When the account belongs to someone else, security stops being an IT checkbox and becomes the thing your relationship rests on. This page is what we do, what we store, and — because it matters more than the first two — the honest list of what we do not have yet.
Four steps. The account holder is in control at both ends of them.
You send an invite. The account holder signs into LinkedIn themselves, on their own device, and grants access there. No credential is typed into anything of ours and none reaches you.
What comes back is a token limited to publishing and reading that account’s own analytics. It is not a login. It cannot read their inbox, change their password or see anything the permission screen did not list.
Stored encrypted, used only for that workspace, and never shared between clients. A person on your team who does not work on that account cannot reach it.
From their own LinkedIn settings, at any time, and it takes effect immediately. That is the point: the person who owns the account never has to come through you to get control back.
Several of these rule out features competitors sell. That is the trade we made.
Most security pages are written to close a deal. This part is here because you may be forwarding this page to somebody whose job is to find what it leaves out, and it is better that they hear it from us.
If any line on this page stops being true, it gets changed here first. A security page that quietly drifts out of date is worse than not having one.
If you are the person being asked to sign off on an agency using this, here is the short version. Your marketing partner is not being given your LinkedIn password, because there is nowhere to put one. You grant access yourself through LinkedIn’s own permission screen, and you can withdraw it yourself from LinkedIn’s settings at any moment without going through the agency.
What the access permits is publishing to that account and reading its own analytics. It does not include messages, connections, or anything else the permission screen did not name. Nothing publishes without an approval you can see recorded, and the record of who approved which wording survives the post.
What we hold is the content written for that account, the analytics LinkedIn returns for it, and the encrypted token. What we do not hold is a credential, and what we do not do is scrape or sell anything. The full detail sits in the privacy policy, and the honest gaps are listed above rather than buried.
If you find a vulnerability, tell us before you tell anyone else and we will work with you rather than argue with you. We will confirm receipt, keep you updated while it is being fixed, and credit you if you would like to be credited. We do not currently run a paid bounty and will not pretend that we do.
Fourteen days, no card. Read the permission screen before you accept it, and revoke it afterwards to see how quickly that works.
No passwords. No extension. Official LinkedIn API.