Skip to content
Security monitoring activeLast reviewed August 2026

Trust is part of the architecture.

IntraQ works across sensitive workforce and organizational information. Security, privacy, evidence integrity, and human control are designed into how the platform operates.

Security

How the platform protects information

  • Encryption

    Connections to IntraQ are served over TLS, with HTTP Strict Transport Security and insecure requests upgraded. Uploaded documents are stored with AES-256 server-side encryption, and multi-factor secrets, connector credentials and single sign-on configuration are encrypted with AES-256-GCM before they are stored.

  • Access control

    Authorization decisions are made on the server, using the identity, tenant and role established for the current authenticated session. Client-supplied claims are not treated as authority, and a request that cannot be authorized is refused rather than allowed.

  • Tenant isolation

    Each customer organization is a separate logical tenant. Queries and writes are scoped to the tenant of the authenticated caller, and that scoping is enforced by the server rather than requested by the client.

  • Session security

    Sessions are managed server-side and carried in HttpOnly, Secure cookies that browser scripts cannot read. Session state is checked against current server records rather than trusted from a token alone, so access can be revoked.

  • Secure development

    Source code, third-party dependencies, infrastructure configuration, secret history and public-facing domains are monitored continuously, and security checks run automatically before changes are released.

  • Human control

    IntraQ distinguishes evidence from inference and preserves uncertainty when information cannot be established. Consequential actions remain subject to authorized human control.

Monitoring

Independent security monitoring

IntraQ uses Aikido Security to continuously monitor parts of its software-development and public attack surface — source code, third-party dependencies, infrastructure configuration, secret history and public-facing domains.

open-source dependency issues
0Criticalopen-source dependency issues
security monitoring
Dailysecurity monitoring
JavaScript packages monitored
1,641JavaScript packages monitored
public domains monitored
2public domains monitored

Monitoring provided by Aikido Security. Figures are drawn from the Aikido Security Audit Report dated August 30, 2026 and describe what is monitored, not a guarantee about every component.

Independent monitoring by Aikido Security

Aikido monitors IntraQ's source code, dependencies, infrastructure configuration, secret history and public-facing domains, and produces the Security Audit Report. Request a copy directly from Aikido — it is issued by them, not by us.

Request IntraQ's Aikido Security Audit Report

Security frameworks

  • OWASP Top 10

    Security measures monitored

  • SOC 2

    Control mapping

  • ISO 27001:2022

    Control mapping

  • CIS Controls v8.1

    Control mapping

Framework references describe security monitoring and control alignment. They do not represent IntraQ certification or third-party attestation unless explicitly stated.

Architecture

How IntraQ is built to be trusted

The model does not decide what is true

IntraQ grounds organizational claims in governed sources and preserves uncertainty when evidence is incomplete.

Customer boundaries are enforced server-side

Tenant, identity and authorization decisions are enforced by server-side authority rather than client-side state.

Humans remain in control

IntraQ can investigate, explain and prepare actions, while consequential actions remain subject to authorized human approval.

Resources

Security resources

Aikido Security Audit Report

August 30, 2026

Independent security monitoring report containing OWASP Top 10 coverage, ISO 27001:2022, SOC 2 and CIS Controls mappings, and scan history.

Generated by Aikido Security from monitored code and infrastructure. This is a monitoring report. It is not a certification, an audit opinion, or a third-party attestation.

Request Security ReportA published copy is being prepared.

Found something?

We take reports about potential security issues seriously. If you believe you have found a vulnerability in IntraQ, please get in touch before disclosing it publicly, and include enough detail for us to reproduce what you saw.

security@intraqai.com

IntraQ monitors its security continuously and maps controls to recognised frameworks. IntraQ is not currently SOC 2 attested, ISO 27001 certified, or CIS certified, and nothing on this page should be read as a certification or third-party attestation.

© IntraQ