Security
Every connector and bridge we ship follows one posture. It fits on a page, on purpose — if a security model needs an hour to explain, it has somewhere to hide.
01 — The posture
| Read-only by default | A connector reads. Writes exist only behind explicit, named scopes that the account holder turns on deliberately — never bundled, never assumed. |
| Your OAuth, your off switch | Every connection is authorised against the customer's own account, by the customer. Revoke the token and the bridge is dead that second. No one has to ask us. |
| Zero credentials held | We never hold end-user passwords. Authorisation is token-based against the software's own published OAuth — staff logins never pass through us. |
| Scrubbed logs | Operational logs record that a request happened, not the customer data inside it. Identifiers needed for debugging are minimised and aged out. |
| A security note with every release | Each release ships with a plain-English note: what changed, what scopes exist, what we can and can't see. This page moves with the product. |
02 — What we never do
Your data stays in your account. The bridge answers questions against it; we don't copy your system into ours.
Customer data is never used to train models — ours or anyone's.
Your data is not a product. It is not sold, shared, pooled or "anonymised and aggregated".
03 — Where we are
HardLink is an Australian practice with global scope. We don't yet carry the certifications a ten-year-old firm would (SOC 2, ISO 27001) — we build to those disciplines and will certify as the practice grows. If your audit needs something this page doesn't answer, ask: [email protected].
Security questions answered by a human, in writing.