Your research and portfolio data are personal. We treat privacy and security as first-class - local-first by design, with your data kept yours.
All data in transit is encrypted via TLS 1.3. All data at rest uses AES-256. Your broker OAuth tokens, OTP secrets, and payment data are never stored in plain text - ever.
Intrynsic enforces phone or email OTP verification on every new login. Broker connections use scoped OAuth tokens - we request the minimum permissions required and never store credentials.
We monitor authentication and data-access events and respond promptly to anything anomalous, with audit logging across the platform.
Production infrastructure runs in India-based data centres. We use isolated environments per service and follow privacy-first principles throughout.
We run a coordinated vulnerability disclosure programme. Security researchers who responsibly report valid vulnerabilities are credited and compensated. We commit to a 48-hour initial response and 30-day remediation target for critical issues.
Patch deployed within 6 hours of report. No user data accessed. Reporter rewarded under our bug bounty programme.
Staging environment hardened. Error messages sanitised. No production impact.
Report it responsibly and we'll respond within 48 hours. Valid reports are rewarded.
security@intrynsic.ai