SOC2C

Is this your company? Buyers are checking intercom Inc here. Claim intercom.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
intercom Inc logo

intercom Inc

intercom.com· 51–200 employees· Security contact
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

intercom Inc is SOC 2 Type II compliant. intercom Inc also holds ISO 27001, ISO 27018, ISO 27701, ISO 42001, GDPR, CCPA, HIPAA, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Fin upholds the highest standards for safety and security, including enterprise-grade testing and controls, internationally recognized compliance accreditations, and advanced protections for Fin AI Agent against LLM threats.

Compliance & infrastructure

SOC 2 Type IIISO 27001ISO 27018ISO 27701ISO 42001GDPRCCPAHIPAACSA STAR
Hosting
AWSAzure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

14
  • A
    Amazon Web Services, Inc. · Hosting, storage and processing (including AI processing) of Customer Data
    USA or EU dependent upon customer's selected region
  • O
    OpenAI, L.L.C. · AI processing
    USA or EU dependent upon customer's selected region
  • M
    Mailgun Technologies, LLC · Email delivery services for individual emails and bulk email campaigns initiated
    USA
  • M
    Message Systems, Inc. (d/b/a Sparkpost) · Email delivery services for individual emails and bulk email campaigns initiated
    USA
  • S
    Snowflake Inc. · Data warehouse services and processing (including AI processing)
    USA or EU dependent upon customer's selected region
  • P
    PlanetScale Inc. · Database storage and caching
    USA or EU dependent upon customer's selected region
  • T
    Twilio, Inc. · SMS and Phone functionality
    USA
  • C
    Cloudflare, Inc. · Provides Transport Layer Security (“TLS”) protection for customers using a custo
    USA
  • M
    Microsoft Corporation (EU) · AI processing
    USA or EU dependent upon customer's selected region
  • A
    Anthropic, PBC · Provides large language model processing via APIs for customers using Intercom’s
    USA
  • G
    Google · Provides AI processing
    USA or EU dependent upon customer's selected region
  • E
    Eleven Labs, Inc. · AI Processing (text to speech)
    USA or EU dependent upon customer's selected region
Show all 14 subprocessors
  • A
    Ably · Message delivery service
    USA, EU or Australia dependent upon customers selected region
  • C
    Cartesia AI, Inc. · AI processing (text to speech)
    USA or EU dependent upon customer's selected region

Compliance leadership

The person who leads intercom Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. intercom Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

🚀 Intercom achieves AIUC-1 certification: A new standard for trust in AI AgentsDec 2025

Intercom is now among the first companies certified under AIUC-1, the new global benchmark for responsible AI. This certification isn’t compliance for compliance’s sake. It gives every business using Intercom confidence that our AI is safe, resilient, and built to the highest level of accountability. Achieving it required independent, enterprise-grade testing of our AI systems, ensuring safety, reliability, and strong protections against issues like hallucinations and brand risk. It confirms that Intercom’s long-standing commitment to trust fully extends to Fin. And it gives every business using Intercom confidence that our AI won’t make unsafe choices, leak data, or behave unpredictably. 🔗 Read the full blog post on our AIUC-1 certification and what it means for Intercom customers here or check out our AIUC-1 certification report in the Trust Center here.

🚨 Malicious phishing targeting Intercom customersOct 2025

We’ve identified phishing campaigns impersonating Intercom, targeting customers’ support addresses. ⚠️ Intercom has not sent any emails about MFA-related incidents. Be alert for lookalike domains such as send\[.\]intercorn\[.\]com. Attackers are using legitimate email-sending services, which can allow these messages to reach inboxes. If you receive an unexpected email that appears to come from Intercom: - ✅ Check the sending domain — never trust a display name. - ⏳ Be cautious of urgency — phishing relies on pressure and fear. - 💬 Confirm via another channel — you can always reach us through the Intercom Messenger. - 🛑 Pause if something feels off — even a brief moment of caution helps. 🔗 Learn more and see examples in our help article: Oct 2025: Malicious phishing targeting Intercom customers

A new, secure way to authenticate Messenger users — with JWTsJul 2025

We’ve introduced a new way to authenticate users in the Messenger, using JSON Web Tokens (JWTs). With JWTs, you benefit from: - ✅ Data protection — Sign and protect both user ID and email, along with any other user attributes. - ✅ Short-lived tokens — JWTs can be set to expire, reducing the risk of misuse for compromised tokens. If your Messenger is in an insecure state, there's no better time to secure things. An insecure Messenger puts your workspace at risk of unauthorised access, cross-user impersonation, data spoofing and more. Learn more about how to secure your Messenger on our help centre. This update replaces the previous Identity Verification (IdV) method with features designed to protect user data. If you’re using Identity Verification, migrate to JWTs to benefit from these improvements. Identity Verification will continue to work, but is considered deprecated and will not receive future updates. You’ll find the new JWT configuration in the Security tab within your Messenger settings.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is intercom Inc SOC 2 compliant?
intercom Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is intercom Inc ISO 27001 certified?
According to intercom Inc's public trust center, intercom Inc is ISO 27001 certified. On SOC2C this listing is Listed.
Is intercom Inc ISO 27018 certified?
According to intercom Inc's public trust center, intercom Inc is ISO 27018 certified. On SOC2C this listing is Listed.
Is intercom Inc ISO 27701 certified?
According to intercom Inc's public trust center, intercom Inc is ISO 27701 certified. On SOC2C this listing is Listed.
Is intercom Inc ISO 42001 certified?
According to intercom Inc's public trust center, intercom Inc is ISO 42001 certified. On SOC2C this listing is Listed.

Business & Industrial peers that completed SOC 2