Security
Your data, and how we look after it
Research data carries obligations that are not ours to be casual about — sponsor terms, human-subjects protections, export control, and the trust of the people whose work it describes.

Certifications
What we can hand your procurement office
SOC 2 Type II
Certified against the AICPA's Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy. Type II means the controls were tested over a period, not photographed on one good day.
Request our SOC 2 report →HECVAT
The Higher Education Community Vendor Assessment Toolkit is how your procurement office compares vendors on a level field. Our completed documentation is available on request, so your review starts from a filled-in form.
Request our HECVAT →WCAG 2.2 AA
The interface conforms to WCAG 2.2 level AA. Research administration software is used by everyone at an institution, and an eRA system that a screen-reader user cannot complete a proposal in is not finished software.
Ask about accessibility →AWS Partner
Streamlyne runs on AWS as a Solution Provider partner, which is what lets us inherit the physical and network security controls of the platform rather than reinventing them.
Ask about our infrastructure →That is the complete list of our security attestations. If a vendor comparison you have been handed shows us holding something not on this page, it is wrong, and we would like to know where you got it.
Architecture
Choices made before the audit
One codebase, not a patchwork
Every module was built inside the same architecture. We have never acquired a product and stitched it into the suite — which matters here because the seams between bolted-together systems are where the workarounds, and the security surprises, live.
Your data stays in the cloud
All customer data is stored in the cloud. Some vendors describe themselves as fully cloud-based while keeping a portion of client data on-premises, which is a different risk profile than the one you were sold.
Customer data is segregated
Client data is segregated physically and/or logically, so an incident affecting one dataset does not reach the rest.
Zero data retention with AI providers
Lyn works inside your permission model — it sees only what the signed-in user can see, and every action it takes is logged and reviewable. Zero data retention is enabled with our AI providers: your data is never stored by the model and never used for training.
Running a security review?
Tell us which framework you are reviewing against and we will send the documentation rather than a sales deck. SOC 2 report, completed HECVAT, accessibility conformance — whichever of them your process needs.
Request security documentation