Security

Security at Linkyhost

At Linkyhost, we take the security and privacy of your data seriously. This page describes the security measures that actually protect your links and files today — no more, no less.

Data Protection

  • All files are encrypted at rest (AES-256) in Google Cloud Storage
  • TLS encryption for all connections in transit
  • Files are stored in Google's secured data centers
  • GDPR-conscious data handling, including a self-service right-to-delete
  • flow for form submissions and full self-service account deletion
  • Deleting a link or your account removes the underlying files immediately
  • Account Security

  • Sign-in via Google or a one-time code emailed to you — there is no stored
  • account password to steal or reuse
  • Hardened, HTTP-only session cookies
  • Cross-site request forgery (CSRF) protection on every state-changing request
  • Rate limiting and brute-force protection on sign-in and link-unlock attempts
  • Banned-account and ban-evasion controls
  • Link Security Features

  • Password-protected links (Pro): PDFs are encrypted with the password
  • itself, and HTML pages are gated behind a server-verified prompt
  • Expiration settings for temporary access (Pro)
  • Per-link analytics for monitoring unexpected traffic
  • Abuse reporting on every hosted page
  • Content Safety

  • Every upload is scanned by our content-moderation pipeline before it goes
  • live, including phishing and malware checks
  • Archives are additionally screened with VirusTotal
  • A dedicated abuse-response process takes down malicious content and the
  • accounts behind it

    Team Access (Enterprise)

  • Team workspaces with role-based permissions (Owner / Admin / Member)
  • Admins control who is on the team; removals take effect immediately
  • Invitations are single-use, expire after 7 days, and can only be accepted
  • by the invited email address

    What We Don't Offer Yet

    We believe in being straightforward: Linkyhost does not currently provide SSO/SAML, two-factor authentication, SCIM provisioning, or formal certifications such as SOC 2 or HIPAA. If those are requirements for your organization, contact support@linkyhost.com and we'll tell you honestly whether we're a fit.