Security
Last updated: October 8, 2026
This is a plain description of how we protect the service and your data today. We do not hold security certifications such as ISO 27001 or SOC 2 at this time. For the contractual version, see Annex II of our Data Processing Addendum.
Data in transit
The website, the app, the REST API and the MCP server are served only over HTTPS. Plain HTTP requests are redirected, and HTTP Strict Transport Security (HSTS) tells browsers to use HTTPS every time.
Accounts and passwords
- Passwords are stored only as salted one-way hashes, never in plain text.
- Email sign-ups are confirmed by a link sent to the address. You can also sign in with GitHub or Google where enabled.
- Sign-up, login and password reset are protected by rate limits and anti-bot checks.
- Logging out ends your session on that device.
Isolation and access control
- Every workspace has its own database.
- Inside a workspace, the owner decides with roles who can see and change which tables, records and functions. API and MCP access, including by AI agents, has exactly the permissions of the token used.
- Access to production servers is limited to a few authorized people, using SSH keys. Configuration secrets live in server-only files, outside the code repository and releases.
Backups and availability
Backups of databases and uploaded files: [Backup frequency and storage location]. You can also export your data to Excel at any time.
Development and releases
Changes are reviewed and must pass automated tests before release. Releases are deployed by script; secrets are never part of a release.
Privacy by default
The marketing site has no advertising trackers and loads cookieless analytics only with consent. We do not use customer data to train AI models. AI providers are only involved when you connect one.
Reporting a vulnerability
If you find a security problem, email hello@integram-ai.online with the subject "Security" and enough detail to reproduce it. Please give us reasonable time to fix it before disclosing it, do not access or change other people’s data, and do not run tests that degrade the service. We will acknowledge your report, keep you updated and will not take legal action against good-faith research that follows these rules.