Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Linear, your compliance team needs documented proof they can be trusted. ThirdProof investigated Linear across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
27 sources queried. 100% confidence. Every Linear investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Linear's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 32% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q41
Not found in FedRAMP marketplace
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q28
Infrastructure detected: Cloudflare
+ 2 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Linear's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Linear is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
27
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Linear
Linear (linear.app) is a product development and issue-tracking SaaS tool assessed at Tier 3 (Moderate Risk) with medium data access. The overall security posture reflects a maturing compliance program with solid technical controls, offset by transparency gaps in subprocessor disclosure and AI data handling that require resolution before full procurement approval. Linear demonstrates several meaningful positive signals across its security infrastructure:
Independence Statement
All evidence underpinning this assessment was sourced independently through automated external data collection without vendor participation, submission, or review.
2 findings identified for Linear
linear.app has certificates from 27 different Certificate Authorities. This may indicate inconsistent certificate management practices.
An AI-specific data usage policy was not discoverable for linear.app through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
27 positive signals verified
Legal Entity Actively Registered
Business Registration →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Domain Infrastructure Healthy
Domain Analysis →Valid SSL Certificate
Domain Analysis →13 Open Ports Detected
Infrastructure Exposure →Established Domain (7+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: security
Tech Community Sentiment →HTTP Security Grade: B+
HTTP Security Scan →Certificate Transparency: 46 Subdomains
Certificate Transparency →Established Web Presence (6+ years)
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Subprocessor Page Found (Placeholder)
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →News Coverage Found (No Risk Signals)
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Linear
Obtain Linear's SOC 2 Type II audit report: contact their security team directly or access the Vanta-hosted trust report linked from https://linear.app/security. Confirm the audit period covers the last 12 months and request a bridge letter if the report predates this assessment by more than 6 months.
Resolve the subprocessor transparency gap: request a current populated subprocessor list from Linear (referencing the DPA Exhibit B), or ask Linear to update the public page at https://linear.app/subprocessors. Review each listed subprocessor for jurisdiction adequacy before processing personal data.
Request Linear's AI data handling terms before enabling AI features: specifically ask about training data use, third-party model providers, retention periods for AI-processed inputs, and opt-out mechanisms. Start with the DPA at https://linear.app/dpa and ask for any AI-specific addendum.
If any PHI-adjacent workflows are in scope, request and execute a HIPAA Business Associate Agreement (BAA) with Linear — their security page at https://linear.app/security indicates BAA availability; engage your privacy or legal team to review the BAA template.
Confirm TLS certificate renewal plans for linear.app before July 10, 2026: ask Linear's security team whether renewal is automated (e.g., Cloudflare auto-renew) or manual. Post-renewal, re-verify the certificate configuration at https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=linear.app.
If Linear is within your organization's SOC 2 audit boundary, document applicable Complementary User Entity Controls (CUECs) — particularly around access provisioning/deprovisioning, SSO enforcement, and data export/deletion workflows — and retain this report with a reviewer signature per CC9.2 requirements.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Linear? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Linear on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Linear's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Linear a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Linear appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Linear's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Linear's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Linear claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Linear depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Linear appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Linear is a project management platform widely adopted by engineering teams, processing issue tracking data, sprint planning, and development workflow information. Linear claims SOC 2, HIPAA, and GDPR compliance. Organizations using Linear alongside other development tools should assess data flows between Linear and connected services (GitHub, Slack, Figma) as part of a holistic vendor risk assessment. For related vendor assessments, see the Figma security review and Slack compliance review.
ThirdProof investigated Linear across 27 intelligence sources and assigned a Low Risk (Tier 4) rating with 82% confidence. Sanctions screening returned clear. Domain reputation is clean across 93 engines with an A+ SSL/TLS grade and B+ HTTP security grade (80/100). The 7-year domain history is relatively short compared to enterprise incumbents, but Linear's clean threat intelligence profile and strong infrastructure security support a favorable risk assessment.
Seeing this in an audit? ThirdProof lets you investigate Linear and every other vendor in your stack — average report time: 7 minutes. Get Linear's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Linear across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.