Contact Us
trust & security

Our commitment to security

Your data belongs to you. We host and operate the platform on AWS. This page lays out our certifications, infrastructure, and supporting documentation.

Used by universities, research hospitals, foundations, and government labs.
Certifications & reports
TX-RAMPauthorized
GovRAMPauthorized
AWS GovCloud (US)in use
SOC 2 Type IIon request
FedRAMPready
01 — security overview

How your data is protected

The controls we have in place. Supporting documentation for each is listed below.

01

Cloud hosting

Hosted on AWS, with environments separated by tenancy and workload.

02

Data protection

Encrypted in transit and at rest. Backups and retention aligned to institutional requirements.

03

Access control

Least-privilege, role-based access via security groups. Multi-factor authentication available for administrative and support access.

04

Compliance program

A documented program with regular internal review and third-party assessment.

05

Vendor management

Subprocessors are reviewed before onboarding and monitored against our requirements.

06

Monitoring & response

Continuous monitoring, with a defined incident response process and named owners.

02 — identity & access

Who can see what

Access is controlled at two levels: by group, and down to the individual record, with sign-on and audit controls.

role-based

Security groups

Users are assigned to security groups that carry View, Add, Edit, and Delete rights across each data area — Technologies, Patents, Agreements, and more.

per-record

Record Access Control

Grant or revoke View, Edit, and Delete rights on individual records, for finer control than a group alone provides.

governed intake

Security Collections

Require new records to be assigned to a collection as they’re created, applying record-level access consistently from the start.

sign-on

SSO / SAML

Single sign-on via SAML is supported, so access follows your institution’s identity provider.

MFA

Multi-factor authentication

Multi-factor authentication is available for administrative and support access.

audit

Record audit log

A full historical record of every change in your database — who changed what, and when — viewable globally or on an individual record.

03 — compliance & certifications

Certifications & authorizations

The current status of each program is listed below.

AICPA SOCreport on request

SOC 2 Type II

Independent audit of our security controls. Report released under NDA.

GovRAMP Authorizedauthorized

GovRAMP

Authorized under GovRAMP (formerly StateRAMP) for state and local government.

DIR TX-RAMP Certifiedauthorized

TX-RAMP

Authorized under the Texas Risk and Authorization Management Program.

FedRAMPready

FedRAMP

FedRAMP Ready. We’re glad to discuss scope and timing for federal evaluations.

summary on request

Penetration testing

Regular third-party testing. Summary report released under NDA.

active

Data Privacy Framework (DPF)

Certified under the EU-U.S. Data Privacy Framework, renewed annually.

in use

AWS GovCloud (US)

Eligible government workloads run in a dedicated GovCloud (US) environment.

Eligible government workloads are hosted in AWS GovCloud (US). AWS GovCloud’s own authorizations cover the underlying infrastructure and do not, on their own, constitute a FedRAMP authorization of Inteum.

04 — hosting & infrastructure

Where your data lives

Inteum runs on Amazon Web Services. Government workloads run in a separate environment from commercial workloads.

commercial environment

AWS Commercial (US)

Standard hosting for universities, hospitals, foundations, and private companies
Data encrypted in transit and at rest
Automated backups with point-in-time recovery
Redundancy across AWS availability zones
government environment

AWS GovCloud (US)

Dedicated environment for eligible government customers
Separated from commercial workloads
Supports stricter access and data-residency requirements
Hosted in AWS GovCloud (US) Regions

Backups & redundancy

Encrypted backups with defined retention and regular restore testing.

Availability

Built for high availability across multiple AWS availability zones.

Continuity

Business continuity and disaster recovery plans, reviewed regularly.

05 — documentation

Security documentation

Most documents download directly. SOC 2 and the penetration test summary are released under NDA through a short request form.

download directly
VPAT 2.4 · WCAG 2.1
PDF · accessibility
Download PDF
Privacy Policy (2026)
PDF
Download PDF
HECVAT (Full 4.10)
XLSX · higher-ed questionnaire
Download PDF
IT Policies, Procedures & Standards
PDF
Download PDF
Configuration Management Plan
PDF
Download PDF
Disaster Recovery Plan
PDF
Download PDF
Incident Response Plan
PDF
Download PDF
request access · NDA required
SOC 2 report
PDF · NDA required
Request access
Penetration test summary
PDF · NDA required
Request access
Requests reach our support team with security and compliance copied on every message. Turnaround is typically 1–2 business days. Prefer email? support@inteum.com
06 — frequently asked

Common questions

The VPAT, Privacy Policy, HECVAT, IT Policies, Configuration Management Plan, Disaster Recovery Plan, and Incident Response Plan all download directly from the documentation section.

Those two are released under NDA. Use the request form and we’ll route it to our security team, with compliance copied.

Yes. Inteum is authorized under both TX-RAMP and GovRAMP. FedRAMP status is Ready.

Yes. We complete questionnaires including HECVAT and CAIQ. The current HECVAT is available for direct download above.

Yes. Eligible government workloads run in a dedicated AWS GovCloud (US) environment, separate from commercial hosting.

Use our vulnerability report form at inteum.com/vulnerability-report-form. We review every submission.

Email support@inteum.com. Security and compliance team members are copied on documentation requests.

Need something that isn’t here?

If your review needs a document or answer not listed above, ask. We’ll get it to the right person.