Snapshot 48787
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content Security Overview Last Modified: September 30, 2026 We take data security seriously. Every claim below is one we can show you evidence for, and where a control is still being built we say so rather than rounding it up. SOC 2 Type II We are preparing for SOC 2 Type II, including a third-party penetration test. Status is on our trust portal. GDPR A DPA that applies to every account automatically, Standard Contractual Clauses for EEA, UK and Swiss transfers, and an Article 27 EU representative. SSO and MFA SAML or OIDC with SCIM provisioning on Enterprise. Multi-factor authentication is available on every plan. Automated backups Daily backups of Customer Data, each retained for seven (7) days, encrypted and isolated from active processing. Encrypted by default TLS 1.2 or higher in transit and AES-256 or equivalent at rest, on every plan, with no configuration to switch on. Tenant isolation Customer data is logically isolated. Access runs through organization and project roles under least privilege. How we protect your data Encryption. We encrypt Customer Data in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent encryption standards. Access Control. We enforce logical isolation of customer data, role-based access controls, and least-privilege principles across all systems. Authentication. Multi-factor authentication (MFA) is available on all plans. Single sign-on (SSO) is available on the Enterprise plan. Backups. Intempt takes daily backups of Customer Data, retains each for seven (7) days and then deletes it as part of Intempt's standard data lifecycle procedures. Intempt also maintains data redundancy and infrastructure resilience controls appropriate to the Services; where infrastructure-level copies of data exist, they are encrypted and isolated from active processing. Monitoring. Intempt monitors its production infrastructure 24/7/365. Logs and metrics are centralized in Grafana, and alerts page a dedicated DevOps/SRE team on call around the clock through Better Stack. Secure Development. We follow a secure software development lifecycle (SDLC) that includes security reviews, dependency scanning, infrastructure hardening, and testing against the OWASP Top 10. Incident Response. The same DevOps/SRE team is Intempt's incident response team, following a defined process for escalation, containment, and remediation. Any security incident affecting a customer's account, or suspected loss or corruption of Customer Data, is treated as Severity 1 under the Service Level Agreement. In the event of a confirmed security incident involving Customer Data, we will notify affected customers within seventy-two (72) hours of confirmation, followed by a formal root cause analysis (RCA) and remediation plan. AI Data Protection. Intempt trains per-customer AI models exclusively within each customer's logically isolated tenant environment. Customer data is never used to train models serving other customers. Third-party AI subprocessors (OpenAI, Anthropic and Google Gemini) are prohibited under commercial API terms from using Customer Data to train their own models. Email Security. Intempt uses Google Workspace with enhanced security features for internal communications, including inbound email screening and attachment controls. Continuous application scanning. Every pull request across our repositories is automatically scanned before it can merge: static analysis of our own code (SAST), known-vulnerable and malicious open-source dependencies (SCA), and any secret or key accidentally committed. Critical and high findings carry defined remediation timelines and are tracked to closure. Cloud and container posture. Our AWS production account is monitored continuously for misconfiguration (cloud security posture management). Infrastructure-as-code and container images are scanned for insecure settings, and our Kubernetes cluster runs an in-cluster agent that scans running workloads and the images behind them. Source and supply-chain security. Code is hosted in GitHub with branch protection and mandatory review. Production branches cannot be force-pushed and move only by a controlled promotion. Build dependencies and CI actions are tracked and pinned to reduce supply-chain risk. Dynamic and manual testing. We run automated dynamic application security testing (DAST) against our public surface and internal penetration testing against the OWASP Top 10. Confirmed findings are triaged by severity and tracked to closure. A third-party penetration test is part of our SOC 2 Type II program. AI Model Security. Customer AI models are trained and stored within logically isolated per-customer environments. Access is restricted to authorized Intempt engineering personnel under least-privilege controls. Training pipelines are subject to Intempt's SDLC security review. Customer AI models are deleted within thirty (30) days of subscription termination. Compliance. Intempt is preparing for SOC 2 Type II, including a third-party penetration test. Frequently askedquestions. We design our products and processes with security in mind and follow industry-standard practices to keep your data safe. 01 / 08 Is Intempt SOC 2 compliant? We are preparing for SOC 2 Type II, including a third-party penetration test. The status is published on our trust portal. We are preparing for SOC 2 Type II, including a third-party penetration test. The status is published on our trust portal. Is your question not listed here? Get in touch at [email protected]. Report a security vulnerability Get in touch with our security team to disclose any security concern. We acknowledge reports and will keep you updated while we investigate. Please do not disclose an issue publicly before we have had a chance to fix it. Contact us Trust Portal: https://intempt.trustshare.com/ Contact: [email protected] | Intempt Technologies LLC, 1101 W 34th St #595, Austin, TX 78705