2026-09-25 · 6 min read

Is Linear SOC 2 or ISO 27001 Certified?

Quick answer. Linear's security page states it undergoes regular SOC 2 Type II audits (first Type I completed October 2021 with Vanta) and has achieved ISO/IEC 27001:2022 certification. HIPAA coverage requires the Enterprise plan. Request current reports through trust.linear.app; we could not independently verify the ISO certificate number.

If Linear runs your engineering workflow and you're heading into a SOC 2 or ISO 27001 audit, you're really asking two things: what has Linear itself certified as a subservice organization in your vendor list, and what evidence does Linear give your auditor about how your own team handles access and change management. Here's what we verified directly.

What Linear has certified

Linear's own security page and security docs state the following, verified directly against those pages:

CertificationStatus
SOC 2 Type II"Undergoes regular Service Organization Controls audits (SOC 2 Type II)"
ISO/IEC 27001:2022Certification stated on the security page
GDPRCompliant; see Linear's Data Processing Agreement
HIPAABAA available, Enterprise plan only

Linear's October 2021 changelog entry records the original milestone: a completed SOC 2 Type I audit, run with Vanta as the automated monitoring partner. The current security page describes ongoing Type II audits, which is the standard progression: Type I attests controls exist at a point in time, Type II attests they operated effectively over a period, typically 6-12 months.

That distinction matters when you're reading any vendor's SOC 2 claim, not just Linear's. A Type I report tells you a vendor designed reasonable controls. A Type II report tells you those controls actually held up under observation. If a security questionnaire response or a vendor's marketing page just says "SOC 2 compliant" without naming the type, ask which one before you rely on it for your own audit.

Common gap

We found the ISO/IEC 27001:2022 claim stated directly on Linear's security page, but no public certificate number and no independent confirmation in a third-party certification registry. If a security questionnaire or your own auditor needs to cite Linear's ISO 27001 status, request the certificate through trust.linear.app rather than repeating the page copy as a verified fact.

Encryption and data handling

Linear forces HTTPS with TLS 1.2 for data in transit and AES-256 encryption at rest. Workspace data is stored in either the US or EU, by customer choice, but workspace metadata, account information, notification emails, usage analytics, and crash data always remain in the US regardless of that setting. That's worth knowing if your own data residency commitments assume everything stays in one region.

Source: Linear Security, Linear Security Docs.

Getting Linear's reports

Linear's trust center at trust.linear.app is where SOC 2 and ISO 27001 documentation, the DPA, and other compliance materials are requested. As with most vendor trust portals, expect an access request and possibly an NDA before the full report is released.

How startups use Linear as SOC 2 or ISO 27001 evidence

Linear shows up in your audit as evidence of your controls, not as a certification you inherit. Three areas matter most.

Access provisioning and review (SOC 2 CC6.1, CC6.2; ISO 27001 Annex A 5.16, 5.18)

Linear supports SSO, SAML, and SCIM provisioning on Enterprise plans, along with domain claiming and login or IP restrictions. If SCIM is wired to your identity provider, deprovisioning in your IdP automatically removes Linear access, which is exactly the evidence auditors want for CC6.2. Without SCIM, you're stuck manually reconciling the Members and roles page against your IdP every audit cycle.

Tip

Pull the Members and roles page as a point-in-time access review, then repeat it quarterly. Auditors want to see the review happened, not just that it's possible.

Monitoring and administrative logging (SOC 2 CC7.2; ISO 27001 Annex A 8.15)

Linear's audit log, an Enterprise-plan feature, records account access, subscription changes, settings changes, user activity, and administrative actions going back 90 days. It's viewable under Workspace Settings > Administration > Audit Log, restricted to workspace owners, and queryable via API by actor, email, IP address, or date range. It can also stream to a webhook for SIEM ingestion, which is the setup you want if your audit period is longer than 90 days, since the in-app view won't cover it.

Change management (SOC 2 CC8.1; ISO 27001 Annex A 8.32)

Linear's cycles, projects, and issue states give you a record of what changed, who requested it, and when it moved through review. This is stronger evidence when issues link to pull requests through Linear's GitHub or GitLab integration, so an auditor can trace an issue from creation through code review to deployment in one thread.

What auditors look for: a Members and roles export showing current access, SSO/SCIM configuration proof, an audit log export or SIEM feed covering the full audit period, and a sample of issues showing the path from request to reviewed change.

Gaps that show up at audit

Audit log is Enterprise-only. Teams on lower plans have no audit trail to hand an auditor. If you're on Standard or Business heading into SOC 2, factor an Enterprise upgrade into your readiness plan early.

No SCIM, manual deprovisioning. Without SCIM, terminated employees can retain Linear access after their IdP account is disabled. Auditors compare termination dates against Linear's last-active timestamps in the audit log.

Issue closure treated as change approval. Marking an issue "Done" isn't a control by itself. Auditors want to see an actual review step, whether that's a linked pull request with required approval or a documented sign-off, not just a status change.

Citing ISO 27001 without the certificate in hand. Repeating Linear's security-page claim in your own vendor risk documentation without the underlying certificate is a common shortcut that falls apart the first time an auditor asks for the source document.

Treating Linear as your only source of truth for engineering changes. If deployment actually happens outside Linear, through a CI/CD pipeline with its own approval gates, your change management evidence needs to include that system too. Linear shows intent and review; it doesn't prove what shipped to production unless it's linked to the pipeline that did the shipping.

Turning tool-by-tool evidence like this into a control set an auditor accepts on the first pass is exactly the kind of work a fractional CISO runs for you, alongside whatever tools you already use. Book a call or see pricing if you want your engineering-tool evidence reviewed before your next audit.

Related reading

Frequently asked questions

Is Linear SOC 2 compliant?
Yes. Linear first completed a SOC 2 Type I audit in October 2021 with Vanta, and its security page now states it undergoes regular SOC 2 Type II audits. Request the current report through trust.linear.app; most vendor trust portals require an NDA before releasing it.
Is Linear ISO 27001 certified?
Linear's own security page states it has achieved ISO/IEC 27001:2022 certification. We could not locate a public certificate number or independently confirm the listing in a third-party registry, so if your auditor needs to cite this, request the certificate directly through trust.linear.app rather than repeating the claim secondhand.
Does Linear support HIPAA?
Linear offers a Business Associate Agreement, but only for customers on its Enterprise plan. If you're on a lower plan and need to handle PHI in Linear, you'll need to upgrade or keep PHI out of Linear entirely.
What is Linear's audit log used for in a compliance audit?
Linear's Enterprise-plan audit log records account access, settings changes, user activity, and administrative actions for the past 90 days, viewable in-app or queryable via API, and can stream to a webhook for SIEM ingestion. It's evidence for access-review and monitoring controls, not a certification itself.
How do I use Linear as evidence in my own SOC 2 audit?
Linear is process evidence, not infrastructure evidence. Use the Members and roles page for access reviews, SSO and SCIM configuration for provisioning and deprovisioning, the audit log for monitoring, and issue and cycle history (often linked to pull requests) for change management.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.