intero

Enterprise security for your safety data.

Intero keeps each customer's data logically isolated and encrypted everywhere. AI governance controls keep a qualified person in charge of every output. SOC 2 Type II in progress.

Infrastructure & data protection

Cloud infrastructure

Hosted on AWS. Application storage (documents, photos, video evidence) lives in Amazon S3; structured data lives in a managed Postgres database. Infrastructure as code for consistent, auditable environments.

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), across S3 storage and the managed Postgres database. Keys are managed and rotated by our cloud provider's key management service.

Tenant isolation

Per-tenant logical separation with per-organization query filtering ensures your data is isolated from every other customer's. Cascade delete guarantees full removal. No cross-tenant data access.

Access control

Role-based access controls (RBAC) map to your organizational structure on every plan, with granular permissions for review, assign, and verify workflows. SSO integration with your identity provider is available on Enterprise.

Audit trails

Every workflow action is logged: who did what, when, and why. Full audit trails for investigations, approvals, and closures. Exportable for compliance reporting.

Data residency

Customer data is hosted on AWS, with encryption at rest and in transit. Customers with specific data-residency requirements should talk to us. Regional commitments are discussable as part of an enterprise agreement.

AI model governance

AI in safety calls for a higher standard of governance. Here is how Intero handles it.

Your data never trains AI models

Your incident data is used only to generate your outputs. It is never shared across organizations and never used to train or fine-tune models, whether ours or our AI providers'.

Model selection

Intero runs on large language models chosen for the analysis and drafting work it does.

Evidence-first outputs

Every AI claim references specific evidence from your data. No hallucinated recommendations.

Human-in-the-loop, always

AI drafts and recommends; it does not decide. Intero provides decision support. Qualified humans on your team review, edit, and approve every finding before it's acted on. Outputs are not a substitute for professional, legal, or safety judgment.

A quality gate on every report

Before anyone signs, a second AI pass critiques the report and rejects weak, unverifiable, or boilerplate findings like “human error,” so they never reach your reviewers.

Organization-scoped learning

When your team corrects AI outputs, those improvements apply only to your organization. No cross-tenant learning.

Compliance & certifications

SOC 2 Type II in progress

Current security controls documentation is available on request, and third-party audit results will be shared once complete.

Security documentation

Architecture overview available on request. A data protection agreement (DPA) is available for Enterprise customers. Penetration test results and a detailed security whitepaper are available under NDA.

Regulatory recordability

Regulatory recordability tracking built in. Incidents are classified and logged to meet regulatory reporting requirements out of the box.

Regulatory jurisdiction

Configurable regulatory jurisdiction per location. Apply the right rules to the right sites across your organization.

Full audit trail: nothing is ever hard-deleted

All records use soft delete. Every change is tracked with who, what, and when. Your compliance and legal teams can always reconstruct the full history.

Responsible disclosure

Found a security issue? Report it to security@intero.ai. We investigate every report and will acknowledge receipt, work with you to understand impact, and keep you posted as we resolve it.

Request our security package

We understand that your security and procurement teams need detailed documentation before any evaluation. We're happy to provide:

Security architecture overview
Data protection agreement (DPA) for Enterprise
AI model governance documentation
Penetration testing results (under NDA)
Vendor security questionnaire responses
Request Security Documentation

Security is built into the foundation.

Every investigation summary and corrective action is tied to evidence and reviewed by a qualified person. Actions are tracked for audit. Intero is built to meet the security standards your procurement team expects. SOC 2 Type II in progress.