Terms & policies
Security and trust in the platform
Last updated: May 13, 2026.
We build the platform with the goal of protecting data for the teams that trust us and for their customers. This page explains how we approach security across the platform.
1. General security approach
Security is part of how the platform is designed from the start, not added as an afterthought.
We apply the principle of least privilege across the platform: each part of the system can only access what it needs to function.
We perform regular reviews and updates of dependencies, configurations, and security practices.
2. Infrastructure and hosting
The platform runs on cloud infrastructure from providers that offer availability guarantees and physical server protection.
Each organisation's data is stored with logical isolation, preventing one customer from accessing another organisation's data.
Data is stored within the European Union.
3. Data encryption
All communications between client and platform are encrypted using TLS 1.2 or higher.
Data stored in the database is managed with encryption at rest enabled by the infrastructure provider.
Passwords are hashed using Argon2, a high-resistance key derivation algorithm, and are never stored in plain text.
4. Authentication and access control
The platform uses short-lived JWT tokens for session authentication, complemented by httponly refresh cookies for added browser security.
New user registration uses single-use magic links, eliminating weak passwords in the sign-up flow.
Access to data and features is controlled by roles within each organisation: owner, admin, and member.
- Access tokens have limited validity and are renewed automatically.
- Authentication cookies are marked as httponly and secure.
- Each organisation operates in an isolated space with its own context.
5. Backups and availability
We run automated database backups on a regular schedule.
Files and documents uploaded to the platform are stored with redundancy, allowing recovery after infrastructure failures.
We actively monitor service health to detect and respond to incidents as quickly as possible.
6. Privacy and regulatory compliance
The handling of personal data is governed by the site Privacy Policy, available on this site.
We apply privacy-by-design principles, limiting what data is collected and how long it is retained.
In the event of a security breach affecting personal data, we will follow the notification procedures required by applicable law.
7. Responsible vulnerability disclosure
If you find a security vulnerability in the platform, we ask you to report it responsibly before any public disclosure.
Write to us at info@intake.es with the details of the vulnerability. We commit to investigating and responding to each report received.
We value the collaboration of researchers and users who help improve the security of the platform.
8. Updates to this page
This page reflects the current security practices for the platform and may be updated as our measures or infrastructure evolve.
The version published on this page is always the most recent.
Security contact
To report vulnerabilities or for any security question, write to us directly. We commit to responding as quickly as possible.
- Owner
- Castany Carranza Adrià
- NIF
- 48219934C
- info@intake.es
- Location
- Calle Can Targa, Núm. 27 C, 08320 El Masnou (Barcelona), Spain
- Domain
- intake.es
This page is informational and describes the general security approach for the platform. For specific questions about personal data protection, also refer to our Privacy Policy.