Trust & security

Everything we send, you can check.

Intakra works from public sources and links every heads-up to where it came from. We hold your data to the same standard.

Public sources only

Intakra reads public sources about companies: job posts, SEC filings, federal contract awards, layoff notices (WARN filings), company web pages, and public DNS and certificate records (the technical records that show when a company sets up a new website or app). We never track your prospects: no cookies on your buyers, no website visitor identification, no contact data. We do collect standard product analytics and error telemetry (PostHog, Sentry) to improve Intakra, per the privacy policy.

Every heads-up comes with its sources

Each thing we find carries the date it happened, the date Intakra first saw it, and a link to the public source. We keep a copy of the page, so you can always see what the source said that day.

Nothing sent on your behalf

Intakra does not write or send email to your prospects. It emails you (and optionally Slack) when a company on your list starts something relevant, and pushes the ones you choose to your CRM. What happens next is up to you.

Separate workspaces

Every customer has their own workspace, and every read is limited to it. What we find in public sources about a company can be shared across customers, but your account list, what you sell, and what you push to your CRM or mark “Not relevant” are never visible to anyone else.

How your data is handled

What we collect

Your account and workspace details, what you tell us you sell, the accounts on your list, what you push to your CRM, mark “Not relevant”, or snooze, and any data you connect (for example, CRM records you import). We don’t buy or use website visitor identification, contact data, or shared topic-intent data.

How the LLM sees it

Model calls go through OpenRouter. Text from public sources is sent to group related findings into one project, and your description of what you sell is sent to check whether that project fits you. We don’t use your data to train models.

Access, control & deletion

CRM connections use OAuth with limited scopes, and you can revoke them from Settings at any time. You can request an export or deletion of your workspace. Payment card data is handled by Stripe and never stored by Intakra.

Subprocessors

The core services Intakra relies on to operate, by role:

Cloud hosting & databaseCloudflare (application and snapshot storage), Neon (Postgres database)
LLM processingOpenRouter, through Cloudflare AI Gateway (groups what we find in public sources into projects and checks whether each one fits what you sell)
Email deliveryResend (sign-in codes, heads-up emails and account email)
CRM connectionsComposio (holds OAuth tokens for the CRMs you connect)
PaymentsStripe (subscription billing; card data never touches Intakra servers)
Product analytics & errorsPostHog (product analytics), Sentry (error monitoring)

Security review & DPA

Enterprise conversations can include a security review and a Data Processing Agreement. If your procurement team needs to run diligence before you buy, we’ll meet you there.

Questions about security or data handling? Email hello@intakra.com and we’ll get you what you need. See also our Privacy and Terms.