Session protection
LinkedIn session cookies are sent to Line1 over HTTPS and encrypted on the server for storage. Line1 decrypts them when needed to make requests on your behalf.
Disconnecting through the extension clears the stored session credentials from the active account record. You can also revoke the session in LinkedIn's settings. Disconnecting does not delete previously collected workspace data; see our Privacy Policy for deletion requests.
Access controls
Clerk handles sign-in. Server-side authorization checks use your workspace membership and role to control access to workspace data and administrative actions. Database access policies provide additional restrictions on tenant-scoped data.
Responsible disclosure
Report suspected vulnerabilities to [email protected]. Include the affected feature, reproduction steps, and potential impact, without sharing credentials or other people's data.
Safe harbor. We will not take legal action against researchers who act in good faith within the scope below. Stay within your own test workspace, do not access data that is not yours, and give us reasonable time to remediate before public disclosure.
In scope:
- Authentication, session handling, and credential protection.
- Workspace isolation and authorization, including unauthorized object access or role escalation.
- Injection vulnerabilities in Line1, including SQL injection, cross-site scripting, and server-side request forgery.
Out of scope:
- Denial-of-service, resource-exhaustion testing, and high-volume scraping.
- Testing with live LinkedIn session credentials, or activity that abuses or risks a LinkedIn account.
- Third-party systems, including LinkedIn and our service providers. Report those issues to the provider.
- Spam and social engineering of staff or customers.
- Automated-scanner output without demonstrated, exploitable impact.