Security & Trust
Last reviewed: April 2026
User Intuition complies with GDPR, CCPA, applicable US state privacy laws, and security best practices. SOC 2, ISO 27001, and HIPAA certifications are on our 2026 roadmap. All of our sub-processors are SOC 2 Type 2 certified, and our customer authentication provider Clerk and our voice provider additionally offer HIPAA Business Associate Agreements.
This trust center documents how we protect customer data, secure our applications and infrastructure, and respond to incidents. Each section below links to a dedicated page with detail; legal documents are also linked here as a single jumping-off point.
Compliance & certifications
SOC 2, ISO 27001, HIPAA roadmap; GDPR, CCPA, and US state privacy laws today.
→Data protection
Encryption in transit and at rest, US data residency, 30-day retention, deletion on request.
→Application security
SDLC, OWASP Top 10, dependency scanning, static analysis, mandatory code review.
→Infrastructure
Hosting on Railway and Supabase in US-East (Ohio); business continuity and disaster recovery.
→Access control
Customer auth via Clerk (MFA, SSO); internal access with MFA, least privilege, quarterly reviews.
→Incident response
72-hour breach SLA, vulnerability remediation timelines, RFC 9116 security.txt for researchers.
→AI governance
No training on customer data, prompt-injection defenses, recording consent, participant PII protection.
→Privacy policy
How we collect, use, retain, and protect personal data — for visitors, customers, and participants.
→Terms & conditions
Master agreement governing use of User Intuition services.
→