Trust & Security

BailLink handles sensitive information at every step of the bail process — personal identifiers, signatures, payment details, and legal documents. Trust is not a marketing word for us; it's the table stakes of operating in this industry. This page describes how we approach security, what our infrastructure looks like at a high level, and how compliance responsibilities are divided between BailLink, our vendors, and our Agency Customers.

Our Security Philosophy

What We Protect Against

The threats we design against include credential theft, unauthorized access between tenants, leakage of sensitive identifiers (SSN, ID images, signatures), payment fraud, abuse of public endpoints, phishing of indemnitors, and accidental exposure through misconfiguration.

Architecture, at a High Level

We avoid publishing low-level architecture details, but here is what is relevant to assessing our posture:

Tenant Isolation

Every Agency Customer operates within its own logical tenant. Tenant isolation is enforced at the database level using row-level security policies — not just at the application layer — so queries cannot accidentally cross tenant boundaries. Storage objects are scoped to tenant paths and accessed only through short-lived signed URLs.

Authentication

Agency users authenticate through a dedicated identity provider with support for strong password policies, email verification, and multi-factor authentication. Platform administrators authenticate separately, with role-based access controls. Bond parties (indemnitors, defendants) do not have permanent accounts — they access the Service only through single-use, time-limited, IP-bound magic links sent by the Agency Customer.

Data Encryption

Payments

Card and bank data are collected, tokenized, and processed by Stripe. BailLink never sees a full card number. Funds flow directly to the Agency Customer's Stripe Connect account; BailLink does not hold customer funds and is not a money transmitter.

Document Integrity

Generated documents (applications, indemnity agreements, receipts) are immutable once executed and are payment-gated when applicable, meaning final documents are not released until the associated premium is paid.

Abuse Prevention

We rate-limit public-facing and signing endpoints, use bot-protection challenges on public forms, monitor for anomalous traffic, and operate background jobs in an isolated job runner.

Monitoring

Application errors and security-relevant events are tracked. We deliberately exclude the following from operational logs: full Social Security numbers, full dates of birth, signature images, and uploaded government-ID images.

Subprocessors

We rely on a curated set of third-party providers, each chosen for its security track record. These include providers for identity, database and file storage, payment processing, transactional email, SMS messaging, mapping, background processing, rate limiting, hosting, error monitoring, and bot protection. A current named list is available on request at support@baillinkusa.com.

Compliance Framework

BailLink itself is not a certifying body, and the bail industry does not have a single overarching federal compliance framework comparable to HIPAA in healthcare. Our compliance posture is built on:

Where Agency Customers operate in states with bail-specific recordkeeping or licensing requirements, the Agency Customer remains responsible for that compliance; BailLink provides tools (audit logs, document retention, exports) that support those obligations.

Shared Responsibility

Security and compliance work because every party does its part:

BailLink's responsibility:

Vendor (subprocessor) responsibility:

Agency Customer responsibility:

Reporting a Vulnerability

If you believe you have found a security vulnerability in the Service, please email support@baillinkusa.com with details. We ask that you give us reasonable time to investigate and remediate before public disclosure, and that you do not access or alter data belonging to anyone other than yourself during testing.

Reporting an Incident or Suspected Account Compromise

If you suspect your account has been compromised, or you believe sensitive information has been exposed, contact us immediately at support@baillinkusa.com or 954-860-8225.

Updates

We update this page as our practices evolve. The most recent revision date is reflected at the bottom of each major section in our policies. For specific questions, reach out at the contacts above.

Bail Link LLC Phone: 954-860-8225 General: info@baillinkusa.com Security & Technical: support@baillinkusa.com