Back to home

Security & Privacy

This page is maintained by Intrinsic Inc. to answer common security and privacy questions about the Intrinsic platform. It reflects controls currently in production and is not a third-party certification.

Access & authentication

Every account uses email + password authentication with optional Google sign-in. Role-based access control separates agency users, agency admins, and Intrinsic operators. Sessions are short-lived and refresh automatically; password reset uses single-use, time-limited links.

Platform & hosting

Intrinsic runs on managed cloud infrastructure with isolated, per-project databases. Application and database traffic are encrypted in transit (TLS 1.2+). Data is encrypted at rest by the underlying managed providers. We do not co-locate customer data on shared multi-tenant tables — agency rows are scoped by row-level security policies.

Data collection & use

We collect the minimum data needed to operate the tools an agency uses — account profile, SIBR/LON inputs you enter, documents you upload, and product usage telemetry for reliability. We never sell data and we do not use agency or participant data to train third-party AI models.

Subprocessors & integrations

A current list of subprocessors (hosting, transactional email, error monitoring) is available on request. Where Protected Health Information is processed, we maintain Business Associate Agreements with subprocessors that handle it.

Retention & deletion

Agency-owned content (saved analyses, documents, reports) is retained for as long as the agency account is active. On written request from an authorized agency admin we will delete agency content within 30 days, except where law requires longer retention.

Compliance posture

Intrinsic is built to support HIPAA-aware workflows for HCBS providers. A Business Associate Agreement is available to partnered agencies on request. This page is not a third-party certification — it describes the controls Intrinsic currently operates.

Reporting a security concern

If you believe you've found a vulnerability or have a question about how Intrinsic handles a specific kind of data, email security@intrinsic.agency. We respond to verified reports within two business days.