Insigo
FeaturesSecurityLoginBook a working session
Trust center

Security at Insigo

Last updated · July 2026

Insigo holds your competitive position, the facts you teach it, and the calls you make. Protecting that isn't an add-on — isolation, privacy, and provenance are how the system is built. This page is a plain summary of how.

Tenant isolationNo model trainingEncryption in transit & at restInvite-only accessFull provenanceGDPR-ready
How we protect your data

Tenant isolation

Every workspace is a separate tenant. Membership is enforced server-side on every request, so no one outside your team can reach your data — and internal service routes are unreachable from the public internet.

No model training

Your prompts, your corpus, and the facts you teach the system are processed under enterprise terms and are never used to train foundation models. Your private facts stay in your workspace.

Encryption

All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest, and integration secrets are held in an encrypted store — never committed to source. Passwords are bcrypt-hashed.

Access control

No open sign-up: accounts are provisioned or invited. Access is role-based (Owner / Admin / Member), authenticated with short-lived tokens, with self-serve reset over a time-boxed link.

Provenance

The system reasons only from evidence it collected or facts you taught it — never free-floating model opinion. Every claim drills to the document behind it, so you can audit the reasoning.

Least privilege

Services run with the minimum access they need. Collection reads public and primary-source records only — it never requires access to your internal systems to work.

Technical controls
Encryption in transit
TLS 1.2+ on every connection, with HSTS and auto-renewed certificates.
Encryption at rest
Database and backups encrypted at rest; an encrypted store for integration secrets.
Secrets
Credentials and keys encrypted with an environment-held key, never committed to source control.
Passwords
bcrypt-hashed with per-user salt — never stored or logged in plaintext.
Authentication
Short-lived access tokens with refresh; invite-only provisioning; role-based authorization.
Isolation
Per-workspace scoping enforced on every request; internal routes sealed from the public edge.
Data ownership
Your evidence, taught facts, and reads are yours — export or deletion available on request.
Availability
Managed, encrypted database with automated backups; monitored infrastructure.
Who touches your data — sub-processors

The corpus Insigo analyses is public-source material — news, registries, filings, public web. Model inference over your workspace runs under enterprise terms and is never used to train models; the private facts you teach the system stay in your workspace. These are the providers involved:

Google Cloud
Cloud infrastructure — hosting, database, backupsRepublic of Korea (EU adequacy decision)
Google Vertex AI
Model inference over workspace content — enterprise terms, never trained on your dataGoogle Cloud enterprise infrastructure
Lemon Squeezy
Billing & payments (merchant of record) — billing contact data only, no workspace contentUnited States (SCCs)
Google Workspace
Transactional email delivery — recipient name & address onlyGoogle enterprise infrastructure
PostHog EU
Product analytics — usage events & session recordings, cookielessEU · Frankfurt, Germany
GDPR & data protection (DSGVO)
Data residency
Customer workspaces — database and backups — are hosted on enterprise cloud infrastructure in the Republic of Korea, a country holding a European Commission adequacy decision (protection essentially equivalent to EU law). Product analytics is EU-hosted (Frankfurt).
Processor role & DPA
For your workspace content, you are the controller and we are the processor. A Data Processing Agreement meeting Article 28 GDPR — with our named sub-processor list — is available on request.
No model training
Workspace content and taught facts are processed under enterprise terms and never used to train foundation models.
No ad tracking
No advertising or cross-site trackers. Product analytics is EU-hosted (Frankfurt) and cookieless, tied to signed-in accounts only — never sold or shared for advertising.
Lawful transfers
Hosting and operations in the Republic of Korea are covered by the European Commission's adequacy decision; other transfers rely on Standard Contractual Clauses.
Data subject rights
Access, rectification, erasure, export, restriction, and objection — actioned within one month via privacy@insigo.ai.
Breach notification
Customers are notified without undue delay of any personal-data breach affecting their workspace, with the detail needed for their own GDPR obligations.
Deletion on exit
On termination, workspace data is deleted or returned within 30 days of request; backup copies clear within 90 days as backups rotate.

Data Processing Agreement, technical & organisational measures, and the current sub-processor list: privacy@insigo.ai

© 2026 InsigoPrivacyTerms