No LinkedIn passwords
LinkedIn passwords are never collected.
This Security Policy explains the safeguards Elaryx uses to protect accounts, OAuth tokens, user content, AI workflows, billing boundaries, and LinkedIn-connected data.
LinkedIn passwords are never collected.
OAuth tokens are protected and access-controlled.
Access is limited by role and operational need.
Security incidents can be reported to Elaryx.
This Security Policy explains the safeguards Elaryx uses to protect accounts, OAuth tokens, user content, AI workflows, billing boundaries, and LinkedIn-connected data.
It applies to the Elaryx web app, website, APIs, integrations, admin systems, databases, cloud infrastructure, support processes, and security operations. It does not cover third-party systems controlled by LinkedIn, payment gateways, AI providers, hosting providers, analytics tools, or the user's own device/network.
Security ownership sits with Elaryx/PINNAL SOFTWARE SOLUTIONS LLP leadership and engineering operations. Policies, access, and data-related changes are reviewed periodically according to operational risk and legal needs.
| Control area | Practice |
|---|---|
| Authentication | Password hashing or third-party auth where implemented, session controls, email verification where supported, and abuse protection where implemented. |
| OAuth token protection | LinkedIn passwords are never requested or stored. Tokens are stored using secure storage practices such as encryption at rest or equivalent provider-managed safeguards. |
| Encryption | HTTPS/TLS for data in transit, encryption at rest where supported, and secrets kept out of frontend code. |
| Access control | Least privilege, role-based access, restricted admin access, access review, and removal when access is no longer needed. |
| Monitoring and logs | Authentication, integration status, publishing/scheduling, error, and security event logs retained for reasonable support/security/legal periods. |
| Incident response | Detect, assess, contain, investigate, remediate, and notify where required by law or operational need. |
LinkedIn access relies on OAuth or approved authorisation. Token access is limited to authorised backend services and operational staff with need-to-know access. Tokens can be revoked or disconnected and are deleted or invalidated when no longer needed, subject to legal, security, and retention needs.
Elaryx uses secure coding practices, input validation, dependency updates, backups, monitoring, production/development separation where implemented, and error logging designed to avoid unnecessary secrets or personal data.
User prompts, brand data, drafts, generated outputs, and uploaded assets may be processed through authorised AI providers or subprocessors. Users should minimise sensitive data in prompts and avoid submitting passwords, API keys, government IDs, confidential client data, or regulated data unless necessary and authorised.
Elaryx triages security issues by severity, applies security patches where needed, monitors errors and abuse signals, and may use dependency checks where available. No public bug bounty is offered unless separately announced.
Backups may be used for databases and content where implemented. Backup deletion may lag behind user deletion requests, and Elaryx does not guarantee that every draft, output, or asset can be recovered.
Elaryx may use hosting, AI, payment, analytics, support, email, logging, and infrastructure providers. Vendors are selected based on operational need and safeguards, with contractual or data-processing terms where applicable. Cross-border processing may occur subject to applicable law.
Report vulnerabilities or suspected account misuse to support@elaryx.ai. Include account email, affected URL, steps to reproduce, screenshots or logs without secrets, and impact details. Do not test accounts or data you do not own, perform destructive testing, spam, social engineering, or data exfiltration.
No system is perfectly secure. Elaryx does not claim SOC 2, ISO 27001, penetration-test certification, DPDP certification, or LinkedIn security approval unless verified evidence is published by Elaryx.
No. Elaryx does not request or store LinkedIn passwords.
Tokens are stored using secure storage practices such as encryption at rest or equivalent safeguards and are limited to authorised backend access.
Payment card details are handled by payment gateways. Elaryx should not store full card numbers or CVV unless a future implementation explicitly states otherwise.
Yes. Disconnecting LinkedIn revokes connected functionality and may disable publishing, scheduling, analytics, and profile-intelligence features.
Change your password or secure your auth provider, review team access, disconnect suspicious integrations, and contact support@elaryx.ai.
Elaryx does not publicly claim SOC 2, ISO 27001, DPDP certification, or LinkedIn security approval unless verified evidence is published.
Elaryx detects, assesses, contains, investigates, remediates, and notifies where required by applicable law or operational need.
Email support@elaryx.ai with affected URL, steps to reproduce, impact, and screenshots or logs without secrets.