Skip to main content
Intempt
Security

Security Overview

Last Modified: June 2026

Encryption. We encrypt Customer Data in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent encryption standards.

Access Control. We enforce logical isolation of customer data, role-based access controls, and least-privilege principles across all systems.

Authentication. Multi-factor authentication (MFA) is available on all plans. Single sign-on (SSO) is available on the Enterprise plan.

Backups. Intempt maintains standard backups of Customer Data, retained for thirty (30) days and then deleted as part of Intempt's standard data lifecycle procedures. Intempt also maintains data redundancy and infrastructure resilience controls appropriate to the Services; where infrastructure-level copies of data exist, they are encrypted and isolated from active processing.

Monitoring. Intempt maintains continuous observability of its infrastructure using Grafana, with automated on-call escalation via BetterStack and 24/7 DevOps/SRE coverage. Further security monitoring capabilities, including SIEM integration and SOC-level coverage, are on Intempt's security roadmap.

Secure Development. We follow a secure software development lifecycle (SDLC) that includes security reviews, dependency scanning, infrastructure hardening, and testing against the OWASP Top 10.

Incident Response. Intempt maintains a formal incident response process, built on continuous observability (Grafana) and automated escalation (BetterStack) with 24/7 DevOps/SRE on-call coverage, with defined escalation, containment, and remediation procedures. In the event of a confirmed security incident involving Customer Data, we will notify affected customers within seventy-two (72) hours of confirmation, where feasible. As part of our SOC 2 Type II certification project, we continue to formalize and expand this process's documentation.

AI Data Protection. Intempt trains per-customer AI models exclusively within each customer's logically isolated tenant environment. Customer data is never used to train models serving other customers. Third-party AI subprocessors (OpenAI and Anthropic) are prohibited under commercial API terms from using Customer Data to train their own models.

Roadmap

SOC 2 Type II certification is a compliance priority with a target completion of Q1 2027.

Email Security. Intempt uses Google Workspace with enhanced security features for internal communications, including inbound email screening and attachment controls.

Vulnerability Scanning. Intempt is implementing automated vulnerability scanning of its cloud infrastructure using AWS-native security tooling. Critical and high vulnerabilities identified will be remediated within defined timelines.

AI Model Security. Customer AI models are trained and stored within logically isolated per-customer environments. Access is restricted to authorized Intempt engineering personnel under least-privilege controls. Training pipelines are subject to Intempt's SDLC security review. Customer AI models are deleted within thirty (30) days of subscription termination.

Trust Portal: https://intempt.trustshare.com/

Contact: hey@intempt.com | Intempt Technologies LLC, 1101 W 34th St #595, Austin, TX 78705

Intempt Security | Enterprise-Grade Data Protection