Is Linear SOC 2 or ISO 27001 Certified?
Quick answer. Linear's security page states it undergoes regular SOC 2 Type II audits (first Type I completed October 2021 with Vanta) and has achieved ISO/IEC 27001:2022 certification. HIPAA coverage requires the Enterprise plan. Request current reports through trust.linear.app; we could not independently verify the ISO certificate number.
If Linear runs your engineering workflow and you're heading into a SOC 2 or ISO 27001 audit, you're really asking two things: what has Linear itself certified as a subservice organization in your vendor list, and what evidence does Linear give your auditor about how your own team handles access and change management. Here's what we verified directly.
What Linear has certified
Linear's own security page and security docs state the following, verified directly against those pages:
| Certification | Status |
|---|---|
| SOC 2 Type II | "Undergoes regular Service Organization Controls audits (SOC 2 Type II)" |
| ISO/IEC 27001:2022 | Certification stated on the security page |
| GDPR | Compliant; see Linear's Data Processing Agreement |
| HIPAA | BAA available, Enterprise plan only |
Linear's October 2021 changelog entry records the original milestone: a completed SOC 2 Type I audit, run with Vanta as the automated monitoring partner. The current security page describes ongoing Type II audits, which is the standard progression: Type I attests controls exist at a point in time, Type II attests they operated effectively over a period, typically 6-12 months.
That distinction matters when you're reading any vendor's SOC 2 claim, not just Linear's. A Type I report tells you a vendor designed reasonable controls. A Type II report tells you those controls actually held up under observation. If a security questionnaire response or a vendor's marketing page just says "SOC 2 compliant" without naming the type, ask which one before you rely on it for your own audit.
Common gap
We found the ISO/IEC 27001:2022 claim stated directly on Linear's security page, but no public certificate number and no independent confirmation in a third-party certification registry. If a security questionnaire or your own auditor needs to cite Linear's ISO 27001 status, request the certificate through trust.linear.app rather than repeating the page copy as a verified fact.
Encryption and data handling
Linear forces HTTPS with TLS 1.2 for data in transit and AES-256 encryption at rest. Workspace data is stored in either the US or EU, by customer choice, but workspace metadata, account information, notification emails, usage analytics, and crash data always remain in the US regardless of that setting. That's worth knowing if your own data residency commitments assume everything stays in one region.
Source: Linear Security, Linear Security Docs.
Getting Linear's reports
Linear's trust center at trust.linear.app is where SOC 2 and ISO 27001 documentation, the DPA, and other compliance materials are requested. As with most vendor trust portals, expect an access request and possibly an NDA before the full report is released.
How startups use Linear as SOC 2 or ISO 27001 evidence
Linear shows up in your audit as evidence of your controls, not as a certification you inherit. Three areas matter most.
Access provisioning and review (SOC 2 CC6.1, CC6.2; ISO 27001 Annex A 5.16, 5.18)
Linear supports SSO, SAML, and SCIM provisioning on Enterprise plans, along with domain claiming and login or IP restrictions. If SCIM is wired to your identity provider, deprovisioning in your IdP automatically removes Linear access, which is exactly the evidence auditors want for CC6.2. Without SCIM, you're stuck manually reconciling the Members and roles page against your IdP every audit cycle.
Tip
Pull the Members and roles page as a point-in-time access review, then repeat it quarterly. Auditors want to see the review happened, not just that it's possible.
Monitoring and administrative logging (SOC 2 CC7.2; ISO 27001 Annex A 8.15)
Linear's audit log, an Enterprise-plan feature, records account access, subscription changes, settings changes, user activity, and administrative actions going back 90 days. It's viewable under Workspace Settings > Administration > Audit Log, restricted to workspace owners, and queryable via API by actor, email, IP address, or date range. It can also stream to a webhook for SIEM ingestion, which is the setup you want if your audit period is longer than 90 days, since the in-app view won't cover it.
Change management (SOC 2 CC8.1; ISO 27001 Annex A 8.32)
Linear's cycles, projects, and issue states give you a record of what changed, who requested it, and when it moved through review. This is stronger evidence when issues link to pull requests through Linear's GitHub or GitLab integration, so an auditor can trace an issue from creation through code review to deployment in one thread.
What auditors look for: a Members and roles export showing current access, SSO/SCIM configuration proof, an audit log export or SIEM feed covering the full audit period, and a sample of issues showing the path from request to reviewed change.
Gaps that show up at audit
Audit log is Enterprise-only. Teams on lower plans have no audit trail to hand an auditor. If you're on Standard or Business heading into SOC 2, factor an Enterprise upgrade into your readiness plan early.
No SCIM, manual deprovisioning. Without SCIM, terminated employees can retain Linear access after their IdP account is disabled. Auditors compare termination dates against Linear's last-active timestamps in the audit log.
Issue closure treated as change approval. Marking an issue "Done" isn't a control by itself. Auditors want to see an actual review step, whether that's a linked pull request with required approval or a documented sign-off, not just a status change.
Citing ISO 27001 without the certificate in hand. Repeating Linear's security-page claim in your own vendor risk documentation without the underlying certificate is a common shortcut that falls apart the first time an auditor asks for the source document.
Treating Linear as your only source of truth for engineering changes. If deployment actually happens outside Linear, through a CI/CD pipeline with its own approval gates, your change management evidence needs to include that system too. Linear shows intent and review; it doesn't prove what shipped to production unless it's linked to the pipeline that did the shipping.
Turning tool-by-tool evidence like this into a control set an auditor accepts on the first pass is exactly the kind of work a fractional CISO runs for you, alongside whatever tools you already use. Book a call or see pricing if you want your engineering-tool evidence reviewed before your next audit.