VendorScore · Issue tracking · Data-access posture
A plain-language answer from Linear's security pages, DPA (with its subprocessor list), AI Services Addendum and Privacy Policy. Linear contractually rules out training on your data but offers no customer-managed keys.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Linear's servers and AI providers process your issues and docs in plaintext with Google Cloud-managed keys; Linear contractually rules out training on your data.
Scored configuration: Linear Enterprise workspace in the EU region, SAML/SCIM, IP restrictions, audit log, AI at defaults (no training; zero data retention where supported). No customer-managed key option.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Linear will not use Customer Data, including prompts or outputs, to train, fine-tune or improve its own AI models.
Evidence: Linear AI Services Addendum34 subprocessors including Anthropic, OpenAI, Fireworks AI, Cohere and Braintrust, plus sales/marketing tools.
Evidence: Linear DPA (Exhibit B)EU region available at workspace creation, but account data and API keys are always stored in the US.
Evidence: Linear Docs: SecurityOur report flags these gaps in Linear's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Linear's servers and AI providers process your issues and docs in plaintext with Google Cloud-managed keys; Linear contractually rules out training on your data. VendorScore rates Linear 49/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Linear Enterprise workspace in the EU region, SAML/SCIM, IP restrictions, audit log, AI at defaults (no training; zero data retention where supported). No customer-managed key option.
Linear says it "encrypts data in-transit with TLS 1.2" and that "All data at-rest is secured using AES 256-bit encryption." The database is encrypted at rest and managed by Google Cloud Platform. We found no customer-managed key option, and Linear makes no E2EE claim.
Public docs don't say. Linear's DPA refers to an Access Control Policy that "can be provided upon request", but the policy isn't public, and we found no public description of staff or support access to workspace content and no customer-visible log of staff access.
No. Linear's AI Services Addendum says: "Linear will not use Customer Data, including Prompts or Outputs, to train, fine-tune, or otherwise improve Linear's own AI models." Its agreements require AI providers not to train on Customer Data and to process it in a zero-data-retention manner where that's commercially available and technically supported. Admin AI opt-outs persist unless you re-enable them. An older 'AI at Linear' FAQ mentions training and refining suggestions without saying whose data is used; the Addendum governs.
VendorScore doesn't certify compliance; Linear publishes a DPA at https://linear.app/dpa. It gives at least 30 days' email notice of new subprocessors and 30 days to object on reasonable data-protection grounds.
Linear's subprocessor list is Exhibit B of its DPA at https://linear.app/dpa (the standalone subprocessor page is JavaScript-only). It has 34 entries, including Google, Cloudflare and AWS for infrastructure; Anthropic, OpenAI, Fireworks AI, TypeSafe AI, Cohere and Braintrust for AI; Intercom and Pylon for support; and sales and marketing tools such as Gong, Outreach and HubSpot.
Yes, if chosen when the workspace is created; it isn't self-serve to change. Workspace info, user account data and API keys are always stored in the United States.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (linear.md), evidence dated 2026-10-07.