Panelynx

Security

Security at Panelynx

How we protect your data, who can reach it, and the controls we build into the product.

Last updated June 2026

Tenant isolation

Each customer's data is logically separated and scoped to their own tenant.

Encryption in transit and at rest

TLS in transit, and encryption at rest with managed keys.

SAML 2.0 single sign-on

Your team signs in through your own identity provider, with your policies.

GDPR support

We help you handle data-subject requests, exports, and deletion.

Scoped access controls

Role-based access so people see only what they should.

Responsible disclosure

A clear channel to report security issues directly to our team.

Our approach

Panelynx is built so the interview itself is structured, consistent, and reviewable. Security is part of that, not an afterthought. This page describes how we handle and protect your data.

Panelynx is new and not yet ISO 27001 certified. We are built to align with it and will fully support your own certification and security review.

Hosting and infrastructure

Customer data is hosted on managed cloud infrastructure with redundancy across availability zones and regular automated backups.

  • Redundancy across availability zones
  • Automated, retained backups
  • Managed, patched infrastructure

Encryption

Data is encrypted in transit using TLS and at rest using managed keys. Key management and rotation follow documented procedures.

Tenant isolation

Each customer is a separate tenant. Data is logically separated and scoped to its tenant, so one customer's data is not reachable from another's.

Access and sign-in

Access is role-based and scoped to the minimum needed. Administrative access is limited and reviewed. Sign-in runs through Clerk, our authentication provider.

Single sign-on

SAML 2.0 single sign-on is available so your team signs in through your own identity provider, with your own policies enforced.

AI and your data

AI in Panelynx is assistive and human-final. It parses what you upload, drafts content for a person to edit, and reads a transcript after you upload it to offer a second opinion. It never makes the decision.

AI features run via the Anthropic Claude API. Your data is not used to train models, and logging is limited to operational metadata.

Responsible disclosure

If you believe you've found a security issue, please contact us so we can investigate and respond quickly. We appreciate good-faith reports.

Contact

For security questions, a security review, or to request our subprocessor list and DPA, reach our team using the details below.