Is this your company? Buyers are checking intercom Inc here. Claim intercom.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
intercom Inc
Sourced from public information. Not yet verified by the company.
intercom Inc is SOC 2 Type II compliant. intercom Inc also holds ISO 27001, ISO 27018, ISO 27701, ISO 42001, GDPR, CCPA, HIPAA, and CSA STAR.
About
Fin upholds the highest standards for safety and security, including enterprise-grade testing and controls, internationally recognized compliance accreditations, and advanced protections for Fin AI Agent against LLM threats.
Compliance & infrastructure
Subprocessors
14- AAmazon Web Services, Inc. · Hosting, storage and processing (including AI processing) of Customer DataUSA or EU dependent upon customer's selected region
- OOpenAI, L.L.C. · AI processingUSA or EU dependent upon customer's selected region
- MMailgun Technologies, LLC · Email delivery services for individual emails and bulk email campaigns initiatedUSA
- MMessage Systems, Inc. (d/b/a Sparkpost) · Email delivery services for individual emails and bulk email campaigns initiatedUSA
- SSnowflake Inc. · Data warehouse services and processing (including AI processing)USA or EU dependent upon customer's selected region
- PPlanetScale Inc. · Database storage and cachingUSA or EU dependent upon customer's selected region
- TTwilio, Inc. · SMS and Phone functionalityUSA
- CCloudflare, Inc. · Provides Transport Layer Security (“TLS”) protection for customers using a custoUSA
- MMicrosoft Corporation (EU) · AI processingUSA or EU dependent upon customer's selected region
- AAnthropic, PBC · Provides large language model processing via APIs for customers using Intercom’sUSA
- GGoogle · Provides AI processingUSA or EU dependent upon customer's selected region
- EEleven Labs, Inc. · AI Processing (text to speech)USA or EU dependent upon customer's selected region
Show all 14 subprocessorsShow fewer
- AAbly · Message delivery serviceUSA, EU or Australia dependent upon customers selected region
- CCartesia AI, Inc. · AI processing (text to speech)USA or EU dependent upon customer's selected region
Compliance leadership
The person who leads intercom Inc's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. intercom Inc's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
🚀 Intercom achieves AIUC-1 certification: A new standard for trust in AI AgentsDec 2025
Intercom is now among the first companies certified under AIUC-1, the new global benchmark for responsible AI. This certification isn’t compliance for compliance’s sake. It gives every business using Intercom confidence that our AI is safe, resilient, and built to the highest level of accountability. Achieving it required independent, enterprise-grade testing of our AI systems, ensuring safety, reliability, and strong protections against issues like hallucinations and brand risk. It confirms that Intercom’s long-standing commitment to trust fully extends to Fin. And it gives every business using Intercom confidence that our AI won’t make unsafe choices, leak data, or behave unpredictably. 🔗 Read the full blog post on our AIUC-1 certification and what it means for Intercom customers here or check out our AIUC-1 certification report in the Trust Center here.
🚨 Malicious phishing targeting Intercom customersOct 2025
We’ve identified phishing campaigns impersonating Intercom, targeting customers’ support addresses. ⚠️ Intercom has not sent any emails about MFA-related incidents. Be alert for lookalike domains such as send\[.\]intercorn\[.\]com. Attackers are using legitimate email-sending services, which can allow these messages to reach inboxes. If you receive an unexpected email that appears to come from Intercom: - ✅ Check the sending domain — never trust a display name. - ⏳ Be cautious of urgency — phishing relies on pressure and fear. - 💬 Confirm via another channel — you can always reach us through the Intercom Messenger. - 🛑 Pause if something feels off — even a brief moment of caution helps. 🔗 Learn more and see examples in our help article: Oct 2025: Malicious phishing targeting Intercom customers
A new, secure way to authenticate Messenger users — with JWTsJul 2025
We’ve introduced a new way to authenticate users in the Messenger, using JSON Web Tokens (JWTs). With JWTs, you benefit from: - ✅ Data protection — Sign and protect both user ID and email, along with any other user attributes. - ✅ Short-lived tokens — JWTs can be set to expire, reducing the risk of misuse for compromised tokens. If your Messenger is in an insecure state, there's no better time to secure things. An insecure Messenger puts your workspace at risk of unauthorised access, cross-user impersonation, data spoofing and more. Learn more about how to secure your Messenger on our help centre. This update replaces the previous Identity Verification (IdV) method with features designed to protect user data. If you’re using Identity Verification, migrate to JWTs to benefit from these improvements. Identity Verification will continue to work, but is considered deprecated and will not receive future updates. You’ll find the new JWT configuration in the Security tab within your Messenger settings.
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is intercom Inc SOC 2 compliant?
Is intercom Inc ISO 27001 certified?
Is intercom Inc ISO 27018 certified?
Is intercom Inc ISO 27701 certified?
Is intercom Inc ISO 42001 certified?
Is intercom Inc GDPR compliant?
Is intercom Inc CCPA compliant?
Is intercom Inc HIPAA compliant?
Is intercom Inc CSA STAR certified?
Is intercom Inc SOC 2 Type I or Type II?
Can I use intercom Inc's SOC 2 for a vendor risk assessment?
Is intercom Inc penetration tested?
Is intercom Inc secure?
Does intercom Inc have a bug bounty or vulnerability disclosure program?
Who are intercom Inc's subprocessors?
Where does intercom Inc host or store data?
Where is intercom Inc's trust center or security page?
Can you provide details related to AI Security?
How do I report a bug, concern or adverse impact?
How do I report a security vulnerability?
How do I contact your security team?
How can I find your recent incidents and uptime?
How do you process our data?
Who are your subprocessors?
Where are your servers located?
Can you provide additional details related to sub-processor per region?
How does Intercom handle cookies?
Are you a data processor or a data controller?
Does Intercom own our customer data?
Business & Industrial peers that completed SOC 2

Newsworthy.ai

Octopus Deploy

1099-Prep
