Security & Trust
At Intelipi, we handle business-critical documents, operational records and customer data. Security is built into how that data is stored, processed, isolated and accessed, not added afterward. This page describes our current practices, the infrastructure we run on, and where we're headed.
At a Glance
| Encryption in transit | TLS 1.2+ on all connections |
|---|---|
| Encryption at rest | AES-256 |
| Data residency | Singapore by default; other regions and single-tenant options available |
| Tenant isolation | Multi-tenant with tenant-level isolation; single-tenant available |
| Authentication | Single sign-on via Microsoft and Google; MFA inherited from your identity provider |
| Customer data used to train AI models | No, not by us, and not by our AI provider |
| Source traceability | Every AI answer links back to the underlying document |
| SOC 2 | Not yet certified; controls being built toward SOC 2 readiness |
| Data Processing Agreement (GDPR) | Available on request |
Data Protection
All customer data is encrypted both in transit and at rest. Connections to Intelipi are secured with TLS 1.2 or higher, and stored data, including uploaded documents, extracted metadata and related operational records, is encrypted at rest using AES-256.
Data is hosted in Singapore by default. For customers with specific residency, compliance or isolation requirements, we can host in other regions or provide single-tenant deployments in which the customer environment is logically and operationally separated from all other tenants.
Infrastructure & Subprocessors
Intelipi runs on a small, deliberately chosen set of infrastructure providers. We keep this list current so customers always know who processes their data.
Operates its own data centers and offers a GDPR Data Processing Agreement. Its data center operations are independently certified to ISO/IEC 27001 and BSI C5.
Provides our edge network, DDoS protection and content delivery, backed by a broad set of independent security certifications including SOC 2 Type II, ISO/IEC 27001, ISO 27701 and PCI DSS.
Powers document classification, metadata extraction and question answering. Content is processed under Anthropic's Commercial Terms: it is not used to train models, and is retained only briefly to operate the service.
AI & Model Training
Your documents and data are never used to train AI models, not by us, and not by our AI provider. Intelipi uses Anthropic's Claude models to classify documents, extract metadata and answer questions. Content processed through Anthropic's API is governed by Anthropic's Commercial Terms: Anthropic does not use commercial API inputs or outputs to train its models, and retains them only briefly to operate the service.
We also do not use your documents, extracted content, prompts, answers or activity to train any general-purpose models of our own. This data is processed for one purpose only: to provide the Intelipi service to you. You can review Anthropic's policy directly here.
Wherever AI is used, Intelipi preserves source traceability. Every AI-generated answer links back to the document or record it was drawn from, so you can verify the source rather than rely on an unsupported response.
Access Control & Authentication
RBAC governs what a user can do, such as viewing documents, managing workflows, approving tasks or administering settings.
ABAC governs which documents and records a user can reach, based on document attributes, user attributes, tenant rules, business units, tags or other configured conditions.
Together, these let organizations define granular policies that reflect real operational boundaries: department, document type, customer, supplier, project, shipment, location or approval responsibility.
Access is through single sign-on (SSO). We support Microsoft and Google as identity providers, so users sign in with existing organizational accounts, with no separate Intelipi passwords to create, store or manage. Because authentication is delegated to your identity provider, your existing security policies apply directly at sign-in, including multi-factor authentication (MFA) and conditional access rules you already enforce.
Isolation, Backups & Retention
Intelipi is a multi-tenant platform with tenant-level data isolation. Each customer's documents, metadata, workflows, users, permissions and operational records are separated at the tenant level. For stricter requirements, we offer single-tenant deployments with dedicated application and data environments.
We maintain backup and recovery practices designed to protect against accidental data loss and service disruption. For enterprise and single-tenant deployments, backup frequency, retention duration and recovery objectives are defined in the service agreement. Retention is configurable, with support for deletion workflows and customer-requested export or removal.
Auditability & Operational Traceability
Intelipi records key platform actions, including document uploads, metadata updates, workflow steps, approvals and access-controlled actions, to support operational review and accountability.
For AI-assisted answers, responses are source-linked, so users can verify the document or data point behind an answer rather than relying on unsupported output.
Compliance
Intelipi is not yet SOC 2 certified. We are building our internal controls, infrastructure practices and operational processes toward SOC 2 readiness, and a formal SOC 2 program is part of our security roadmap. We'll define its scope and timeline as the platform matures and customer requirements become clearer.
The infrastructure Intelipi runs on is already backed by independent certifications, which underpin our hosting and network environment. Hetzner is certified to ISO/IEC 27001 and BSI C5, and Cloudflare to SOC 2 Type II and ISO 27001. For customers with GDPR or other data-protection obligations, a Data Processing Agreement is available on request.
Get in Touch
We're glad to walk prospective customers through our security architecture, hosting model, data-handling practices and deployment options during procurement, security review or PoC planning, including completing security questionnaires.
We typically respond within one business day.
A Data Processing Agreement and completed security questionnaires are available on request.