Sales & support · intravo.comintravo.com
Trust & Compliance

Security Overview

How Intravo protects customer data, infrastructure, and operations. This page is intended to answer the most common questions on security review questionnaires.

Last updated: April 29, 2026
On this page

Security Program

Intravo maintains a written information security program designed to protect the confidentiality, integrity, and availability of customer data. The program is reviewed at least annually and updated as needed in response to changes in technology, regulation, threat landscape, and business operations.

Our security objectives are:

Infrastructure & Hosting

Intravo's production services are hosted on Amazon Web Services (AWS) in the United States. AWS maintains industry-leading certifications, including ISO 27001, SOC 1, SOC 2, SOC 3, and PCI DSS. Intravo inherits the underlying physical and environmental controls of the AWS data center facilities.

Production environments are logically separated from development and staging environments. Customer data does not flow into non-production environments except as required for narrowly scoped, authorized debugging, with appropriate safeguards.

Encryption

Access Controls

Network Security

Application Security

Logging & Monitoring

Incident Response

Intravo maintains a documented incident response plan covering identification, containment, eradication, recovery, and post-incident review.

Backup & Disaster Recovery

Vendor & Subprocessor Management

Intravo conducts due diligence on subprocessors before engagement and imposes data protection and security obligations consistent with our customer commitments. The current list of subprocessors is published at intravo.com/subprocessors. Customers may subscribe to change notifications by emailing [email protected].

Personnel Security

Data Privacy & Retention

Intravo processes personal data on behalf of customers in accordance with the Privacy Policy and the Data Processing Addendum. Customers control retention policies for their data within the Services and may request export or deletion at any time, subject to applicable legal obligations.

Vulnerability Disclosure

Intravo welcomes responsible reports of security vulnerabilities. If you believe you have discovered a security issue, please email [email protected] with details. We commit to:

A machine-readable contact is published at /.well-known/security.txt.

Certifications & Audits

We believe in being straightforward about what we have today and what we are building toward. Intravo does not currently hold a SOC 2, ISO 27001, or PCI DSS certification of its own. Our compliance and certification posture is evolving:

Detailed documentation by request. Our internal security policies (Information Security Policy, Cyber Incident Response Plan, Key Management, Patch Management, Vulnerability Assessment, Audit Trail, BYOD, Background Check, Change Management, Business Impact Analysis, Document Retention, Wireless Network Security, and AI Acceptable Use), summaries of annual penetration testing, and completed security questionnaires (CAIQ, SIG Lite, custom forms) are available under NDA. Contact [email protected].

Contact Security

Security Team — Intravo
Email: [email protected]
Privacy & Compliance: [email protected]