Security

Your data, and how we look after it

Research data carries obligations that are not ours to be casual about — sponsor terms, human-subjects protections, export control, and the trust of the people whose work it describes.

SOC 2 Type II certifiedHECVAT — Higher Education Community Vendor Assessment ToolkitW3C WAI-AA WCAG 2.2 conformanceAWS Partner — Solution Provider

Certifications

What we can hand your procurement office

SOC 2 Type II

Certified against the AICPA's Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy. Type II means the controls were tested over a period, not photographed on one good day.

Request our SOC 2 report →

HECVAT

The Higher Education Community Vendor Assessment Toolkit is how your procurement office compares vendors on a level field. Our completed documentation is available on request, so your review starts from a filled-in form.

Request our HECVAT →

WCAG 2.2 AA

The interface conforms to WCAG 2.2 level AA. Research administration software is used by everyone at an institution, and an eRA system that a screen-reader user cannot complete a proposal in is not finished software.

Ask about accessibility →

AWS Partner

Streamlyne runs on AWS as a Solution Provider partner, which is what lets us inherit the physical and network security controls of the platform rather than reinventing them.

Ask about our infrastructure →

That is the complete list of our security attestations. If a vendor comparison you have been handed shows us holding something not on this page, it is wrong, and we would like to know where you got it.

Architecture

Choices made before the audit

One codebase, not a patchwork

Every module was built inside the same architecture. We have never acquired a product and stitched it into the suite — which matters here because the seams between bolted-together systems are where the workarounds, and the security surprises, live.

Your data stays in the cloud

All customer data is stored in the cloud. Some vendors describe themselves as fully cloud-based while keeping a portion of client data on-premises, which is a different risk profile than the one you were sold.

Customer data is segregated

Client data is segregated physically and/or logically, so an incident affecting one dataset does not reach the rest.

Zero data retention with AI providers

Lyn works inside your permission model — it sees only what the signed-in user can see, and every action it takes is logged and reviewable. Zero data retention is enabled with our AI providers: your data is never stored by the model and never used for training.

Running a security review?

Tell us which framework you are reviewing against and we will send the documentation rather than a sales deck. SOC 2 report, completed HECVAT, accessibility conformance — whichever of them your process needs.

Request security documentation