Trust & Security

Built to be trusted with your data.

We build software for healthcare, finance and education — domains where a breach isn't an inconvenience, it's a harm. Security, privacy and data protection aren't features we add at the end; they're constraints we design from. Here's how we work, and what you can hold us to.

Our commitments

Five things we take seriously

Security

Encryption in transit and at rest, least-privilege access, secure development practices and continuous patching — applied to every system we build and operate.

Privacy

We collect the minimum data needed, are explicit about why, and never sell it. Privacy decisions are made in the architecture, not buried in a policy.

Data handling

A clear lifecycle for every record — how it's collected, stored, used, retained and deleted — with isolation between customers and auditable access.

Compliance readiness

We engineer to the controls behind GDPR, HIPAA-style and SOC 2 frameworks — so platforms we build can meet the standard your industry demands.

Enterprise confidence

Documentation, accountability and operational maturity — so a security or procurement team can say yes to working with us without reservation.

Have a question we don't answer here?

Our security team is happy to walk through architecture, controls and documentation.

Contact security
Security

The controls behind every system

Encryption everywhere

TLS for data in transit and strong encryption at rest. Secrets are managed in dedicated vaults, never in source code.

Least-privilege access

Role-based access control, multi-factor authentication for our team, and access scoped to what each role genuinely needs.

Secure development

Code review, dependency scanning, secrets detection and security checks in CI — so vulnerabilities are caught before they ship.

Monitoring & logging

Centralised logs, audit trails of who accessed what, and alerting on anomalous activity across the systems we operate.

Backups & recovery

Automated, encrypted backups with tested restore procedures, so data survives failure and service can be recovered.

Tenant isolation

Multi-tenant systems enforce strict separation — application and database controls keep one customer's data away from another's.

Data handling

A clear lifecycle for every record

Collect

Only what's needed for the service to work, with a clear purpose for every field. No collection "just in case."

Store & use

Encrypted, access-controlled, and used only for the purposes it was collected for — isolated per customer.

Retain

Kept only as long as there's a reason to, governed by defined retention periods rather than indefinite default.

Delete & export

Removed on request or at end of retention, and exportable so your data is never held hostage by us.

For products we operate, the specifics of what we collect and why live in our Privacy Policy. For platforms we build and hand over to you, you control the data — we engineer the controls that let you protect it.
Compliance readiness

Engineered to meet the standard you answer to

GDPR & data-protection principles

Lawful basis, data minimisation, subject rights and breach-notification practices designed into how we handle personal data.

Healthcare-grade privacy

For products like Healodex, we apply HIPAA-style safeguards — access controls, audit trails and encryption for sensitive health data.

SOC 2-aligned controls

Our operational practices map to the trust-service criteria — security, availability and confidentiality — that enterprise buyers assess.

Data residency options

We can architect where data lives and processes to meet residency and sovereignty requirements for your region.

A note on honesty: we describe how we engineer to these frameworks, not certifications we haven't earned. Where a formal audit or certification is required for your engagement, we'll tell you plainly what's in place today and what we'd put in place for you — and support the audit process. Ask us for current status.

Responsible disclosure

Found a security issue in one of our products? We want to hear about it. Email security@inteople.com with the details and we'll respond promptly. We don't pursue good-faith researchers who report vulnerabilities responsibly.

Let's talk

Evaluating Inteople for sensitive work?

We'll walk your security and compliance teams through our architecture, controls and documentation — and answer the hard questions.