Security & Trust

Security, built in.
Not bolted on.

At Intelipi, we handle business-critical documents, operational records and customer data. Security is built into how that data is stored, processed, isolated and accessed, not added afterward. This page describes our current practices, the infrastructure we run on, and where we're headed.

At a Glance

The short version.

Encryption in transit TLS 1.2+ on all connections
Encryption at rest AES-256
Data residency Singapore by default; other regions and single-tenant options available
Tenant isolation Multi-tenant with tenant-level isolation; single-tenant available
Authentication Single sign-on via Microsoft and Google; MFA inherited from your identity provider
Customer data used to train AI models No, not by us, and not by our AI provider
Source traceability Every AI answer links back to the underlying document
SOC 2 Not yet certified; controls being built toward SOC 2 readiness
Data Processing Agreement (GDPR) Available on request

Data Protection

Encrypted in transit and at rest.

All customer data is encrypted both in transit and at rest. Connections to Intelipi are secured with TLS 1.2 or higher, and stored data, including uploaded documents, extracted metadata and related operational records, is encrypted at rest using AES-256.

Data is hosted in Singapore by default. For customers with specific residency, compliance or isolation requirements, we can host in other regions or provide single-tenant deployments in which the customer environment is logically and operationally separated from all other tenants.

Infrastructure & Subprocessors

A small, deliberate set of providers.

Intelipi runs on a small, deliberately chosen set of infrastructure providers. We keep this list current so customers always know who processes their data.

Hetzner — Hosting & compute

Operates its own data centers and offers a GDPR Data Processing Agreement. Its data center operations are independently certified to ISO/IEC 27001 and BSI C5.

Cloudflare — Edge, DDoS & CDN

Provides our edge network, DDoS protection and content delivery, backed by a broad set of independent security certifications including SOC 2 Type II, ISO/IEC 27001, ISO 27701 and PCI DSS.

Anthropic — AI processing

Powers document classification, metadata extraction and question answering. Content is processed under Anthropic's Commercial Terms: it is not used to train models, and is retained only briefly to operate the service.

AI & Model Training

Your data never trains a model.

Your documents and data are never used to train AI models, not by us, and not by our AI provider. Intelipi uses Anthropic's Claude models to classify documents, extract metadata and answer questions. Content processed through Anthropic's API is governed by Anthropic's Commercial Terms: Anthropic does not use commercial API inputs or outputs to train its models, and retains them only briefly to operate the service.

We also do not use your documents, extracted content, prompts, answers or activity to train any general-purpose models of our own. This data is processed for one purpose only: to provide the Intelipi service to you. You can review Anthropic's policy directly here.

Wherever AI is used, Intelipi preserves source traceability. Every AI-generated answer links back to the document or record it was drawn from, so you can verify the source rather than rely on an unsupported response.

Access Control & Authentication

Granular access. Your identity provider.

Role-based access control (RBAC)

RBAC governs what a user can do, such as viewing documents, managing workflows, approving tasks or administering settings.

Attribute-based access control (ABAC)

ABAC governs which documents and records a user can reach, based on document attributes, user attributes, tenant rules, business units, tags or other configured conditions.

Together, these let organizations define granular policies that reflect real operational boundaries: department, document type, customer, supplier, project, shipment, location or approval responsibility.

Access is through single sign-on (SSO). We support Microsoft and Google as identity providers, so users sign in with existing organizational accounts, with no separate Intelipi passwords to create, store or manage. Because authentication is delegated to your identity provider, your existing security policies apply directly at sign-in, including multi-factor authentication (MFA) and conditional access rules you already enforce.

Isolation, Backups & Retention

Separated by tenant. Recoverable by design.

Tenant isolation

Intelipi is a multi-tenant platform with tenant-level data isolation. Each customer's documents, metadata, workflows, users, permissions and operational records are separated at the tenant level. For stricter requirements, we offer single-tenant deployments with dedicated application and data environments.

Backups & retention

We maintain backup and recovery practices designed to protect against accidental data loss and service disruption. For enterprise and single-tenant deployments, backup frequency, retention duration and recovery objectives are defined in the service agreement. Retention is configurable, with support for deletion workflows and customer-requested export or removal.

Auditability & Operational Traceability

Every answer, back to its source.

Intelipi records key platform actions, including document uploads, metadata updates, workflow steps, approvals and access-controlled actions, to support operational review and accountability.

For AI-assisted answers, responses are source-linked, so users can verify the document or data point behind an answer rather than relying on unsupported output.

Compliance

Honest about where we are.

Intelipi is not yet SOC 2 certified. We are building our internal controls, infrastructure practices and operational processes toward SOC 2 readiness, and a formal SOC 2 program is part of our security roadmap. We'll define its scope and timeline as the platform matures and customer requirements become clearer.

The infrastructure Intelipi runs on is already backed by independent certifications, which underpin our hosting and network environment. Hetzner is certified to ISO/IEC 27001 and BSI C5, and Cloudflare to SOC 2 Type II and ISO 27001. For customers with GDPR or other data-protection obligations, a Data Processing Agreement is available on request.

Get in Touch

Need a security review?

We're glad to walk prospective customers through our security architecture, hosting model, data-handling practices and deployment options during procurement, security review or PoC planning, including completing security questionnaires.

We typically respond within one business day.

A Data Processing Agreement and completed security questionnaires are available on request.