Security

Security at GetIntent

GetIntent is AI landing-page personalization for B2B SaaS, built and operated by Getia AS in Oslo, Norway. The application runs on Railway in the European Union, all traffic is served over HTTPS, and sensitive tokens are encrypted with AES-256-GCM. GetIntent is not SOC 2 or ISO 27001 certified. We answer security questionnaires on request.

At a glance

Hosting
Railway, European Union
In transit
HTTPS with HSTS (2-year max-age, preload)
Token encryption
AES-256-GCM for Google Ads tokens and 2FA secrets
Sign-in
Password, magic link, TOTP 2FA, SAML 2.0 SSO
Certifications
None. No SOC 2, no ISO 27001
Vulnerability reports
[email protected]

Data location

Application servers and the primary database are hosted by Railway in the European Union. Some subprocessors are located in the United States: Stripe (payments), Cloudflare (CDN, DNS and edge security) and Anthropic (AI text generation). Transactional email is sent through GetMailer in the EU. Transfers outside the EEA are covered by the safeguards described in our Data Processing Agreement.

See the full subprocessor list

Encryption

  • All pages, the API and the visitor script are served over HTTPS. Strict-Transport-Security is set with a two-year max-age, includeSubDomains and preload.
  • Google Ads OAuth refresh tokens are encrypted at the application level with AES-256-GCM before they are stored.
  • Two-factor authentication secrets are encrypted with AES-256-GCM. Backup codes are stored as bcrypt hashes.
  • Passwords are hashed with bcrypt (cost factor 12). API keys, magic-link tokens and email-verification tokens are stored as SHA-256 hashes, never in plain text.

Account access

  • Time-based one-time passwords (TOTP) for two-factor authentication, with ten single-use backup codes and attempt limits on the challenge step.
  • SAML 2.0 single sign-on, configured by an organization owner or admin, with a default role for new SSO users.
  • Role-based access: organization owners and admins, plus per-site editor and viewer roles.
  • API access uses per-organization API keys sent in the X-API-Key header. Keys can be created and revoked from the dashboard.

Logging and abuse protection

  • Security-relevant events (sign-in and sign-out, SSO sign-in, API key creation and revocation, member and role changes, SSO configuration, and site and organization changes) are written to an audit trail. Organization admins can review it under Settings → Audit log.
  • Rate limits protect authentication, two-factor verification and the personalization API.
  • Outbound requests to customer-supplied URLs (site crawling, page preview and proxying, CRM webhook URLs and Salesforce instance URLs) pass an SSRF guard that blocks private, loopback and link-local addresses and re-validates each redirect.
  • A Content-Security-Policy and standard security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy) are set on every response.

What the visitor script stores

  • The GetIntent pixel (/pixel.js) sets no cookies and assigns no visitor or session ID in the browser. It caches the site configuration, the personalized copy and the landing UTM parameters for the current tab in sessionStorage, and reads localStorage only to check whether your consent tool has recorded consent.
  • For A/B test assignment the server derives a short SHA-256 hash from the visitor's IP address and user agent. Visitor profiles hold a hashed visitor identifier, approximate location (country, region, city), device, browser, visit counts and the last UTM source and campaign. They do not hold names or email addresses.
  • IP addresses stored with personalization records are truncated (the last IPv4 octet is removed) before they are saved.
Read the visitor tracking docs

GDPR and your data

  • Getia AS acts as processor for visitor data on your sites and offers a Data Processing Agreement.
  • Account owners can export their data and delete their account, including related records, from the dashboard (GDPR Articles 15, 17 and 20).
  • The DPA commits us to notify you of a personal data breach without undue delay and within 72 hours, and to delete or return personal data when the service ends.

Data retention

  • There is no automatic deletion of visitor data yet. Personalization records, pageview records, visitor profiles and analytics events are kept for as long as the organization's account exists.
  • Deleting your user account (Settings → Account) removes your user record and the records tied to it. Organization, site and visitor data is not removed by that step; email [email protected] to have an organization's data deleted.
  • When the service ends, the DPA commits us to delete or return personal data.
  • Sign-ups whose verification email bounced and who never logged in are flagged after 7 days, deactivated 14 days after flagging and deleted 30 days after flagging.

Certifications and questionnaires

GetIntent is not SOC 2 or ISO 27001 certified, and we do not claim to be. If your procurement process needs a security questionnaire answered, email [email protected] or use the contact page and we will complete it.

Reporting a vulnerability

Send vulnerability reports to [email protected]. Our security.txt file is published at /.well-known/security.txt. Service status is available on our status page.

Status page

Security FAQ

Where is GetIntent data hosted?

In the European Union. Application servers and the database run on Railway in the EU. Payments (Stripe), CDN and DNS (Cloudflare) and AI text generation (Anthropic) are US-based subprocessors listed on our subprocessors page.

Is GetIntent SOC 2 or ISO 27001 certified?

No. GetIntent holds neither certification. We will answer your security questionnaire on request at [email protected].

Does the GetIntent script set cookies?

No. The pixel sets no cookies and stores no visitor ID in the browser. It uses sessionStorage to cache configuration, personalized copy and landing UTM parameters for the current tab, and reads localStorage only to detect consent stored by your consent tool. For A/B test assignment, the server derives a hash from the visitor's IP address and user agent.

How long do you keep visitor data?

There is no automatic retention limit yet: visitor and analytics data is kept while the organization's account exists, and is deleted on request or returned/deleted under the DPA when the service ends. Email [email protected] to have an organization's data deleted.

Does GetIntent support single sign-on?

Yes. Organization owners and admins can configure SAML 2.0 single sign-on with their identity provider and choose the default role for new SSO users.

Do you sign a DPA?

Yes. Our Data Processing Agreement is published on the DPA page and covers breach notification within 72 hours, subprocessors and international transfers.

How do I report a security issue?

Email [email protected]. The address is also published in our security.txt file.