Legal — Security

Security

Last updated: 7 June 2026

Security is built into how we work — not bolted on afterwards. As a company that ships production AI and red-teams models for a living, we hold our own systems to the same standard. This page describes, at a high level, how Lynkstr Private Limited protects its systems, data, and the products it builds, and how to report a vulnerability.

01Our approach

We follow a defence-in-depth, least-privilege philosophy and apply controls proportionate to risk. Our practices are informed by widely recognised standards and guidance, including the OWASP Top 10 and the OWASP Top 10 for Large Language Model Applications. Security is a shared responsibility across the team, and we treat it as an ongoing process rather than a one-time checklist.

02Infrastructure & hosting

03Encryption

04Access control

05Secure development

06AI & model security

Securing AI systems is a core competency — it is one of the services we offer. For our own products and client work, we consider AI-specific risks such as prompt injection, data leakage, insecure output handling, and model misuse. Where appropriate, we apply input/output controls, guardrails, and red-teaming and safety evaluation to probe for failure modes, bias, and adversarial weaknesses before release.

07Monitoring & logging

08Vulnerability management

We track and triage vulnerabilities in our infrastructure, applications, and dependencies, prioritising remediation by severity and exploitability. We welcome reports from the security community — see Reporting a vulnerability.

09Incident response

We maintain a process to detect, contain, investigate, and remediate security incidents. Where an incident affects personal data, we act in accordance with our Privacy Policy and applicable law, including India's Digital Personal Data Protection Act, 2023, and will notify affected parties and authorities where required.

10Data protection

How we collect, use, and protect personal data is described in our Privacy Policy. On client engagements, we handle client data per the relevant agreement and only as instructed, applying the safeguards described on this page.

11Subprocessors

We use a limited set of trusted third-party providers (for example, cloud hosting, email, and AI model providers) to operate our business. We select providers with appropriate security practices and bind them with suitable contractual terms. A current list can be provided to clients on request.

Reporting a vulnerability

If you believe you've found a security vulnerability in a Lynkstr website, system, or product, we'd like to hear from you. Please email prasanna@lynkstr.com with the subject line “Security” and include enough detail to reproduce the issue.

Please give us a reasonable opportunity to investigate and remediate before public disclosure, and avoid privacy violations, data destruction, or service disruption while testing. We will acknowledge legitimate reports and keep you updated on our progress. We appreciate responsible disclosure and the work of the security community.

This page describes our practices at a high level and does not form part of any contract or warranty. Specific security commitments for an engagement are set out in the applicable agreement.