Last updated: 18 August 2026

Security

Supplier data is commercially sensitive, and a monitoring platform sees a lot of it. This page describes how Intellens protects it: where data lives, how it is encrypted, who can reach it and how we know. Everything here is what runs in production today. Where we do not yet have something a questionnaire asks for, we say so.

  • Hosting

    AWS eu-north-1 (Stockholm), EU

  • In transit

    TLS everywhere

  • Sign-in

    Mandatory two-factor sign-in

  • Data rights

    Self-service export + erasure in Settings

  • Data residency

    Your data lives in the European Union.

    • Intellens runs on AWS in eu-north-1 (Stockholm, Sweden). Application, database, pipeline and file storage are all in that region.
    • A small number of third-party services process specific data outside the EU. The full list, with the data each receives and where it is processed, is provided to customers under our data processing agreement.
  • Encryption

    Encrypted in transit and at rest.

    • Data is encrypted in transit (TLS) and at rest with AWS-managed keys.
    • Credentials are held in a managed secrets store.
    • Passwords are hashed, never stored.
  • Authentication

    Every account signs in with two factors. There is no way to turn that off.

    • Mandatory two-factor sign-in for every account.
    • Brute-force lockout on sign-in.
    • Short-lived sessions, revoked immediately on password change, logout or user removal.
  • Access control

    Scoped to your workspace, governed by roles, and every staff look is logged.

    • Every request is scoped to your workspace. For alerts, tasks, assistant conversations and operational records the database enforces that boundary on its own as well: a query without a workspace scope returns nothing.
    • Role-based permissions, adjustable by the workspace owner.
    • Staff access to your workspace is time-boxed, logged and notified to you.
  • Development security

    Merges are blocked by scanners, not by good intentions.

    • Automated dependency, secret and static-analysis scans block every merge to the application.
    • The API is fuzz-tested against its own schema on every change.
    • Deploys use short-lived credentials. No long-lived cloud keys are stored in repositories.
  • Monitoring

    Alarms on the pipeline and the application, plus a tamper-evident trail.

    • Continuous alarming on the data pipeline and the application.
    • Deliverability monitoring on outbound email.
    • A tamper-evident audit trail on the cloud account.
    • Every mutating request is written to a tenant audit log.
  • Data rights

    GDPR export and erasure are self-service, not a support ticket.

    • Export: workspace owners can download the whole workspace as machine-readable JSON from Settings, at any time.
    • Erasure: workspace owners can request deletion from Settings. Access is revoked for every user immediately, and personal data is permanently erased after a 30-day retention window.
    • Supplier attestation evidence that is subject to statutory retention is excluded from erasure.
    • A data processing agreement (DPA) is available on request.
    Request a DPA
  • Responsible disclosure

    Found something? Tell us before you tell anyone else.

    • Report vulnerabilities to security@intellens.ai. Include steps to reproduce and the affected URL or endpoint.
    • We will acknowledge your report and keep you informed while we fix it.
    • Please do not access data that is not yours, degrade the service, or run automated scanning against production while testing.
    security@intellens.ai

Plain answers

The questions every security questionnaire asks, answered without spin.

Are you SOC 2 or ISO 27001 certified?

No. Intellens is not certified against SOC 2 or ISO 27001 today. This page describes the controls that are actually in production, and we do not claim a certification we do not hold.

Have you had an independent penetration test?

Not yet. The API is fuzz-tested against its own schema on every change, and dependency and static-analysis scans block merges, but no third-party penetration test has been completed.

Do you support single sign-on (SSO)?

Not today. Every account signs in with a password and a mandatory second factor. SSO is on the roadmap.

Who are your subprocessors, and where do they process data?

The list of third-party services that process data on our behalf, with the data each receives, whether it is personal, and the processing region, is provided to customers under our data processing agreement and updated by notice. Ask through the contact form.

Will you sign a DPA?

Yes. A data processing agreement is available on request through the contact form.

Need more for your vendor review?

A data processing agreement is available on request, and we answer security questionnaires directly. Vulnerability reports go to security@intellens.ai.

Request a DPA

The list of third parties that process data on our behalf is provided under our DPA.