Security & data handling
Security details, stated plainly.
This page describes the current product behavior buyers can verify in the platform and our published Privacy Policy. It focuses on how access, conversation data, connected tools, and model providers work together.
On this page
01
Authentication and workspace access
Accounts can sign in with Google OAuth or with an email and password. IntellaOne uses session-based access after sign-in.
Authenticated workspace access is scoped to the account and the workspace it is allowed to use. Workspaces distinguish owners, admins, and members: owners and admins have management scope, while members have member access.
- Signed-in access is required for the workspace dashboard, workspace library, and management operations.
- Workspace membership is checked before authenticated workspace-scoped operations are performed.
- An owner- or admin-issued share link can provide a limited live-call workspace experience without signing up. It grants access only to the live-call endpoints, not the workspace library; inactive or revoked links are rejected.
02
Transport and stored data
The published Privacy Policy says data is transmitted over HTTPS and that IntellaOne uses reasonable security measures. It also notes that no method of transmission or storage is completely secure.
Transcript text, generated content, uploaded source content, and the extracted content used in a workspace are retained as server-side workspace data under the Privacy Policy. This page does not promise a fixed retention window.
- Uploaded source content is processed into extracted text for workspace source content; that extracted text is retained as workspace data.
- Session transcript text is retained with the session rather than treated as browser-only data.
- Newly saved connector credentials are encrypted before storage.
03
Audio and transcript text are different
IntellaOne never records or stores call audio. Depending on the call mode, speech recognition runs in the browser, where audio is not transmitted to our servers, or audio streams to our speech provider in real time and is discarded after transcription.
The resulting transcript text is processed by IntellaOne servers to provide live guidance and is retained with the session. Audio not being retained does not mean transcript text is not retained.
- Browser speech recognition: the call audio is not transmitted to IntellaOne servers.
- Streaming speech recognition: audio is sent to the speech provider in real time, then discarded after transcription.
- Call audio is not a stored recording in either mode; transcript text and session context are separate data flows.
04
Integrations, connector credentials, and write-back
Connected tools sync server-side under the user's own credentials. Connector availability, requested permissions, inbound data, and outbound actions are connector-specific; the public integrations catalog is the current source for those details.
Connector credentials are handled server-side. CRM write-back requires explicit rep initiation or approval: proposal approval authorizes proposal writes, while forwarding notes occurs only after an explicit rep action.
- Integrations are opt-in and use the permissions described by each connector.
- Connected data can include CRM context, prior conversation context, approved documents, or meeting context depending on the connector.
- A successful write-back depends on the connected provider accepting the approved action; availability and provider behavior can change.
05
Customer data and model processing
Authorized workspace context may be sent to third-party AI providers solely to provide the requested feature. Provider processing is how a requested AI feature is delivered; it is distinct from using customer data for model training.
Our Privacy Policy states that customer data is not used to train or fine-tune models. That published policy statement is the source for the training and fine-tuning claim; this page does not add a broader provider-policy or organizational promise.
Model outputs can be incomplete or incorrect. Sellers should review suggestions and supporting sources before use.
06
For procurement and security review
This overview describes current product behavior and published policy language. It does not replace a customer-specific security assessment.
Requirements beyond these published facts—such as negotiated terms, geographic processing, specific retention commitments, or compliance documentation—should be reviewed with the IntellaOne team before purchase.