InmateLink trust center
Security and Data Protection
Security claims should describe what is actually implemented—not badges, absolutes, or future plans.
Effective and last updated: August 24, 2026.
This page is a current operational description, not a certification, audit report, warranty, or claim that every InmateLink feature is suitable for every category of sensitive information.
1
Current safeguards
- InmateLink uses authenticated account access, encrypted network transport, access controls, database controls, logging, and feature-specific protections where implemented.
- Private records are intended to be owner-scoped, and release testing checks unauthorized access and cross-account isolation for affected features in proportion to risk.
- We minimize public release of unreviewed directory records and preserve source, identity, correction, and publication controls for governed data.
2
Your responsibility
- Use a unique password through the enabled identity provider, protect your device and email account, sign out of shared devices, and report suspected unauthorized access promptly.
- Check recipients, permissions, links, and displayed privacy status before inviting, saving, exporting, or sharing anything.
- Do not bypass access controls, probe other accounts, upload malware, automate abusive traffic, or disclose a vulnerability publicly before giving us a reasonable opportunity to investigate.
3
Sensitive-data limits
- LifeLink and ordinary InmateLink fields are not a general password manager. Do not enter passwords, recovery codes, private keys, full payment credentials, or full account numbers.
- Do not enter government identifiers, medical records, private case files, information about children, or person-level custody information unless the exact enabled feature requests it and clearly describes the applicable safeguards and purpose.
- Messaging, file upload, payment, advertising, monitoring, and notification capabilities must not be assumed unless the specific live screen says they are enabled.
4
No absolute security
No service can guarantee that every transmission, account, provider, integration, backup, device, or stored record will remain secure or continuously available. InmateLink does not claim “bank-level,” “military-grade,” PCI, HIPAA, GDPR, CCPA, or other certification or compliance status merely because a technical control or policy exists.
5
Security reports
- Email support@inmatelink.com with “Security report,” the affected URL or feature, time observed, impact, and safe reproduction details.
- Do not access, alter, retain, or disclose more data than needed to demonstrate the issue. Do not use social engineering, denial of service, destructive testing, or real-person sensitive records.
- We will triage credible reports, preserve appropriate evidence, contain and remediate where warranted, and provide notices required by applicable law.