Security

Built to be audited.

Every connector and bridge we ship follows one posture. It fits on a page, on purpose — if a security model needs an hour to explain, it has somewhere to hide.

01 — The posture

Five rules, no exceptions.

Read-only by defaultA connector reads. Writes exist only behind explicit, named scopes that the account holder turns on deliberately — never bundled, never assumed.
Your OAuth, your off switchEvery connection is authorised against the customer's own account, by the customer. Revoke the token and the bridge is dead that second. No one has to ask us.
Zero credentials heldWe never hold end-user passwords. Authorisation is token-based against the software's own published OAuth — staff logins never pass through us.
Scrubbed logsOperational logs record that a request happened, not the customer data inside it. Identifiers needed for debugging are minimised and aged out.
A security note with every releaseEach release ships with a plain-English note: what changed, what scopes exist, what we can and can't see. This page moves with the product.

02 — What we never do

The short list that matters.

No data warehousing.

Your data stays in your account. The bridge answers questions against it; we don't copy your system into ours.

No training on your data.

Customer data is never used to train models — ours or anyone's.

No resale, no sharing.

Your data is not a product. It is not sold, shared, pooled or "anonymised and aggregated".

03 — Where we are

Plain answers, here too.

HardLink is an Australian practice with global scope. We don't yet carry the certifications a ten-year-old firm would (SOC 2, ISO 27001) — we build to those disciplines and will certify as the practice grows. If your audit needs something this page doesn't answer, ask: hello@hardlink.com.au.

hello@hardlink.com.au

Security questions answered by a human, in writing.