Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: Vendor attested — trust page
ThirdProof independently checks public intelligence sources to show what your team can verify about Linear before Linear sends a questionnaire or a security document.
Linear's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Linear — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Linear's own trust page.
⚠ Linear was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Linear assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Linear Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 47% of a 133-question vendor security questionnaire — without waiting for Linear. The remaining 70 are listed as open, so the follow-up you send is short and specific.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Encryption at rest claim found on trust page (Vendor attested)
Q38
ISO 27001 claim found on trust page (Vendor attested)
+ 58 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Linear for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Linear
Linear is a modern issue tracking and project management SaaS platform with a Tier 4 (Low Risk) rating and 98% confidence.
The vendor demonstrates strong foundational security infrastructure and operational maturity across multiple dimensions. Positive signals include: a well-established 8+ year domain with valid TLS 1.3 encryption, clean domain reputation with no malware or phishing indicators, robust HTTP security headers (B+ grade), comprehensive audit logging with IP/country tracking for privileged access, support for SSO and passkeys, EU data residency options, and a 30-day data deletion SLA compliant with GDPR/CCPA.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from public domain records, threat intelligence feeds, certificate registries, vendor-published pages, and third-party security scans — the vendor did not participate in or influence this assessment.
2 findings identified for Linear
The [subprocessor page](https://linear.app/subprocessors) exists but contains placeholder or stub content with zero individual subprocessors extracted. The vendor's [Data Processing Agreement](https://linear.app/dpa) explicitly states that Linear engages Authorized Sub-Processors with access to personal data, yet the published list is incomplete or inaccessible. …
Linear's [trust page](https://linear.app/security) claims SOC 2 Type II, ISO 27001, HIPAA compliance, and GDPR compliance. However, independent registry verification could not confirm these certifications: ISO 27001 returned no match in the IAF CertSearch database, and SOC 2 reports are confidential with no public registry. …
Evidence that positively supports Linear's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Established Domain (8+ years)
Domain Registration →Linear complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Linear is a project management platform widely adopted by engineering teams, processing issue tracking data, sprint planning, and development workflow information. Linear claims SOC 2, HIPAA, and GDPR compliance. Organizations using Linear alongside other development tools should assess data flows between Linear and connected services (GitHub, Slack, Figma) as part of a holistic vendor risk assessment. For related vendor assessments, see the Figma security review and Slack compliance review.
ThirdProof investigated Linear across 27 intelligence sources. Sanctions screening returned clear. Domain reputation is clean across 93 engines with an A+ SSL/TLS grade and B+ HTTP security grade (80/100). The 7-year domain history is relatively short compared to enterprise incumbents, but Linear's clean threat intelligence profile and strong infrastructure security support a favorable risk assessment.
Represent Linear? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Linear assessment above is already written; ask for it and it lands in your inbox.