Security

We never hold your client’s password

When the account belongs to someone else, security stops being an IT checkbox and becomes the thing your relationship rests on. This page is what we do, what we store, and — because it matters more than the first two — the honest list of what we do not have yet.

Last reviewed 19 August 2026 · Written for the person whose account it actually is

Access

How we get permission, and how it ends

Four steps. The account holder is in control at both ends of them.

01

They authorise, not you

You send an invite. The account holder signs into LinkedIn themselves, on their own device, and grants access there. No credential is typed into anything of ours and none reaches you.

02

We receive a scoped token

What comes back is a token limited to publishing and reading that account’s own analytics. It is not a login. It cannot read their inbox, change their password or see anything the permission screen did not list.

03

The token stays encrypted and scoped

Stored encrypted, used only for that workspace, and never shared between clients. A person on your team who does not work on that account cannot reach it.

04

They can revoke it without asking you

From their own LinkedIn settings, at any time, and it takes effect immediately. That is the point: the person who owns the account never has to come through you to get control back.

The posture

What we do and what we refuse to do

Several of these rule out features competitors sell. That is the trade we made.

Practice
Why it matters
Hypelio
Access
Storing passwordsWe have no field for one. If a client offers you theirs, you do not need it and should not take it.
Breach blast radius
Never
Browser extension driving the accountWe ship none. Publishing goes through LinkedIn’s official interface, which is also what keeps the account out of trouble.
Account risk
None
Scraping profiles or selling dataNo lead database, no exports of other people’s profiles, no data brokered to anyone.
Third-party privacy
Never
Inside your workspace
Per-client isolationContent, analytics and tokens live per workspace. Your team sees the clients they are assigned to.
Client confidentiality
Yes
Roles and permissionsWriter, editor, approver and admin, so publishing rights are held by the people who should hold them.
Internal control
Yes
Audit trailWho approved which text, at what time, and what actually published. The record you will want on the one bad day.
Accountability
Yes
Your content
Training models on your workYour drafts and your clients’ posts are not used to train anything that serves another customer.
Competitive leakage
Never
EncryptionIn transit and at rest, tokens included.
Baseline hygiene
Yes
Getting your data outExport any time, and content stays exportable for ninety days after a subscription ends.
No hostage-taking
Yes

What we do not have yet

Most security pages are written to close a deal. This part is here because you may be forwarding this page to somebody whose job is to find what it leaves out, and it is better that they hear it from us.

No SOC 2 or ISO 27001 reportWe are a new company and have not been through either audit. Anyone claiming one at our age is either much better funded or not being straight with you. If your client’s procurement requires a report, we will not be able to satisfy it today — tell us and we will say where we are rather than stall you.
No penetration-test certificate to hand outNot yet commissioned. When one exists we will say so here with its date, and we will not describe an internal review as if it were an external test.
The DPA and sub-processor list are still being draftedHypelio acts as a processor for personal data belonging to people who are not our customers — your clients. That deserves a proper data processing agreement and a published list of who else touches the data. Both are in progress and neither is finished, so we are not pretending otherwise.
No single sign-on or SCIMSensible for a large in-house team and not something we support today. If it is a requirement, it is worth telling us early rather than discovering it in week three.

If any line on this page stops being true, it gets changed here first. A security page that quietly drifts out of date is worse than not having one.

For your client’s IT or compliance team

If you are the person being asked to sign off on an agency using this, here is the short version. Your marketing partner is not being given your LinkedIn password, because there is nowhere to put one. You grant access yourself through LinkedIn’s own permission screen, and you can withdraw it yourself from LinkedIn’s settings at any moment without going through the agency.

What the access permits is publishing to that account and reading its own analytics. It does not include messages, connections, or anything else the permission screen did not name. Nothing publishes without an approval you can see recorded, and the record of who approved which wording survives the post.

What we hold is the content written for that account, the analytics LinkedIn returns for it, and the encrypted token. What we do not hold is a credential, and what we do not do is scrape or sell anything. The full detail sits in the privacy policy, and the honest gaps are listed above rather than buried.

Reporting something

If you find a vulnerability, tell us before you tell anyone else and we will work with you rather than argue with you. We will confirm receipt, keep you updated while it is being fixed, and credit you if you would like to be credited. We do not currently run a paid bounty and will not pretend that we do.

Questions

What people ask before connecting a client

Can Hypelio read my client’s LinkedIn messages?+
No. The access we request covers publishing to the account and reading that account’s own post analytics. Messages, connections and the rest of the profile are outside it, and LinkedIn’s permission screen shows exactly what is being granted before anyone agrees to it.
What happens if my agency and I part ways?+
You revoke the access from your own LinkedIn settings, which takes effect immediately and does not require the agency to cooperate. Any posts already published stay yours, because they are on your profile.
What if a member of my team leaves?+
Remove them and their access ends with the account. Because nobody on your team ever held a client password, there is no credential circulating afterwards — which is the failure mode that makes leavers genuinely dangerous under the shared-password approach.
Where is the data held?+
Content and analytics sit with our hosting provider, encrypted in transit and at rest. Specific regions and the full sub-processor list belong in the data processing agreement, which is being drafted — ask us and we will tell you where it currently stands rather than guess.
Do you use our content to train AI?+
Not for anything that serves another customer. Voice profiles are built from an account’s own posts and used only for that account. Your client’s writing does not end up shaping drafts for a competitor.
Is this page audited or just marketing?+
It is a description of how the product is built, written by the people who built it, and not certified by anyone. That is precisely why the gaps are listed on it. Weigh it accordingly.

Connect one account and check for yourself

Fourteen days, no card. Read the permission screen before you accept it, and revoke it afterwards to see how quickly that works.

No passwords. No extension. Official LinkedIn API.