Enterprise security for your safety data.
Intero keeps each customer's data logically isolated and encrypted everywhere. AI governance controls keep a qualified person in charge of every output. SOC 2 Type II in progress.
Infrastructure & data protection
Cloud infrastructure
Hosted on AWS. Application storage (documents, photos, video evidence) lives in Amazon S3; structured data lives in a managed Postgres database. Infrastructure as code for consistent, auditable environments.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), across S3 storage and the managed Postgres database. Keys are managed and rotated by our cloud provider's key management service.
Tenant isolation
Per-tenant logical separation with per-organization query filtering ensures your data is isolated from every other customer's. Cascade delete guarantees full removal. No cross-tenant data access.
Access control
Role-based access controls (RBAC) map to your organizational structure on every plan, with granular permissions for review, assign, and verify workflows. SSO integration with your identity provider is available on Enterprise.
Audit trails
Every workflow action is logged: who did what, when, and why. Full audit trails for investigations, approvals, and closures. Exportable for compliance reporting.
Data residency
Customer data is hosted on AWS, with encryption at rest and in transit. Customers with specific data-residency requirements should talk to us. Regional commitments are discussable as part of an enterprise agreement.
AI model governance
AI in safety calls for a higher standard of governance. Here is how Intero handles it.
Your data never trains AI models
Your incident data is used only to generate your outputs. It is never shared across organizations and never used to train or fine-tune models, whether ours or our AI providers'.
Model selection
Intero runs on large language models chosen for the analysis and drafting work it does.
Evidence-first outputs
Every AI claim references specific evidence from your data. No hallucinated recommendations.
Human-in-the-loop, always
AI drafts and recommends; it does not decide. Intero provides decision support. Qualified humans on your team review, edit, and approve every finding before it's acted on. Outputs are not a substitute for professional, legal, or safety judgment.
A quality gate on every report
Before anyone signs, a second AI pass critiques the report and rejects weak, unverifiable, or boilerplate findings like “human error,” so they never reach your reviewers.
Organization-scoped learning
When your team corrects AI outputs, those improvements apply only to your organization. No cross-tenant learning.
Compliance & certifications
SOC 2 Type II in progress
Current security controls documentation is available on request, and third-party audit results will be shared once complete.
Security documentation
Architecture overview available on request. A data protection agreement (DPA) is available for Enterprise customers. Penetration test results and a detailed security whitepaper are available under NDA.
Regulatory recordability
Regulatory recordability tracking built in. Incidents are classified and logged to meet regulatory reporting requirements out of the box.
Regulatory jurisdiction
Configurable regulatory jurisdiction per location. Apply the right rules to the right sites across your organization.
Full audit trail: nothing is ever hard-deleted
All records use soft delete. Every change is tracked with who, what, and when. Your compliance and legal teams can always reconstruct the full history.
Responsible disclosure
Found a security issue? Report it to security@intero.ai. We investigate every report and will acknowledge receipt, work with you to understand impact, and keep you posted as we resolve it.
Request our security package
We understand that your security and procurement teams need detailed documentation before any evaluation. We're happy to provide:
Security is built into the foundation.
Every investigation summary and corrective action is tied to evidence and reviewed by a qualified person. Actions are tracked for audit. Intero is built to meet the security standards your procurement team expects. SOC 2 Type II in progress.
