Intriq AI
Security

Security Overview

How Intriq AI protects your data and ensures the integrity of our platform.

Transformation Diagnostics AI LimitedLast Updated: May 2026Classification: Public

Our security programme is independently certified to ISO 27001:2022 and SOC 2 Type II (Trust Service Criteria: Security, Availability, Confidentiality). Security is built into every layer of our platform — from infrastructure design to personnel practices.

01.

Certifications

ISO 27001:2022

Transformation Diagnostics AI Limited operates a certified Information Security Management System (ISMS) conforming to ISO/IEC 27001:2022. The ISMS covers all aspects of platform development, operations, and data handling. Annual surveillance audits and continuous internal review maintain certification.

SOC 2 Type II

The Intriq AI platform has completed an independent SOC 2 Type II examination across the Trust Service Criteria for Security (CC1–CC9), Availability (A1), and Confidentiality (C1). The Type II report covers an audit period of operational effectiveness, confirming that controls performed as described over the examination period. The report is available to enterprise clients and prospective customers under NDA on request.

02.

Data Encryption

All data in transit is protected using TLS 1.3. All data at rest is encrypted using AES-256 with AWS KMS-managed keys. This applies to document storage (S3), database records (RDS PostgreSQL), and AI embeddings. Encryption key management is performed through AWS KMS with hardware security module (HSM) backing. Encryption standards are reviewed annually as part of our ISO 27001 risk assessment cycle.

03.

Access Control

Access to client data and platform resources is governed by a least-privilege, role-based access control (RBAC) model. Users are assigned one of four roles (Viewer, Analyst, Manager, Admin) with permissions scoped to their organisational context. Every API endpoint enforces organisation-level data isolation — users cannot access data belonging to any other organisation.

Authentication is provided through AWS Cognito with a minimum 12-character password policy and time-limited JWT session tokens. Multi-factor authentication (MFA) is mandatory for all developer and AWS infrastructure access. End-user MFA via TOTP is available and configurable per organisation.

All privileged access to production infrastructure is logged via AWS CloudTrail and subject to quarterly access review.

04.

Network Security

The production environment runs on AWS (eu-west-1, Ireland) within a dedicated VPC with strict security group policies. All Lambda functions and ECS services run within private subnets with no direct internet exposure. API access is routed through AWS API Gateway with JWT authorisation. AWS GuardDuty and AWS Security Hub provide continuous threat detection and compliance monitoring. Vulnerability scanning is conducted regularly, and penetration testing is performed annually by an independent third party.

05.

Physical Security

All production infrastructure is hosted on AWS, which provides physical data centre security including 24/7 surveillance, biometric access controls, and environmental monitoring at its eu-west-1 (Ireland) and eu-west-2 (London) facilities. Physical security controls for AWS data centres are covered under AWS's own ISO 27001 certification and are carved out of our SOC 2 report as a subservice organisation. No client data is processed on any on-premise or co-located hardware operated by Transformation Diagnostics AI Limited.

06.

Data Residency

All client data is processed and stored within the UK / European Economic Area. The primary AWS region is eu-west-1 (Ireland); S3 cross-region replication targets eu-west-2 (London) for resilience. AI inference via GCP Vertex AI uses europe-west1 (Ireland) and europe-west2 (London). No client data is transferred outside the UK/EEA.

07.

Audits and Compliance

Intriq AI undergoes annual independent security audits including:

  • ISO 27001:2022 surveillance and recertification audits
  • SOC 2 Type II examination by an independent AICPA-accredited auditor
  • Annual penetration testing by a third-party security firm
  • Continuous automated compliance scanning via Sprinto

We comply with the UK GDPR, EU GDPR, and Data Protection Act 2018. Our platform and data processing practices meet the requirements of both UK and EU data protection law. All client data is processed and stored within the UK/EEA, ensuring full territorial compliance.

Transformation Diagnostics AI Limited is registered with the UK Information Commissioner's Office (ICO Registration No. ZB724099). Our Data Protection Officer is contactable at dpo@intriq.ai. Data Processing Agreements (DPAs) are executed with all clients prior to onboarding as a condition of access.

08.

Incident Response

A documented Incident Response Plan (IRP) is in place and tested annually. The plan defines classification, escalation, containment, notification, and post-incident review procedures. AWS GuardDuty, CloudWatch alarms, and Sentry are configured to alert on anomalous behaviour.

Confirmed data breaches are reported to the UK ICO within 72 hours in accordance with UK GDPR Article 33. Clients are notified within 24 hours of Intriq AI becoming aware of a breach affecting their data, followed by a full written incident report within 7 days.

09.

Employee Training

All personnel complete security awareness training at onboarding and annually thereafter, delivered through our Sprinto-integrated training programme. Training covers data handling, access control, phishing awareness, incident reporting, and acceptable use. Background checks are conducted for all employees prior to engagement.

10.

AI-Specific Controls

The Intriq AI platform processes sensitive financial documents on behalf of clients. Controls specific to the AI pipeline include:

  • Client data is strictly isolated — no cross-organisation data sharing within AI processing pipelines
  • AI model outputs and uploaded document content are never used to train, fine-tune, or benchmark any AI model — this is a contractual warranty in our Data Processing Agreement. AWS Bedrock and GCP Vertex AI process inference requests under zero-training terms.
  • All AI inference is performed within the UK/EEA (GCP Vertex AI, eu-region endpoints)
  • Human review workflows are available for all AI-generated outputs
  • Output disclaimers are presented to users at the point of delivery
11.

Availability and Data Retention

The platform targets 99.0% monthly uptime with a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour. Availability is monitored continuously via AWS CloudWatch and reported to clients. The full service level schedule is included in our Terms of Use.

Client documents and AI-generated outputs are retained for the duration of the engagement plus 7 years in accordance with UK statutory requirements. On account closure, personal data is deleted within 14 days of confirmation. Backup archives are purged within 90 days.

12.

Summary

Control / StandardStatus
ISO 27001:2022Certified
SOC 2 Type IICompleted — report available under NDA
UK GDPR / DPA 2018Compliant
Encryption in transitTLS 1.3
Encryption at restAES-256, AWS KMS
Data residencyUK / EEA only
Penetration testingAnnual, independent third party
MFAEnforced for all staff and infrastructure access
No model trainingContractual warranty — client data never used for AI training
Client breach notificationWithin 24 hours of detection
ICO registrationZB724099
Uptime target99.0% monthly · RTO 4h · RPO 1h
Data retentionDuration + 7 years · deletion within 14 days on request

Report a Vulnerability

To report a security vulnerability or make an enquiry about our security programme, contact us at:

Transformation Diagnostics AI Ltd (Intriq AI)

20 Wenlock Road, London, N1 7GU, United Kingdom

For the full SOC 2 Type II system description or to request a copy of the report, contact us at security@intriq.ai. DPO: dpo@intriq.ai

© 2026 Intriq AI. All rights reserved.