Data Security
Integrate.io does not store customer data. We move and transform data between customer systems, with data encrypted in transit and at rest.
Security Overview
Integrate.io does not store customer data. We move and transform data between customer systems, with data encrypted in transit and at rest.
After customer processing completes, ephemeral data is deleted. Temporary copy and unload data is automatically deleted within 24 hours.
Integrate.io undergoes an annual SOC 2 compliance audit and third-party security penetration test. Audit and test reports are available upon request.
We sign data processing agreements and can process all data in our European data center hosted in the Ireland region.
Direct connection, SSH Tunnel, Reverse SSH Tunnel, and AWS PrivateLink connectivity methods along with IP whitelisting.
We can sign a Business Associate Agreement and handle PHI data for customers that need HIPAA-aligned processing.
Passwords must be 12 characters or longer. We support 2FA, SSO, and role-based access control with standard and custom rules.
Field-level encryption, hashing, masking, and removal functions are supported directly in transformation workflows.
We can complete vendor risk assessments and facilitate calls with our security teams upon request.
Support job logs are encrypted and automatically deleted after 30 days. Customer data is not stored in job logs.
Operational Security
Integrate.io follows industry best practices across hosting, access, monitoring, and review to ensure your data is safe and secure.
Integrate.io's infrastructure is hosted and managed within major cloud provider data centers. Data center operations are accredited under ISO 27001, SOC 1 and SOC 2/SSAE 16/ISAE 3402, PCI Level 1, FISMA Moderate, and Sarbanes-Oxley.
We use SSL/TLS encryption on all our websites and microservices to maintain the highest security and data protection standards. Sensitive data such as connection credentials are encrypted in the Integrate.io platform using industry-standard encryption.
Firewalls restrict access from external networks and between internal systems. Default access is denied, and only explicitly allowed ports and protocols are accepted based on business requirements.
Operating system access is limited to Integrate.io staff and requires username and key authentication. Password authentication is disabled to reduce brute force, theft, and sharing risk.
Integrate.io does not store paid-account credit card information on its servers. Stripe is used as the third-party credit card and payment processor.
We encourage responsible disclosure of security vulnerabilities and value the work of security researchers in helping keep our business and customers safe.