Workflow agent Lindy publishes approval gates for outside-facing actions; SOC 2, GDPR and HIPAA remain self-declared, no insurance disclosed
The Slack, iMessage and browser-based automation agent says nothing irreversible happens without a named approver and scopes its own channel visibility; SOC 2 Type II, GDPR, HIPAA and PIPEDA compliance is asserted on the vendor's own page with no certificate, auditor or report date, and no insurance or liability-cover term is published.
Lindy, a workflow agent that operates in Slack, iMessage and the browser, publishes narrower run-time restrictions than most agentic tools AI Dispatch has reviewed. "Anything with outside impact waits for a named approver: sending an email, updating a ticket, posting to another channel, publishing a doc," the company says. Elsewhere it states plainly: "Nothing irreversible happens without your approval."
The vendor positions Lindy as completing work rather than assisting with it: "Most of them stop at a draft. Lindy finishes the job." A cited example handoff has the agent updating HubSpot, writing a Notion doc, posting to a Slack channel, booking a meeting and sending a welcome email in sequence. It also runs unprompted on a schedule: "Shows up on schedule. Whatever you do on repeat, hand it to Lindy on a schedule."
Its access to Slack is scoped by channel type: "Public channels once it's in your workspace. Private channels only if a channel manager invites it. It never sees archived channels, and never anyone's personal DMs." On data use, the company says "Your data is never sold and never used for training."
Compliance is asserted but not documented. The page states "SOC 2 Type II, GDPR, HIPAA, and PIPEDA, encrypted in transit and at rest" and separately that "Lindy is SOC 2 and GDPR compliant, and Enterprise adds HIPAA with a signed BAA." No certificate, named auditor, SOC 2 type detail beyond "Type II," or report date accompanies either claim on the pages AI Dispatch reviewed. The company's only audit-trail claim is a single feature-list line, "Audit logs," with no retention period, scope or tamper-evidence description attached.
Pricing tracks seats and usage rather than results: "Plans start at $29.99 per user per month with 3,000 credits," pooled across a workspace. No insurance carrier, coverage limit or customer indemnity appears on the pages reviewed, and no mechanism ties payment to a verified outcome.
Lindy's approval-gate and channel-scoping disclosures are more specific about run-time behavior than most vendors in this category. That specificity does not extend to the compliance claims sitting beside it, which are self-declared, or to insurance, which is undisclosed.
Entries in this piece 1
Published index entries backed by the same source documents this piece cites.
Sources 11
“Anything with outside impact waits for a named approver: sending an email, updating a ticket, posting to another channel, publishing a doc.”
lindy.ai · checked Aug 10, 2026“Nothing irreversible happens without your approval.”
lindy.ai · checked Aug 10, 2026“Most of them stop at a draft. Lindy finishes the job.”
lindy.ai · checked Aug 10, 2026“Updates HubSpot Writes the Notion doc Posts to #customer-success Books the kickoff Sends the welcome email”
lindy.ai · checked Aug 10, 2026“Shows up on schedule. Whatever you do on repeat, hand it to Lindy on a schedule.”
lindy.ai · checked Aug 10, 2026“Public channels once it's in your workspace. Private channels only if a channel manager invites it. It never sees archived channels, and never anyone's personal DMs.”
lindy.ai · checked Aug 10, 2026“Your data is never sold and never used for training.”
lindy.ai · checked Aug 10, 2026“SOC 2 Type II, GDPR, HIPAA, and PIPEDA, encrypted in transit and at rest.”
lindy.ai · checked Aug 10, 2026“Lindy is SOC 2 and GDPR compliant, and Enterprise adds HIPAA with a signed BAA.”
lindy.ai · checked Aug 10, 2026“Audit logs”
lindy.ai · checked Aug 1, 2026“Plans start at $29.99 per user per month with 3,000 credits.”
lindy.ai · checked Aug 10, 2026