Lintro B2B Networking Application – Enterprise Security Compliance

Lintro B2B Networking App Enterprise Security Image

Last Updated: 6th August, 2026

Executive Summary

Lintro is an outcome-driven professional business to business (B2B) connection engine designed with enterprise security, data privacy, and strict identity verification at its core.

Recognizing that our enterprise clients entrust us with mapping their internal corporate networks alongside external professional relationships, Lintro has engineered a zero-trust identity layer and a highly segregated data architecture.

For full transparency we are happy to shares Lintro’s security posture, compliance inheritance, identity attestation, and data isolation mechanisms that protect corporate seat holders in our internal, external, and hybrid matching environments.

These not only ensure our corporate clients security and IT departments are comfortable with our compliance, but also demonstrate to all Lintro users our commitment to privacy and security.

1. Infrastructure & Core Compliance

Lintro’s backend enterprise security infrastructure is powered exclusively by Google Cloud Platform (Firebase). By leveraging Google’s enterprise-grade data centers and security perimeter, Lintro natively inherits compliance with the most stringent global standards, including:

  • SOC 2 (Type II) & SOC 3: Google Cloud’s infrastructure is audited against the AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy).
  • ISO/IEC 27001, 27017, & 27018: Certified for Information Security Management and protection of personally identifiable information (PII) in public clouds.
  • PCI-DSS: Compliant for secure payment processing (Note: Enterprise seats are invoiced manually via B2B contracts; Lintro does not store native credit card data).
  • HIPAA & GDPR: Infrastructure designed to support protected health information and European data sovereignty requirements.

All data is encrypted both in transit (TLS 1.2+) and at rest (AES-256) by default.


2. Identity & Authentication (Zero-Trust Verification)

Lintro does not rely on basic username/password authentication, which is highly susceptible to credential stuffing and phishing. Instead, we utilize a dual-layered, decentralized identity model.

2.1 Primary Identity (LinkedIn OIDC)

All user accounts are intrinsically tied to a verified LinkedIn profile via OpenID Connect (OIDC). This ensures that the base identity of every user is anchored to a real-world professional footprint, vastly reducing spam, bot activity, and impersonation. All users are asked to verify an additional email with Brevo SecureOTP as an additional trust layer.

2.2 Corporate/Enterprise Attestation (Brevo OTP Failsafe)

To access an enterprise-provisioned seat, users must prove current employment via our Corporate Attestation engine:

  1. Domain Matching: The user provides their corporate email address (e.g., user@company.com).
  2. Secure OTP: Our system dispatches a time-sensitive, 6-digit One-Time Password via the secure Brevo transactional email API.
  3. Atomic Verification: Upon successful OTP entry, a secure cloud transaction locks the user’s ID to the enterprise’s unique orgId.
  4. Privately Attributed orgId + userId combination your employees provides access to enterprise features.

2.3 The 90-Day Hygiene Lease (Offboarding Security)

Corporate seat entitlement is never permanent. Enterprise verification is granted on a rolling 90-day lease. Every 90 days, the user is challenged to re-verify their corporate email.

  • The Benefit: If an employee leaves the company or is terminated, they lose access to their corporate inbox. Once the 90-day lease expires, Lintro automatically revokes their enterprise tier status, removes them from the internal matching pool, and decrements the organization’s usedSeats counter. This returns the seat to the available pool for reuse within the active period of the enteprise contract.

3. Enterprise Data Segregation & Hybrid Matching

Enterprises utilize Lintro for a mix of internal matching (connecting siloed employees within the same company) and external/hybrid matching (connecting employees with the broader industry).

3.1 Strict Organizational Silos

Enterprise seat tracking and user affiliation are strictly segregated at the database level:

  • Each enterprise has a dedicated document in the organizations collection governing their authorized email domains, seat counts (totalSeats vs usedSeats), and contract expiry.
  • When a user verifies their corporate domain, their user profile is permanently stamped with the corresponding orgId.
  • Internal matching algorithms strictly query against this orgId parameter, ensuring that internal corporate networking data cannot bleed into the public/external pools.

4. Data Privacy & Minimization

Lintro operates on a strict Data Minimization philosophy. We only collect the data explicitly required to facilitate professional networking.

4.1 No OS-Level Tracking or Background Location

Unlike many modern applications, Lintro does not request or require OS-level GPS permissions (such as ACCESS_FINE_LOCATION on Android or NSLocationWhenInUse on iOS).

  • Privacy by Design: Location data is provided strictly via user-typed text intent (e.g., manually searching for “Chicago, IL” to find local connections).
  • Ad-Tech Protection: Because GPS permissions are never requested by the app, it is physically impossible for any third-party SDKs to silently inherit location permissions or siphon precise geographic tracking data to data brokers. Location matching is powered by a secure, direct REST API call to Google Places Autocomplete, not a monolithic tracking SDK.

4.2 Protected Personal Data

  • The only personal data stored by Lintro is the public professional data supplied by LinkedIn (Name, Profile Picture) and the specific intents/focuses the user manually enters during onboarding.
  • In-app messaging is securely stored in Firebase and isolated to the specific connection (the “Match”).
  • Corporate email addresses are isolated into a separate, secure private sub-collection that is never exposed to the public frontend API.

Conclusion

By combining the infrastructure security of Google Cloud, OIDC identity verification, 90-day corporate email leases, and a strict adherence to data minimization (zero GPS tracking), Lintro provides a networking environment that enterprise IT and Security teams can trust.

For a copy of this document for your internal enterprise/corporate records please use this link to Download the PDF version.