How your trust story reads from the public web
vs. Asana, monday.com, Shortcut
One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about Linear's actual security.
This edition documents two narrow gaps in an otherwise complete surface; Linear was not asked and is not being pitched.
The short version
Linear answers 18 of the 20 standard reviewer topics from the public web — through a trust center with a 70-control public inventory and dated 2026 pentest summaries, a public subprocessor list, and a full-text, footer-linked DPA. The two open topics are narrow — the Enterprise uptime-SLA figure and vendor risk management detail — and the five-minute first pass ends on an owned trust page for all four companies in this table.
Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for Linear, on 2026-09-02:
At this point the reviewer has formed a first impression of Linear as a vendor — before anyone at Linear knows the review has started.
All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.
| Observable artifact | Linear | Asana | monday.com | Shortcut |
|---|---|---|---|---|
| Public trust/security page | Publishedlinear.app/security, footer-linked; trust center at trust.linear.app with a 70-control public inventory | Publishedasana.com/trust, footer-linked; trust center at trustcenter.asana.com with 36 documents and 58 public FAQs | Publishedmonday.com/trustcenter, footer-linked; compliance hub at trust.monday.com | Publishedshortcut.com/security, linked from nav and footer |
| SOC 2 visibility & report path | PublishedType II stated on linear.app/security; report (2025-11), bridge letter (2026-08), and ISO 27001:2022 certificate (2026-04) via self-serve request gate at trust.linear.app | PublishedType 2 + HIPAA report (2026) and SOC 3 listed at trustcenter.asana.com behind a self-serve "Get Access" gate | PublishedSOC 1, 2 and 3 (FY25, posted 2025-11-26) via self-serve gate with bulk download at trust.monday.com | PublishedType 2 stated on shortcut.com/security; report by emailing security@shortcut.com |
| Security answers available publicly | topics (linear.app/security, trust.linear.app, linear.app/dpa) | topics (asana.com/terms/security-standards, trustcenter.asana.com) | topics (trust.monday.com, support.monday.com) | topics (shortcut.com/security, shortcut.com/pricing) |
| Subprocessor list & DPA | Publishedsubprocessor list on the trust center with dated change entries; full-text DPA at linear.app/dpa, footer-linked, subprocessors in Exhibit B with 30-day advance notice | Publishedasana.com/terms/subprocessors (updated 2026-08-31) with change subscription; DPA at asana.com/terms/data-processing | Publishedmonday.com/terms/subprocessors (updated 2026-06-24); DPA at monday.com/terms/dpa with self-serve signing | Partialsubprocessor list at shortcut.com/gdpr-subprocessors (updated 2025-11-12); no public DPA found |
| Enterprise signals on pricing page | Published"SAML and SCIM," "IP restrictions," "Audit log," "HIPAA compliance," "Uptime SLA" on Enterprise (linear.app/pricing); the SLA names no figure | PublishedSAML and Audit Log API on Advanced; SCIM and "99.9% uptime SLA" on Enterprise; IP allowlisting, data residency, and HIPAA on Enterprise+ (asana.com/pricing) | Partial"Enterprise-grade security & governance," "99.9% uptime SLA," and HIPAA named; SAML, SCIM, and audit logs not named on the pricing page (monday.com/pricing) | PublishedSAML SSO and SCIM (add-on on Business, included on Enterprise), HIPAA on Enterprise; no uptime SLA or audit log named (shortcut.com/pricing) |
| Column summary | 4/4 published · 18/20 topics | 4/4 published · 20/20 topics | 3/4 published · 20/20 topics | 3/4 published · 10/20 topics |
This is the most trust-mature set the series has benchmarked: four trust pages, four stated SOC 2 attestations, four subprocessor lists. Linear matches the leaders on every artifact row, publishes the set's most granular self-serve evidence — the 70-control inventory — and trails only on the answerability count, where Asana and monday.com start at 20/20.
Exhibit
Enterprise — SAML and SCIM · IP restrictions · Audit log · HIPAA compliance
Enterprise tier, feature list
“Uptime SLA”
The tier names an SLA; the figure lives in the contract. The two competitors that publish one print the number.
Recreated from linear.app/pricing as observed 2026-09-02. "Uptime SLA" is the one enterprise feature listed without a stated value.
Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, Linear starts with 18/20 topics answerable self-serve; Asana starts at 20/20 — the difference is round-trips.
Topic-by-topic (public web only):
Publicly answered (18): encryption at rest and in transit (AES 256, TLS 1.2 — linear.app/security), SSO/SAML and SCIM (linear.app/security and pricing), subprocessor list (trust.linear.app/subprocessors; also Exhibit B of the DPA), data residency (EU or US hosting, linear.app/security), pentest cadence ("at least annually," two dated 2026 summaries, trust.linear.app), DPA (full text at linear.app/dpa, dated 2025-05-31), compliance report access path (self-serve request gate, trust.linear.app), and ten operational topics — access control, backups, incident response, vulnerability management, employee security training, BC/DR, data retention/deletion, change management, logging/monitoring, and physical/hosting security detail — each stated as a named, described control on trust.linear.app/controls.
Not publicly answerable (2): the uptime SLA — named on the Enterprise tier, but the figure and terms are stated nowhere a logged-out visitor can reach — and vendor risk management, where the closest public statement is a "Third-party agreements established" control line: it records that agreements exist, not how vendors are reviewed. A topic that can't fill a questionnaire field counts as not answerable.
Reads well: most of the page. The trust center publishes control descriptions rather than badges alone; the subprocessor list carries dated change entries (2026-05-13, 2026-08-19) and the DPA commits to thirty days' advance notice plus a subscription mechanism; the SOC 2 attestation has sat on Linear's own changelog since 2021-10-21; and the EU-or-US region choice is stated at workspace creation. The two open topics above are the whole of the gap.
Which topics counted toward each company's publicly answerable score in the table above.