also kept out of our logs and analytics.

Do you train AI models on my code or prompts?

No. Code and prompts that pass through Lineman are never used to train any model.

Is my data encrypted?

Yes. All traffic to and from the Lineman API is encrypted with TLS, and data at rest is encrypted using cloud-provider managed keys.

Are you ISO 27001 or SOC 2 certified?

We are actively working towards ISO/IEC 27001, ISO/IEC 27701, and SOC 2 Type II. Until each certificate is awarded we describe these as in progress rather than claiming a status we have not yet earned. This page is updated as each one is granted.

Who audits your security?

Lineman is continuously assessed by Aikido, an independent security platform covering code scanning, dependency and secret detection, cloud posture, and container image analysis. Our live audit report can be requested from this page.

Do you store my payment details?

No. Card data is handled entirely by Stripe, our PCI-DSS compliant payments provider. Lineman never sees or stores your card number.

What happens to my data if I close my account?

Account data is deleted after closure in line with our retention policy. The code you process is never retained in the first place, so there is nothing further to remove.

Can I sign a Data Processing Agreement?

Yes. Business customers can sign our Data Processing Agreement, which sets out our role as processor, the security measures we apply, and the sub-processors we use.

Reporting a vulnerability

If you believe you've found a security vulnerability in Lineman, please email security@lineman.io. We acknowledge reports within one business day and will keep you updated through resolution.

Have a security question?

We're happy to walk your security or procurement reviewers through how Lineman handles data, and to share our latest independent audit report.

Last updated: June 2026