InmateLink trust center

Security and Data Protection

Security claims should describe what is actually implemented—not badges, absolutes, or future plans.

Effective and last updated: August 24, 2026.

This page is a current operational description, not a certification, audit report, warranty, or claim that every InmateLink feature is suitable for every category of sensitive information.

1

Current safeguards

  • InmateLink uses authenticated account access, encrypted network transport, access controls, database controls, logging, and feature-specific protections where implemented.
  • Private records are intended to be owner-scoped, and release testing checks unauthorized access and cross-account isolation for affected features in proportion to risk.
  • We minimize public release of unreviewed directory records and preserve source, identity, correction, and publication controls for governed data.
2

Your responsibility

  • Use a unique password through the enabled identity provider, protect your device and email account, sign out of shared devices, and report suspected unauthorized access promptly.
  • Check recipients, permissions, links, and displayed privacy status before inviting, saving, exporting, or sharing anything.
  • Do not bypass access controls, probe other accounts, upload malware, automate abusive traffic, or disclose a vulnerability publicly before giving us a reasonable opportunity to investigate.
3

Sensitive-data limits

  • LifeLink and ordinary InmateLink fields are not a general password manager. Do not enter passwords, recovery codes, private keys, full payment credentials, or full account numbers.
  • Do not enter government identifiers, medical records, private case files, information about children, or person-level custody information unless the exact enabled feature requests it and clearly describes the applicable safeguards and purpose.
  • Messaging, file upload, payment, advertising, monitoring, and notification capabilities must not be assumed unless the specific live screen says they are enabled.
4

No absolute security

No service can guarantee that every transmission, account, provider, integration, backup, device, or stored record will remain secure or continuously available. InmateLink does not claim “bank-level,” “military-grade,” PCI, HIPAA, GDPR, CCPA, or other certification or compliance status merely because a technical control or policy exists.

5

Security reports

  • Email support@inmatelink.com with “Security report,” the affected URL or feature, time observed, impact, and safe reproduction details.
  • Do not access, alter, retain, or disclose more data than needed to demonstrate the issue. Do not use social engineering, denial of service, destructive testing, or real-person sensitive records.
  • We will triage credible reports, preserve appropriate evidence, contain and remediate where warranted, and provide notices required by applicable law.