232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE
← Intercom · Security Page

This is an extract from an archived copy, fetched 10 September 2026. Intercom didn't author this page for us. It's a snapshot we captured from https://www.intercom.com/security. We hold the whole page and publish this part of it: the sentence a verdict rests on, with the text either side, so you can see it hasn't been lifted out of an exception.

SHA-256
66DF498F…5804

The passage, in context

Paragraph 25 of 29

Security & Privacy FAQs

Intercom and Fin hold SOC 2 Type II and HIPAA compliance along with ISO 27001, ISO 27018, ISO 27701, and ISO 42001 certification, and Fin AI Agent is also AIUC-1 certified (the industry standard for AI agent security). We also comply with GDPR and CCPA. All documentation is available to self-serve at trust.intercom.com .

The Fin AI Engine applies safety checks at multiple stages before any response reaches a customer: it validates the query, retrieves content grounded in your knowledge base, reranks for accuracy, and performs a final validation pass before responding. When confidence thresholds aren't met, Fin escalates to a human agent rather than guessing.

Fin can use anonymized customer data for model fine-tuning, and you can opt out at any time, with data deleted within 30 days. Third-party AI providers are contractually restricted from using your data for training, with zero data retention once an output is generated.

Intercom's services, including AI Agent and Core Platform, are backed by a 99.8% uptime SLA, with redundant systems across regions and no single point of failure. Fin's multi-model resilience means it automatically switches between AI providers to maintain performance.

Intercom integrates with Okta, Azure AD, and OneLogin for SSO, and supports 2FA, SCIM, and IP restrictions, so only the right people reach your workspace and data.

Data is hosted in the US, EU, or Australia based on your residency needs, with redundant systems architected for continuous uptime across regions.

Checking the rest of it

The complete page is kept here and isn't republished. It's Intercom's copyrighted document, and an extract is what a reader needs to check a quotation. The SHA-256 above is of that whole snapshot: fetch the page yourself, hash it, and you can tell whether ours has been altered without having to trust us.

If you work for Intercom, or you are researching this and need the full capture, ask us for it and we will send it. If you believe a quote here is wrong or out of date, send us the paragraph. The correction gets published beside the clause.