The model does not decide what is true
IntraQ grounds organizational claims in governed sources and preserves uncertainty when evidence is incomplete.
IntraQ works across sensitive workforce and organizational information. Security, privacy, evidence integrity, and human control are designed into how the platform operates.
Security
Connections to IntraQ are served over TLS, with HTTP Strict Transport Security and insecure requests upgraded. Uploaded documents are stored with AES-256 server-side encryption, and multi-factor secrets, connector credentials and single sign-on configuration are encrypted with AES-256-GCM before they are stored.
Authorization decisions are made on the server, using the identity, tenant and role established for the current authenticated session. Client-supplied claims are not treated as authority, and a request that cannot be authorized is refused rather than allowed.
Each customer organization is a separate logical tenant. Queries and writes are scoped to the tenant of the authenticated caller, and that scoping is enforced by the server rather than requested by the client.
Sessions are managed server-side and carried in HttpOnly, Secure cookies that browser scripts cannot read. Session state is checked against current server records rather than trusted from a token alone, so access can be revoked.
Source code, third-party dependencies, infrastructure configuration, secret history and public-facing domains are monitored continuously, and security checks run automatically before changes are released.
IntraQ distinguishes evidence from inference and preserves uncertainty when information cannot be established. Consequential actions remain subject to authorized human control.
Monitoring
IntraQ uses Aikido Security to continuously monitor parts of its software-development and public attack surface — source code, third-party dependencies, infrastructure configuration, secret history and public-facing domains.
Monitoring provided by Aikido Security. Figures are drawn from the Aikido Security Audit Report dated August 30, 2026 and describe what is monitored, not a guarantee about every component.
Security measures monitored
Control mapping
Control mapping
Control mapping
Framework references describe security monitoring and control alignment. They do not represent IntraQ certification or third-party attestation unless explicitly stated.
Architecture
IntraQ grounds organizational claims in governed sources and preserves uncertainty when evidence is incomplete.
Tenant, identity and authorization decisions are enforced by server-side authority rather than client-side state.
IntraQ can investigate, explain and prepare actions, while consequential actions remain subject to authorized human approval.
Privacy
Resources
Independent security monitoring report containing OWASP Top 10 coverage, ISO 27001:2022, SOC 2 and CIS Controls mappings, and scan history.
Generated by Aikido Security from monitored code and infrastructure. This is a monitoring report. It is not a certification, an audit opinion, or a third-party attestation.
We take reports about potential security issues seriously. If you believe you have found a vulnerability in IntraQ, please get in touch before disclosing it publicly, and include enough detail for us to reproduce what you saw.
security@intraqai.com