Security & Compliance
Last updated: 11 August 2026 | Version 1.1
Intelli-Assist is the AI executive assistant from IntelliInfra AI Pty Ltd (ACN 695 904 511). This page sets out where your data lives, how it is protected, and the regulatory boundary we operate within — with particular attention to Australian financial-advice and other regulated professional firms.
Plain-English boundary: IntelliInfra AI Pty Ltd is not an Australian Financial Services (AFS) licensee, an authorised representative, a registered tax agent, an Australian legal practitioner, or a registered medical practice. Intelli-Assist produces drafts, summaries, and analysis. The professional or licensee using Intelli-Assist remains responsible for the advice, lodgement, document, or decision that goes to the end client.
1. Where your data lives
Intelli-Assist runs on Google Kubernetes Engine in the australia-southeast1 (Sydney) region. Your account, conversations, encrypted integration tokens, embeddings, and database backups are stored in that region.
- Application: GKE in
australia-southeast1. - Primary database: PostgreSQL 16 with pgvector and pgcrypto, SSL enforced, in-region.
- Object storage and artefact registry: Google Artifact Registry in
australia-southeast1. - AI inference: traffic is routed to model providers under signed enterprise agreements; we prefer providers with AU/regional data-handling commitments and we do not authorise training on customer prompts or outputs.
- Backups: encrypted and in-region, retained 30 days daily, 90 days weekly, 12 months monthly.
2. Encryption
- In transit: TLS 1.2+ on every connection — public ingress, agent-to-database, agent-to-agent.
- At rest: Disk-level encryption on every volume; OAuth tokens, refresh tokens, and webhook secrets are encrypted before being written to the database using a dedicated encryption key held separately from the database credential. Sensitive columns use PostgreSQL
pgcrypto. - Key separation: the OAuth-token encryption key and the application database password are separate, held in different secret stores, and never written to the application image.
3. Access, isolation, and audit
- Every record is scoped to a tenant (organisation). Queries enforce the tenant boundary in application code; multi-tenant isolation is verified by integration tests.
- Every action your AI takes — opening a record, sending a message, generating a document — is written to an audit log with the user, the agent, the tool called, and the arguments. The log is exportable on request.
- Production access by IntelliInfra AI staff is limited to break-glass scenarios, requires MFA, is logged separately, and is subject to a written authorisation from the customer for any access that would touch customer-identifiable data.
- Read-only support access never extends to your inbox, your client files, or your conversations without your explicit grant.
4. Integrations and credentials
- We connect to your tools through OAuth wherever the provider supports it (Google Workspace, Microsoft 365, Xero, Slack, GitHub, GitLab, HubSpot, Salesforce, Notion, and others).
- Tokens are stored encrypted, scoped per organisation, and revocable from your settings page or by disconnecting the integration at the provider.
- Where a provider does not support OAuth (some self-hosted systems, application passwords such as WordPress), we store the credential encrypted and use it only for the calls you have authorised.
- We do not bulk-copy your inbox, drive, calendar, or CRM. Intelli-Assist accesses your data on-demand to answer the request in front of it, and writes to memory only what you tell it is worth remembering.
- Coming: 1Password CLI integration, so your most sensitive credentials never leave your own vault — the agent presents to a system as you, using a token your vault releases for the duration of the call. We will publish a separate technical note on this when it ships.
5. PII handling and AI safeguards
- Outputs pass through an output-guardrail layer that flags personally identifiable information and, for content generation, applies a grounding check against the source material to reduce hallucination.
- Conversations are stored in your tenant. You can delete a conversation, export it, or purge the underlying memory at any time from Settings.
- Long-term memory is opt-in per tenant. When enabled, what is remembered is visible and editable in the memory browser.
- We do not use your prompts or outputs to train models. We do not share customer data with third parties except as needed to deliver the integration you have configured (e.g. sending an email through your Gmail account on your instruction).
6. AU financial-advice firms — where we are up to
Status: in development, not yet available.
Advice-specific drafting and file-review skills are being built. They are not in the product today, and nothing on this page should be read as a statement that Intelli-Assist currently produces Statements of Advice, Records of Advice, Fee Disclosure Statements, or compliance audits against the advice obligations. If you are evaluating Intelli-Assist for an AFS licensee, talk to us about where it actually is before you plan around it.
What we can say today: Intelli-Assist is a general drafting, research, and document-processing assistant. Licensees already use general-purpose skills for correspondence, meeting notes, research summaries, and document review. Those outputs are drafts for a human to check, the same as everything else the product produces.
The regulatory boundary does not change as that work lands. Intelli-Assist does not give financial product advice. Any advice-related capability we ship will produce drafts for the licensee's authorised representatives, paraplanners, and responsible managers to review, evidence, and sign, and will carry a mandatory disclaimer saying so. The licensee remains the AFS-licensed party responsible for the advice given.
We do not maintain a register of approved products, do not exercise discretion over client portfolios, do not transact on client behalf, and do not communicate with retail clients in the licensee's name without that licensee's explicit configuration.
If advice-firm workflows matter to you, we would rather build them with you than describe them before they exist. Get in touch.
7. What we do not do
- We do not train models on your prompts, your documents, or your outputs.
- We do not read customer conversations except where you raise a support ticket and grant read-only access to a specific conversation, or where lawfully compelled.
- We do not sell, rent, or share customer data — your prompts, documents, conversations, or connected-system content — with advertising or analytics networks. This is separate from ordinary web analytics on our public marketing site, which is described in our Privacy Policy and only runs where you have consented.
- We do not bulk-copy your inbox, drive, or calendar to a separate index — we query your systems on-demand under your OAuth grant.
- We do not give regulated advice. Any output that resembles advice is a draft for a licensed professional to review.
8. Independent assurance
We are working towards independent third-party assurance (SOC 2 Type II / ISO 27001 path). Until that completes, we publish this posture transparently and will provide on request:
- A current architecture diagram including data flows and provider list.
- The list of sub-processors and their data-handling regions.
- Our incident-response procedure and notification commitments.
- A penetration-test summary letter when the most recent test is completed.
If you are an AFSL holder evaluating Intelli-Assist for inclusion in your licensee's technology stack, contact us — we will provide the evidence pack your responsible manager needs to make the assessment.
9. Reporting a security issue
Please email security@intelliinfra.ai with reproduction steps and any supporting evidence. We acknowledge within 24 hours and aim to triage critical issues within 72 hours.
For data-subject access, correction, or deletion requests under the Australian Privacy Act 1988 (Cth) or applicable foreign law, see our Privacy Policy.
This page describes the security and compliance posture of Intelli-Assist as operated by IntelliInfra AI Pty Ltd. It is provided for transparency and does not itself constitute a warranty, contract, or legal advice. Specific contractual commitments, including any service level agreements, are set out in the Master Services Agreement applicable to your subscription.