Trust & security

Built to be verifiable, not just trusted.

Intakra’s premise is reviewable timing: it works from public and licensed business signals and shows available source links. That principle shapes how we handle your data too, the same page you’d want to send is the standard we hold ourselves to.

Provider inventory updated July 21, 2026.

Verifiable business signals

Intakra reads public sources and licensed business-data services for funding, hiring, executive moves, M&A, launches, and related events. We do not place cookies on your prospects, de-anonymize your website visitors, or buy co-op topic-intent data. Available source links are shown so you can inspect the underlying evidence.

Review before use

Signals and generated material may be incomplete or wrong. Intakra shows a source link when the record contains one and presents generated pages for human review before external use.

Your own sending domain

Customer outbound sends only from your DKIM-verified domain, never a shared pool. Current sequenced email includes sender identification, a postal address, an unsubscribe method, and no open or click tracking pixel.

Workspace isolation

Every customer lives in a separate workspace. The application data model and primary customer-data queries are workspace-scoped and designed to prevent one customer from viewing another customer's accounts, signals, or contacts.

Analytics by choice

Meta Pixel has been removed. Optional PostHog browser analytics stay off until a visitor affirmatively allows them, and Global Privacy Control or Do Not Track keeps them disabled. Sentry is limited to service reliability and has session replay disabled in the current configuration.

How your data is handled

What we collect

Your account and workspace details, the market/ICP you define, the accounts you track and their public or licensed signals, professional contacts, generated assessments, and data you connect, such as CRM records. We do not buy or use anonymous website de-anonymization or co-op topic-intent data.

How the LLM sees it

Page and outreach drafting, signal evaluation, grounded research, and reply classification route through OpenRouter to the model tier used for that feature. Only the prompt context needed for that request is sent, which can include public signal text, customer instructions, account context, a draft, or a reply. Routed providers handle that context under their applicable service terms, settings, and privacy commitments.

Access, control & deletion

Connected services receive only the scopes and records used for the selected feature. Contact us about a connection or to request an available data copy or deletion. Payment card data is handled by Stripe and never stored by Intakra.

Browser analytics

Necessary authentication and security storage is always available. Optional PostHog browser analytics starts only after an affirmative choice and can be changed from Analytics choices in the footer. Declining does not disable any core product feature.

Processing providers

These providers may process customer personal data only when needed for the listed feature. Optional means the integration or configuration may be off. Processor terms are not currently offered; see the release-status page before submitting data that requires them.

VercelApplication hosting, delivery, and abuse protection. Application requests, account and workspace data, and technical logs.Core
NeonManaged Postgres database. Account, workspace, target-account, signal, integration, and outreach records.Core
OpenRouter, Anthropic, and PerplexityAI inference and grounded web research. Prompts containing the account context, public signal text, customer instructions, and feature-specific content needed for a generation.Core
AgentMail and its AWS SES infrastructureCustomer-directed outbound email and inbound reply handling. Sender and recipient business contact details, message content, delivery data, and replies.Feature-dependent
ResendAuthentication and house-originated operational or marketing email. Recipient email address, message content, delivery metadata, and suppression-related identifiers.Core
Trigger.devBackground jobs and scheduled processing. Workspace and record identifiers plus the feature data required by each job.Core
SentryError monitoring and service reliability. Error details, request context, device and browser data, and technical identifiers.Optional
PostHogProduct analytics. Consented browser events and limited service events associated with a user or workspace identifier.Optional
LangfuseOptional AI request observability. Feature purpose, model, cost, and workspace or onboarding-step identifiers; prompt content is not included in the current trace payload.Optional
Cloudflare, including R2 when enabledDNS, email routing, security, and optional object storage. Domain and routing data, network request data, and files stored by an enabled feature.Feature-dependent
ComposioCustomer-enabled CRM authorization and actions. OAuth connection data and the CRM records a customer chooses to import or push.Feature-dependent
SvixWebhook signing and delivery when enabled. Webhook payloads and delivery metadata.Optional

Business-data sources

These services supply or verify company and professional information. A source may act as an independent controller under its own notice rather than as Intakra’s subprocessor.

ApolloCompany, professional contact, and business-email enrichment. Company domains, business profiles, professional contact details, and provider identifiers.Core
TheirStackCompany and job-posting signals. Company domains, job postings, and related business metadata.Core
BuiltWithCompany technology-stack signals. Company domains and detected technology metadata.Core
ExaPublic-web search and research. Company names, domains, search queries, and public-web results.Core
Abstract APIBusiness-email verification. Business email addresses submitted for verification.Feature-dependent
Lusha, Crunchbase, and IndeedOptional company, professional, funding, and job data. Company and professional lookup inputs and returned business records.Optional

Customer-enabled and billing services

These services receive data only when a customer uses the relevant sign-in, billing, CRM, or alerting feature.

StripeSubscription billing and payment processing. Billing contact, plan, payment status, and transaction identifiers; Intakra does not receive full card details.Feature-dependent
Google and Soxoa AccountsOptional account sign-in. Identity, email address, authentication tokens, and authorized profile fields.Feature-dependent
HubSpot and SalesforceCustomer-enabled CRM import and push. Authorization data and selected company or account records with supported score metadata.Feature-dependent
SlackCustomer-configured incoming-webhook alerts. Webhook destination, supported workspace alert content, and delivery metadata.Feature-dependent

Processor terms are release-gated

Intakra has not yet completed the provider-contract and transfer verification required to offer processor or service-provider terms. Do not submit personal data that requires those terms. Contact us before that use and review the current release-status page.

Questions about security or data handling? Email [email protected] and we’ll get you what you need. See also our Privacy and Terms.