Trust Security and governance

Clear the security review without losing the quarter.

The slowest part of an AI deployment is usually not the build, it is the review that clears it. So here it is up front: where your data lives, who can act on it, what gets logged, and which certifications we do and do not hold.

25+ years in enterprise IT, including Fortune 500 pharma and healthcare data platforms.

  • Least privilege
  • Human approval
  • Audit logging

No preparation needed. You leave with next steps in writing.

Have a question? Call or text (941) 242-7434 Text

By hand, then governed

The work does not change. What changes is who does the routine part, where a person is still required, and whether anyone can show what happened afterwards.

Where your data lives

Your review scope does not grow.

Nothing new leaves your boundary, so there is no second copy of your records to protect, no fresh transfer for your privacy team to paper, and no vendor environment for your security team to assess. The work happens inside the perimeter you already defend and already pay to defend.

That holds because we deploy into your own cloud, whether that is AWS, Azure, or GCP, inside your VPC and inside the audit boundary your team already controls. The system runs where your other regulated workloads run. There is no side trip to an IntellaGrow account and no shadow copy of your records sitting somewhere you cannot see. The accounts, the network, and the keys remain yours.

Access and permissioning

A mistake stays as small as the access that caused it.

The expensive version of an agent error is the one where a process holding broad standing credentials reaches a system nobody expected it to touch. Bounding the access is what bounds the cost of being wrong, and it is the difference between an incident that is a ticket and one that is a disclosure with legal and customers attached.

So each agent is scoped to exactly what its job needs and nothing more. Broad, standing access is not the default here. An agent that reads a reporting table cannot also reach into a payments system, because it was never granted that path.

  • Permissions scoped per agent, per task, not per account.
  • No standing admin access handed to automated processes.
  • Access reviewed and tightened as roles change.

Human approval gates

Your people spend their hours only on the decisions that carry risk.

The routine volume goes to the system, which is where the capacity comes from. The judgment calls stay with your team, which is how you get that capacity back without handing over the authority. Nobody finds out after the fact that an agent spoke for the business.

The mechanism is a gate. Anything that acts on sensitive data or sends output to the outside world stops there, and a person reviews and approves before the action runs. That line is set with you, not assumed. You decide which actions need a person in the loop, and the system holds at that line until someone with the authority to approve does.

Audit and evidence

Answer the evidence request without pulling the team off the roadmap.

The expensive part of an audit is rarely the audit. It is the engineering time spent afterwards reconstructing what happened, out of logs that were never designed to answer that question, while the work those people were hired for waits. When the record is written as the system runs, most of that cost never arrives: the answer is a query rather than a project.

What makes that possible is that every action leaves a reviewable record: what ran, on whose authority, against what data, and what it produced. The trail is built to be read by your auditors and your own team, not just by an engineer. When a review comes, the record is already there.

How a governed agent runs

The gate is the part that matters. Routine work keeps moving; anything with consequences waits for a person, and either way the record is already written.

Compliance posture

A straight answer now, including where the answer is no.

What costs a buyer time is not a gap. It is finding out about the gap late in diligence, after the budget is allocated and the timeline is committed. So the posture is written down here, before you spend a review cycle on it. This practice was shaped inside large, heavily regulated enterprises, and that discipline is how we build by default: scoped access, logged actions, human approval on risky decisions, and data that stays where it belongs. We set guardrails to your risk and compliance requirements rather than a generic checklist.

Where we act as a business associate on an engagement involving protected health information, we will execute a Business Associate Agreement before that data comes into scope. We are glad to walk your security and compliance teams through how a given deployment maps to the controls they already enforce, which is usually the fastest way to shorten your own review rather than lengthen it.

What we build to, and what we hold

Read the second half of every entry below. That is the part that tells you whether you have to budget for a gap, and it is the part most vendors leave out until diligence, when the budget is already spent.

  • HIPAA Security Rule Deployments are designed against the technical safeguards at 45 CFR 164.312: access control, audit controls, integrity, authentication, and transmission security. There is no HIPAA certification to hold, for us or for anyone.
  • AICPA Trust Services Criteria The criteria a SOC 2 examination runs against. We build toward the evidence a Type II asks for, in particular a complete, dated population of system actions across the observation period. We hold no SOC 2 report, and SOC 2 is an attestation rather than a certificate in any case.
  • NIST AI Risk Management Framework The governance work is structured around its four functions: govern, map, measure, and manage. The framework is voluntary and non-certifiable, so nobody is certified against it.
  • ISO/IEC 42001 The AI management system standard. We align to its control structure. It certifies how an organization governs AI rather than whether a given model is safe or accurate, and we are not certified against it.

A plain note on language: we describe how we run engagements, not badges we have not earned. IntellaGrow holds no security or AI certification today, is not a law firm or an auditor, and issues no certifications of its own. If a specific attestation matters to your decision, ask, and we will tell you exactly where things stand.

Security review questions

The questions your security team will open with.

Answered here so your reviewer can close half the questionnaire before the first call, and so the review starts from facts rather than from a form. Several of the answers are no, which is the point.

  • Where does our data live?

    Inside your own cloud account, whether that is AWS, Azure, or GCP, in your VPC and inside the audit boundary your team already controls. The practical effect on your review is that its scope does not grow: no second copy of your records to protect, no new transfer for your privacy team to paper, and no vendor environment to assess. Your data does not leave your environment to reach us, and the accounts, the network, and the keys stay yours.

  • Is IntellaGrow SOC 2 certified?

    No, and no organization is, because SOC 2 produces an attestation report from a licensed CPA firm rather than a certificate. IntellaGrow holds no SOC 2 report today and does not claim one. What the work produces instead is the artifact that costs you real money to be missing: a dated, retrievable population of the actions the system took across the whole observation window, which is what a Type II examination samples. An ungoverned AI deployment cannot hand an auditor that population, and if the record was never written there is nothing to sample and no way to buy it back afterwards.

  • Are you HIPAA compliant?

    Compliance is a property of your whole program, assessed by the HHS Office for Civil Rights, and no vendor can self-declare it on your behalf. There is also no such thing as HIPAA certification. What you can hold us to is that a deployment is designed against the technical safeguards at 45 CFR 164.312: access control, audit controls, integrity, authentication, and transmission security. Your privacy officer reviews controls they already recognize rather than learning a new vendor model, and where we act as a business associate, we will execute a Business Associate Agreement before protected health information comes into scope. We hold none today because no engagement has yet required one.

  • How do you control what an AI agent can reach?

    Scoping is what caps the cost of an agent being wrong, so each one gets exactly what its task needs and nothing standing. An agent that reads a reporting table has no route into a payments system, because that route was never issued. Where protected health information is involved this is also a regulatory requirement, not just good practice: the HIPAA minimum necessary standard at 45 CFR 164.502(b) limits access to what the purpose actually requires, which is the rule an agent handed a whole record for a three-field task has already broken.

  • What gets logged, and would an auditor accept it?

    You get to answer an evidence request without a reconstruction project, because every action is recorded as it happens: what ran, on whose authority, against what data, and what it produced. The record is written before the result is returned to the calling system, so it exists even when the downstream workflow fails. Whether an auditor accepts it is their determination against their own scope and standard, and no vendor can promise that outcome. What we control is that the evidence exists, is dated, is complete for the period, and is retained under your rules in your environment.

  • Which frameworks do you build to, and which do you hold?

    You get a direct answer now rather than a gap that surfaces late in diligence, when it costs a review cycle. We design against the HIPAA Security Rule, the AICPA Trust Services Criteria that a SOC 2 examination is conducted against, the NIST AI Risk Management Framework functions of govern, map, measure, and manage, and the ISO/IEC 42001 control structure for AI management systems. We hold no certification, attestation, or authorization against any of them, and we will not imply one. If a specific attestation decides your purchase, ask, and we will tell you exactly where things stand rather than where we would like them to be.

  • Who else touches our data?

    Only the parties you approve, and you can see the whole list before you sign. The deployment runs on your cloud accounts and on the model providers you approve, chosen with you during the assessment rather than assumed. The vendors IntellaGrow uses to run its own business, such as hosting, forms, and email, are listed in full on the sub-processors page.

How we handle your data in an engagement

What you get, and the control behind it.

Six commitments that hold across every engagement, regulated or not.

  • Your review scope does not grow

    Agents run inside your AWS, Azure, or GCP environment. Your data stays in your accounts and is not copied out to ours, so there is no new vendor boundary for your team to assess.

  • A mistake stays contained

    Every agent gets only the permissions its job requires, which caps what a wrong step can reach. We do not request broad or standing access by default.

  • Nothing risky runs unattended

    Anything that touches sensitive data or sends external output waits for a person to approve it, so the authority stays with your team.

  • You can prove what happened

    Actions are logged as they happen, so the evidence exists when your auditors, your legal team, or you ask for it, instead of being rebuilt under deadline.

  • Protected health data waits for the paperwork

    Where we act as a business associate on an engagement that touches protected health information, we will execute a Business Associate Agreement before that data is in scope. We hold none today because no engagement has yet required one.

  • Your rules, not a template

    We configure access, retention, and approval rules to your risk and compliance requirements, so your team is not arguing with someone else's defaults.

The shortest path through the review is to start it now.

An intro call with the people who own the review costs twenty minutes and saves the round trips. No pitch, just straight answers about where your data lives, who can act on it, and what gets logged, while there is still time to change the design rather than argue about it.

Book an intro call

If AI is not the right tool for your problem, you will hear that from us.

Within one business dayYour scope is settled, in writing.

Just have a question? Call, text, chat, or send a note.