Security Overview
Last Modified: August 2026
We take data security seriously. Every claim below is one we can show you evidence for, and where a control is still being built we say so rather than rounding it up.
SOC 2 Type II
In progress, targeting Q1 2027. Controls, evidence and the audit timeline are published on our trust portal.
GDPR
A signed DPA, Standard Contractual Clauses for EEA, UK and Swiss transfers, and an Article 27 EU representative.
SSO and MFA
SAML or OIDC with SCIM provisioning on Enterprise. Multi-factor authentication is available on every plan.
Automated backups
Standard backups of Customer Data are retained for fourteen (14) days, encrypted and isolated from active processing.
Encrypted by default
TLS 1.2 or higher in transit and AES-256 or equivalent at rest, on every plan, with no configuration to switch on.
Tenant isolation
Customer data is logically isolated. Access runs through organization and project roles under least privilege.
How we protect your data
Encryption. We encrypt Customer Data in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent encryption standards.
Access Control. We enforce logical isolation of customer data, role-based access controls, and least-privilege principles across all systems.
Authentication. Multi-factor authentication (MFA) is available on all plans. Single sign-on (SSO) is available on the Enterprise plan.
Backups. Intempt maintains standard backups of Customer Data, retained for fourteen (14) days and then deleted as part of Intempt's standard data lifecycle procedures. Intempt also maintains data redundancy and infrastructure resilience controls appropriate to the Services; where infrastructure-level copies of data exist, they are encrypted and isolated from active processing.
Monitoring. Intempt maintains continuous observability of its infrastructure using Grafana, with automated on-call escalation via BetterStack and 24/7 DevOps/SRE coverage. Further security monitoring capabilities, including SIEM integration and SOC-level coverage, are on Intempt's security roadmap.
Secure Development. We follow a secure software development lifecycle (SDLC) that includes security reviews, dependency scanning, infrastructure hardening, and testing against the OWASP Top 10.
Incident Response. Intempt maintains a formal incident response process, built on continuous observability (Grafana) and automated escalation (BetterStack) with 24/7 DevOps/SRE on-call coverage, with defined escalation, containment, and remediation procedures. In the event of a confirmed security incident involving Customer Data, we will notify affected customers within seventy-two (72) hours of confirmation, where feasible. As part of our SOC 2 Type II certification project, we continue to formalize and expand this process's documentation.
AI Data Protection. Intempt trains per-customer AI models exclusively within each customer's logically isolated tenant environment. Customer data is never used to train models serving other customers. Third-party AI subprocessors (OpenAI and Anthropic) are prohibited under commercial API terms from using Customer Data to train their own models.
Roadmap
SOC 2 Type II certification is a compliance priority with a target completion of Q1 2027.
Email Security. Intempt uses Google Workspace with enhanced security features for internal communications, including inbound email screening and attachment controls.
Vulnerability Scanning. Intempt is implementing automated vulnerability scanning of its cloud infrastructure using AWS-native security tooling. Critical and high vulnerabilities identified will be remediated within defined timelines.
AI Model Security. Customer AI models are trained and stored within logically isolated per-customer environments. Access is restricted to authorized Intempt engineering personnel under least-privilege controls. Training pipelines are subject to Intempt's SDLC security review. Customer AI models are deleted within thirty (30) days of subscription termination.
Frequently askedquestions.
We design our products and processes with security in mind and follow industry-standard practices to keep your data safe.
- Not yet. SOC 2 Type II is our current compliance priority, with a target completion of Q1 2027. We are formalizing and documenting the controls now, and the status is published on our trust portal. We will not describe ourselves as certified before the report exists.
Is your question not listed here? Get in touch at hey@intempt.com.
Report a security vulnerability
Get in touch with our security team to disclose any security concern. We acknowledge reports and will keep you updated while we investigate. Please do not disclose an issue publicly before we have had a chance to fix it.
Contact usTrust Portal: https://intempt.trustshare.com/
Contact: hey@intempt.com | Intempt Technologies LLC, 1101 W 34th St #595, Austin, TX 78705