Security
The controls that protect licensed data and the record of who touched it
intelID holds credit reporting data, register extracts and audit records about real people. The security position below is what allows those licences to be held and what an organisation's own risk team will want to review before requesting access.
Hosting and infrastructure
The platform runs on Google Cloud Platform. Physical data centre security, hardware lifecycle management, network isolation and platform-level protections are provided by that infrastructure, which is independently audited by its operator. intelID does not run servers in an office, and there is no on-premises copy of the production environment.
Data is held in a hosting region selected for the service, and some processing or support may occur outside New Zealand. Where information is transferred outside New Zealand we take reasonable steps to ensure the recipient is subject to safeguards comparable to those in the Privacy Act 2020, in accordance with Information Privacy Principle 12.
Production, and any non-production environment used for testing, are separated. Live subject data is not copied into a test environment. Administrative access to infrastructure is limited to named individuals, uses multi-factor authentication, and is reviewed rather than granted permanently by default.
Encryption
Traffic between a user and the platform is encrypted in transit using current transport layer security. Connections to upstream data providers are likewise encrypted, and credentials for those integrations are held in managed secret storage rather than in application configuration.
Data at rest is encrypted, including account records and the audit log. Encryption keys are managed through the hosting platform’s key management service, so key material is not handled manually by staff in the course of ordinary operations.
Access control
Most data incidents begin with an account, not with infrastructure.
There is no self-service signup. An account exists only after the applicant, the organisation and the intended authorised purpose have been verified, and the sources that account may reach are set at the time it is issued. A user cannot see a source their role has not been granted, and elevated permissions are not available on request from within the application.
Organisation administrators manage their own users, including removing access when someone leaves. Because every query is written to the audit log with the user, the timestamp, the declared authorised purpose and the sources touched, an unusual pattern of activity is visible while it is still an internal matter. The compliance framework these logs support is described on the compliance page.
Internal staff access follows the same principle. Support access to an organisation’s data is limited to what is required to resolve a specific issue, is logged, and is not a standing entitlement held by everyone in the company.
Subject data is never used for marketing, is never resold, and is not exposed to public indexing. This website carries no subject data at all, which is why nothing behind the login is reachable from a search engine.
Monitoring and incident response
A plan that exists before an incident is worth more than a well-written statement afterwards.
- Detect. Platform and application logging is monitored for authentication anomalies, unusual query volume and infrastructure alerts.
- Contain. Affected accounts or integrations are suspended first, before root cause analysis begins.
- Assess. We establish what information was involved, whose it was, and whether the event is a notifiable privacy breach under the Privacy Act 2020.
- Notify. Where a privacy breach has caused, or is likely to cause, serious harm, we notify the Office of the Privacy Commissioner and the affected individuals as required by the Privacy Act 2020, and we notify the affected customer. Any data provider whose information was involved is also notified.
- Remediate. The fix, the timeline and the preventive change are recorded, and the affected organisation receives a written account.
Retention
What we keep, and why we keep it.
- Verification material. Held while the account exists, and afterwards for as long as we need it to show that access was granted lawfully.
- Audit records. Retained after an account closes so the lawful basis for a search can still be demonstrated.
- Declined access requests. Retained only as long as needed to record the decision.
We do not retain personal information for longer than the purpose for which it may lawfully be used requires. The full position is set out in our privacy policy.
Vendor management
Our security position is only as good as the providers we depend on.
Every third party that touches platform data is assessed before it is integrated: hosting, data providers, and any supporting service. The assessment covers the provider’s own security posture, where data is held, what it may be used for, and how the relationship can be ended. Our vendor security programme is benchmarked to SOC 2 Type II providers. intelID does not itself claim a SOC 2 attestation, and we will not describe our position as certified when it is not.
Data provider agreements set permitted-purpose conditions that we pass through to users rather than absorb quietly. That is why the authorised-purpose declaration is mandatory and why some sources are restricted by role. The legal basis for each integration is set out on the data sources page.
Reporting a vulnerability
If you believe you have found a security issue affecting intelID, email info@intelid.nz with enough detail to reproduce it and a contact number. Please do not test against real subject data or another organisation’s account. We acknowledge reports, triage them, and will not pursue action against anyone acting in good faith.
Security questions
Where is intelID hosted?
The platform is hosted on Google Cloud Platform. Infrastructure security, physical access control and network protection at the hosting layer are provided by that platform. Some processing or support may occur outside New Zealand, under safeguards comparable to the Privacy Act 2020 in accordance with Information Privacy Principle 12.
Is data encrypted?
Yes. Data is encrypted in transit and at rest, including subject results, account records and audit logs.
Does intelID hold a SOC 2 attestation?
No. intelID does not claim a SOC 2 attestation. Our vendor security programme is benchmarked to SOC 2 Type II providers.
How do I report a security issue?
Email info@intelid.nz with the detail of the issue and a contact number. Reports are acknowledged and triaged, and we will not pursue action against a reporter acting in good faith.
Have your risk team review us first
If your organisation needs written detail on hosting, encryption or incident response before applying, contact us and we will provide it.