GRANWORTH Benchmarked 2026-09-02 · Public web only
THE GRANWORTH INDEX Enterprise Trust Benchmark · 2026-09-02 edition

How your trust story reads from the public web

Linear

vs. Asana, monday.com, Shortcut

One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about Linear's actual security.

This edition documents two narrow gaps in an otherwise complete surface; Linear was not asked and is not being pitched.

The short version

Linear answers 18 of the 20 standard reviewer topics from the public web — through a trust center with a 70-control public inventory and dated 2026 pentest summaries, a public subprocessor list, and a full-text, footer-linked DPA. The two open topics are narrow — the Enterprise uptime-SLA figure and vendor risk management detail — and the five-minute first pass ends on an owned trust page for all four companies in this table.

What an enterprise security reviewer sees in the first 5 minutes

Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for Linear, on 2026-09-02:

  1. Search "Linear security" / "Linear trust center": top results are Linear-owned — linear.app/security, the docs' security section, and trust.linear.app; no third-party page outranks them.
  2. Site footer/nav: linear.app links Security under Product and the DPA under Legal; the security page links the trust center.
  3. Attestation path: SOC 2 Type II and ISO 27001:2022 stated on linear.app/security; the Type II report (2025-11), a bridge letter (2026-08), and the ISO certificate (2026-04) sit behind a self-serve request gate at trust.linear.app.
  4. Standard questionnaire topics answerable publicly: 18/20 — encryption, subprocessors, DPA, pentest cadence, and incident response are all answered; the uptime-SLA figure and vendor risk management detail are not (full list in the appendix).
  5. Pricing page, Enterprise tier: names "SAML and SCIM," "IP restrictions," "Audit log," "HIPAA compliance," and "Uptime SLA" (linear.app/pricing) — the SLA line carries no figure.

At this point the reviewer has formed a first impression of Linear as a vendor — before anyone at Linear knows the review has started.

Side by side

All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.

Observable trust artifacts, Linear compared with Asana, monday.com, Shortcut
Observable artifact Linear Asana monday.com Shortcut
Public trust/security page Publishedlinear.app/security, footer-linked; trust center at trust.linear.app with a 70-control public inventory Publishedasana.com/trust, footer-linked; trust center at trustcenter.asana.com with 36 documents and 58 public FAQs Publishedmonday.com/trustcenter, footer-linked; compliance hub at trust.monday.com Publishedshortcut.com/security, linked from nav and footer
SOC 2 visibility & report path PublishedType II stated on linear.app/security; report (2025-11), bridge letter (2026-08), and ISO 27001:2022 certificate (2026-04) via self-serve request gate at trust.linear.app PublishedType 2 + HIPAA report (2026) and SOC 3 listed at trustcenter.asana.com behind a self-serve "Get Access" gate PublishedSOC 1, 2 and 3 (FY25, posted 2025-11-26) via self-serve gate with bulk download at trust.monday.com PublishedType 2 stated on shortcut.com/security; report by emailing security@shortcut.com
Security answers available publicly topics (linear.app/security, trust.linear.app, linear.app/dpa) topics (asana.com/terms/security-standards, trustcenter.asana.com) topics (trust.monday.com, support.monday.com) topics (shortcut.com/security, shortcut.com/pricing)
Subprocessor list & DPA Publishedsubprocessor list on the trust center with dated change entries; full-text DPA at linear.app/dpa, footer-linked, subprocessors in Exhibit B with 30-day advance notice Publishedasana.com/terms/subprocessors (updated 2026-08-31) with change subscription; DPA at asana.com/terms/data-processing Publishedmonday.com/terms/subprocessors (updated 2026-06-24); DPA at monday.com/terms/dpa with self-serve signing Partialsubprocessor list at shortcut.com/gdpr-subprocessors (updated 2025-11-12); no public DPA found
Enterprise signals on pricing page Published"SAML and SCIM," "IP restrictions," "Audit log," "HIPAA compliance," "Uptime SLA" on Enterprise (linear.app/pricing); the SLA names no figure PublishedSAML and Audit Log API on Advanced; SCIM and "99.9% uptime SLA" on Enterprise; IP allowlisting, data residency, and HIPAA on Enterprise+ (asana.com/pricing) Partial"Enterprise-grade security & governance," "99.9% uptime SLA," and HIPAA named; SAML, SCIM, and audit logs not named on the pricing page (monday.com/pricing) PublishedSAML SSO and SCIM (add-on on Business, included on Enterprise), HIPAA on Enterprise; no uptime SLA or audit log named (shortcut.com/pricing)
Column summary 4/4 published · 18/20 topics 4/4 published · 20/20 topics 3/4 published · 20/20 topics 3/4 published · 10/20 topics

This is the most trust-mature set the series has benchmarked: four trust pages, four stated SOC 2 attestations, four subprocessor lists. Linear matches the leaders on every artifact row, publishes the set's most granular self-serve evidence — the 70-control inventory — and trails only on the answerability count, where Asana and monday.com start at 20/20.

Exhibit

Enterprise — SAML and SCIM · IP restrictions · Audit log · HIPAA compliance

Enterprise tier, feature list

“Uptime SLA”

The tier names an SLA; the figure lives in the contract. The two competitors that publish one print the number.

Recreated from linear.app/pricing as observed 2026-09-02. "Uptime SLA" is the one enterprise feature listed without a stated value.

What this costs in a security review

Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, Linear starts with 18/20 topics answerable self-serve; Asana starts at 20/20 — the difference is round-trips.

Full findings

Topic-by-topic (public web only):

Publicly answered (18): encryption at rest and in transit (AES 256, TLS 1.2 — linear.app/security), SSO/SAML and SCIM (linear.app/security and pricing), subprocessor list (trust.linear.app/subprocessors; also Exhibit B of the DPA), data residency (EU or US hosting, linear.app/security), pentest cadence ("at least annually," two dated 2026 summaries, trust.linear.app), DPA (full text at linear.app/dpa, dated 2025-05-31), compliance report access path (self-serve request gate, trust.linear.app), and ten operational topics — access control, backups, incident response, vulnerability management, employee security training, BC/DR, data retention/deletion, change management, logging/monitoring, and physical/hosting security detail — each stated as a named, described control on trust.linear.app/controls.

Not publicly answerable (2): the uptime SLA — named on the Enterprise tier, but the figure and terms are stated nowhere a logged-out visitor can reach — and vendor risk management, where the closest public statement is a "Third-party agreements established" control line: it records that agreements exist, not how vendors are reviewed. A topic that can't fill a questionnaire field counts as not answerable.

Reads well: most of the page. The trust center publishes control descriptions rather than badges alone; the subprocessor list carries dated change entries (2026-05-13, 2026-08-19) and the DPA commits to thirty days' advance notice plus a subscription mechanism; the SOC 2 attestation has sat on Linear's own changelog since 2021-10-21; and the EU-or-US region choice is stated at workspace creation. The two open topics above are the whole of the gap.

Appendix — topic ledger

Which topics counted toward each company's publicly answerable score in the table above.

Linear 18/20
encryption at rest · encryption in transit · SSO/SAML · subprocessor list · data residency · pentest cadence · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Asana 20/20
encryption at rest · encryption in transit · SSO/SAML · uptime SLA · subprocessor list · data residency · pentest cadence · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · vendor risk management · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
monday.com 20/20
encryption at rest · encryption in transit · SSO/SAML · uptime SLA · subprocessor list · data residency · pentest cadence · DPA · access control · backups · incident response · vulnerability management · employee security training · BC/DR · vendor risk management · data retention/deletion · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Shortcut 10/20
encryption at rest · encryption in transit · SSO/SAML · subprocessor list · access control · backups · change management · logging/monitoring · physical/hosting security detail · compliance report access path