Security
Encryption in transit and at rest, least-privilege access, secure development practices and continuous patching — applied to every system we build and operate.
We build software for healthcare, finance and education — domains where a breach isn't an inconvenience, it's a harm. Security, privacy and data protection aren't features we add at the end; they're constraints we design from. Here's how we work, and what you can hold us to.
Encryption in transit and at rest, least-privilege access, secure development practices and continuous patching — applied to every system we build and operate.
We collect the minimum data needed, are explicit about why, and never sell it. Privacy decisions are made in the architecture, not buried in a policy.
A clear lifecycle for every record — how it's collected, stored, used, retained and deleted — with isolation between customers and auditable access.
We engineer to the controls behind GDPR, HIPAA-style and SOC 2 frameworks — so platforms we build can meet the standard your industry demands.
Documentation, accountability and operational maturity — so a security or procurement team can say yes to working with us without reservation.
Our security team is happy to walk through architecture, controls and documentation.
Contact securityTLS for data in transit and strong encryption at rest. Secrets are managed in dedicated vaults, never in source code.
Role-based access control, multi-factor authentication for our team, and access scoped to what each role genuinely needs.
Code review, dependency scanning, secrets detection and security checks in CI — so vulnerabilities are caught before they ship.
Centralised logs, audit trails of who accessed what, and alerting on anomalous activity across the systems we operate.
Automated, encrypted backups with tested restore procedures, so data survives failure and service can be recovered.
Multi-tenant systems enforce strict separation — application and database controls keep one customer's data away from another's.
Only what's needed for the service to work, with a clear purpose for every field. No collection "just in case."
Encrypted, access-controlled, and used only for the purposes it was collected for — isolated per customer.
Kept only as long as there's a reason to, governed by defined retention periods rather than indefinite default.
Removed on request or at end of retention, and exportable so your data is never held hostage by us.
Lawful basis, data minimisation, subject rights and breach-notification practices designed into how we handle personal data.
For products like Healodex, we apply HIPAA-style safeguards — access controls, audit trails and encryption for sensitive health data.
Our operational practices map to the trust-service criteria — security, availability and confidentiality — that enterprise buyers assess.
We can architect where data lives and processes to meet residency and sovereignty requirements for your region.
A note on honesty: we describe how we engineer to these frameworks, not certifications we haven't earned. Where a formal audit or certification is required for your engagement, we'll tell you plainly what's in place today and what we'd put in place for you — and support the audit process. Ask us for current status.
How we collect, use, protect and share personal data across our products.
Read the policy →The terms that govern use of our websites, products and services.
Read the terms →Vendor assessments, architecture reviews and DPAs — send them our way.
Contact security →Found a security issue in one of our products? We want to hear about it. Email security@inteople.com with the details and we'll respond promptly. We don't pursue good-faith researchers who report vulnerabilities responsibly.
We'll walk your security and compliance teams through our architecture, controls and documentation — and answer the hard questions.