SECURITY

Security is a foundation, not an afterthought.

IntelliCEO is early-stage software built by a small team — and we take that seriously. Every business's data is isolated at the database level, sensitive work like payment processing is handled by specialists who do it better than we could build ourselves, and we're transparent about exactly what's in place today as we continue to harden the platform over time.

A waiter serving a table at an outdoor restaurant

How your data is protected in transit and at rest.

All traffic between you and IntelliCEO — and between IntelliCEO and the infrastructure it runs on — is encrypted using TLS. Application data is stored in Supabase's managed Postgres infrastructure.

Encrypted in transit

Every connection to IntelliCEO uses TLS, the same standard used across the web for secure connections.

Encrypted at rest

Application data is stored in Supabase's managed infrastructure, which encrypts data at rest at the platform level.

Your account is protected by dedicated authentication infrastructure.

IntelliCEO uses Supabase Auth to handle sign-in, sessions, and password resets — your password is never processed, stored, or logged by IntelliCEO's own systems.

Managed authentication

Sign-in and password handling run through Supabase Auth, a dedicated authentication service, not custom code we wrote ourselves.

Secure sessions

Your session is managed through secure cookies and refreshed automatically on every request.

Email-verified password resets

Resetting your password requires access to the email address on your account.

Your financial data is isolated — and never touches payment details.

Every business's financial data — revenue, cash, costs, and the numbers you enter or sync from your point-of-sale system — is isolated at the database level using row-level security, enforced on every request. No other account can ever query or see it.

Row-level tenant isolation

Every table enforces row-level security tied to your business — there's no shared query path that could return another account's data.

Payments handled entirely by Stripe

IntelliCEO never receives, processes, or stores your card details. All payment data is handled directly by Stripe.

POS sync is aggregate-only

Square and Clover integrations pull month-to-date revenue totals only, never individual transaction or card-level data.

Your business data belongs to you.

IntelliCEO doesn't yet have a self-service export or deletion tool built into the product. If you'd like a copy of your data, or want it deleted entirely, email info@intelliceo.com and we'll take care of it directly.

What IntelliCEO sends to its AI provider, and what it doesn't.

The CEO Brief, Chat, and Content Studio are powered by Anthropic. To ground its answers in your real business, IntelliCEO sends the information you've entered — your business overview and priorities, your finance snapshot, and recent conversation history. IntelliCEO never sends your payment details, login credentials, or point-of-sale access tokens to Anthropic or anyone else. Anthropic's own API terms state that data submitted through the API is not used to train their models.

The specialists IntelliCEO relies on.

Rather than building everything ourselves, IntelliCEO relies on established providers for the functions they specialize in.

Supabase

Authentication and database infrastructure, including all business data.

Stripe

Billing and payment processing — the only place your card details are ever handled.

Anthropic

Powers the CEO Brief, Chat, and Content Studio.

Square & Clover

Point-of-sale revenue sync, only for businesses that connect one.

Sentry

Error monitoring, to help us catch and fix problems quickly.

What happens to your data when you cancel.

Canceling your subscription stops billing, but your account and data stay intact — you can pick up right where you left off if you reactivate. If you'd prefer your data be deleted entirely instead of retained, email info@intelliceo.com and we'll process the request.

Found a vulnerability? Tell us.

If you believe you've found a security vulnerability in IntelliCEO, please report it to info@intelliceo.com. We ask that you give us reasonable time to investigate and address the issue before any public disclosure, and we commit to responding to every report we receive.

Questions about security?

For security questions, vulnerability reports, or data requests, reach us directly.