Last updated: 18 August 2026
Security
Supplier data is commercially sensitive, and a monitoring platform sees a lot of it. This page describes how Intellens protects it: where data lives, how it is encrypted, who can reach it and how we know. Everything here is what runs in production today. Where we do not yet have something a questionnaire asks for, we say so.
Hosting
AWS eu-north-1 (Stockholm), EU
In transit
TLS everywhere
Sign-in
Mandatory two-factor sign-in
Data rights
Self-service export + erasure in Settings
Data residency
Your data lives in the European Union.
- Intellens runs on AWS in eu-north-1 (Stockholm, Sweden). Application, database, pipeline and file storage are all in that region.
- A small number of third-party services process specific data outside the EU. The full list, with the data each receives and where it is processed, is provided to customers under our data processing agreement.
Encryption
Encrypted in transit and at rest.
- Data is encrypted in transit (TLS) and at rest with AWS-managed keys.
- Credentials are held in a managed secrets store.
- Passwords are hashed, never stored.
Authentication
Every account signs in with two factors. There is no way to turn that off.
- Mandatory two-factor sign-in for every account.
- Brute-force lockout on sign-in.
- Short-lived sessions, revoked immediately on password change, logout or user removal.
Access control
Scoped to your workspace, governed by roles, and every staff look is logged.
- Every request is scoped to your workspace. For alerts, tasks, assistant conversations and operational records the database enforces that boundary on its own as well: a query without a workspace scope returns nothing.
- Role-based permissions, adjustable by the workspace owner.
- Staff access to your workspace is time-boxed, logged and notified to you.
Development security
Merges are blocked by scanners, not by good intentions.
- Automated dependency, secret and static-analysis scans block every merge to the application.
- The API is fuzz-tested against its own schema on every change.
- Deploys use short-lived credentials. No long-lived cloud keys are stored in repositories.
Monitoring
Alarms on the pipeline and the application, plus a tamper-evident trail.
- Continuous alarming on the data pipeline and the application.
- Deliverability monitoring on outbound email.
- A tamper-evident audit trail on the cloud account.
- Every mutating request is written to a tenant audit log.
Data rights
GDPR export and erasure are self-service, not a support ticket.
- Export: workspace owners can download the whole workspace as machine-readable JSON from Settings, at any time.
- Erasure: workspace owners can request deletion from Settings. Access is revoked for every user immediately, and personal data is permanently erased after a 30-day retention window.
- Supplier attestation evidence that is subject to statutory retention is excluded from erasure.
- A data processing agreement (DPA) is available on request.
Responsible disclosure
Found something? Tell us before you tell anyone else.
- Report vulnerabilities to security@intellens.ai. Include steps to reproduce and the affected URL or endpoint.
- We will acknowledge your report and keep you informed while we fix it.
- Please do not access data that is not yours, degrade the service, or run automated scanning against production while testing.
Plain answers
The questions every security questionnaire asks, answered without spin.
Are you SOC 2 or ISO 27001 certified?
No. Intellens is not certified against SOC 2 or ISO 27001 today. This page describes the controls that are actually in production, and we do not claim a certification we do not hold.
Have you had an independent penetration test?
Not yet. The API is fuzz-tested against its own schema on every change, and dependency and static-analysis scans block merges, but no third-party penetration test has been completed.
Do you support single sign-on (SSO)?
Not today. Every account signs in with a password and a mandatory second factor. SSO is on the roadmap.
Who are your subprocessors, and where do they process data?
The list of third-party services that process data on our behalf, with the data each receives, whether it is personal, and the processing region, is provided to customers under our data processing agreement and updated by notice. Ask through the contact form.
Will you sign a DPA?
Yes. A data processing agreement is available on request through the contact form.
Need more for your vendor review?
A data processing agreement is available on request, and we answer security questionnaires directly. Vulnerability reports go to security@intellens.ai.
Request a DPAThe list of third parties that process data on our behalf is provided under our DPA.
We use essential and analytics cookies to improve your experience. Cookie Policy.