Our commitment to security
Your data belongs to you. We host and operate the platform on AWS. This page lays out our certifications, infrastructure, and supporting documentation.
How your data is protected
The controls we have in place. Supporting documentation for each is listed below.
Cloud hosting
Hosted on AWS, with environments separated by tenancy and workload.
Data protection
Encrypted in transit and at rest. Backups and retention aligned to institutional requirements.
Access control
Least-privilege, role-based access via security groups. Multi-factor authentication available for administrative and support access.
Compliance program
A documented program with regular internal review and third-party assessment.
Vendor management
Subprocessors are reviewed before onboarding and monitored against our requirements.
Monitoring & response
Continuous monitoring, with a defined incident response process and named owners.
Who can see what
Access is controlled at two levels: by group, and down to the individual record, with sign-on and audit controls.
Security groups
Users are assigned to security groups that carry View, Add, Edit, and Delete rights across each data area — Technologies, Patents, Agreements, and more.
Record Access Control
Grant or revoke View, Edit, and Delete rights on individual records, for finer control than a group alone provides.
Security Collections
Require new records to be assigned to a collection as they’re created, applying record-level access consistently from the start.
SSO / SAML
Single sign-on via SAML is supported, so access follows your institution’s identity provider.
Multi-factor authentication
Multi-factor authentication is available for administrative and support access.
Record audit log
A full historical record of every change in your database — who changed what, and when — viewable globally or on an individual record.
Certifications & authorizations
The current status of each program is listed below.
SOC 2 Type II
Independent audit of our security controls. Report released under NDA.
authorizedGovRAMP
Authorized under GovRAMP (formerly StateRAMP) for state and local government.
authorizedTX-RAMP
Authorized under the Texas Risk and Authorization Management Program.
FedRAMP
FedRAMP Ready. We’re glad to discuss scope and timing for federal evaluations.
Penetration testing
Regular third-party testing. Summary report released under NDA.
Data Privacy Framework (DPF)
Certified under the EU-U.S. Data Privacy Framework, renewed annually.
AWS GovCloud (US)
Eligible government workloads run in a dedicated GovCloud (US) environment.
Eligible government workloads are hosted in AWS GovCloud (US). AWS GovCloud’s own authorizations cover the underlying infrastructure and do not, on their own, constitute a FedRAMP authorization of Inteum.
Where your data lives
Inteum runs on Amazon Web Services. Government workloads run in a separate environment from commercial workloads.
AWS Commercial (US)
AWS GovCloud (US)
Backups & redundancy
Encrypted backups with defined retention and regular restore testing.
Availability
Built for high availability across multiple AWS availability zones.
Continuity
Business continuity and disaster recovery plans, reviewed regularly.
Security documentation
Most documents download directly. SOC 2 and the penetration test summary are released under NDA through a short request form.
Common questions
The VPAT, Privacy Policy, HECVAT, IT Policies, Configuration Management Plan, Disaster Recovery Plan, and Incident Response Plan all download directly from the documentation section.
Those two are released under NDA. Use the request form and we’ll route it to our security team, with compliance copied.
Yes. Inteum is authorized under both TX-RAMP and GovRAMP. FedRAMP status is Ready.
Yes. We complete questionnaires including HECVAT and CAIQ. The current HECVAT is available for direct download above.
Yes. Eligible government workloads run in a dedicated AWS GovCloud (US) environment, separate from commercial hosting.
Use our vulnerability report form at inteum.com/vulnerability-report-form. We review every submission.
Email support@inteum.com. Security and compliance team members are copied on documentation requests.
Need something that isn’t here?
If your review needs a document or answer not listed above, ask. We’ll get it to the right person.
