Trust

Data Security

Last updated: 16 August 2026

This page describes the current security approach for the Intelplexis public website, case form and related research correspondence. It is not a certification, audit report or guarantee that every security event can be prevented.

Current scope

Intelplexis is pre-launch. The public website has no user account, customer database, production integration or live operational-processing environment. The current form is intended only to start a conversation about public, historical, reconstructed or sandbox cases.

Data minimisation first

The primary safeguard is to avoid collecting sensitive operational data in the first place. A useful first contact normally needs only a public provider source, a material implementation or testing question, and enough professional contact information to reply.

Do not send

  • passwords, API keys, tokens or other credentials;
  • non-public architecture, configuration, source code or vulnerability details;
  • raw production logs, evidence files or customer records;
  • client, employee or end-user information not necessary for the enquiry;
  • special-category personal data, criminal-offence data or regulated secrets; or
  • information subject to a confidentiality duty that has not been cleared for disclosure.

If a later discussion requires a different channel or written confidentiality arrangement, that must be agreed before the information is sent.

Current safeguards

  • the public site is static and exposes no product login or production customer environment;
  • access to form submissions, aggregate analytics dashboards and correspondence is restricted to the founder and necessary service providers;
  • the production website uses provider-managed HTTPS to protect traffic in transit when accessed through intelplexis.com;
  • the form uses provider-managed delivery and anti-abuse controls;
  • campaign attribution is limited to an allow-list of non-secret URL labels and is not stored in cookies, local storage or session storage;
  • administrative access is kept separate from public access and uses the protections available from the relevant account provider; and
  • retention and deletion are limited as described in the Privacy Notice.

Service providers

Website hosting, form delivery and email necessarily involve external providers. Those providers operate their own infrastructure and security controls. Intelplexis selects and configures services proportionately to the limited pre-launch processing and reviews the arrangement when the scope or risk changes.

Security incidents

A suspected incident will be assessed for confidentiality, integrity and availability impact. Appropriate steps may include containment, credential or access review, preservation of relevant evidence, provider escalation, risk assessment, remediation and documentation. Where a personal-data breach triggers a legal notification duty, the competent authority and affected people will be informed as required by applicable law.

Report a concern

To report a suspected website or data-security issue, email contact@intelplexis.com with the subject “Security report”. Include a concise description and a safe way to reproduce the issue. Do not include secrets, exploit code, personal data or confidential customer information in the first message. Intelplexis does not currently operate a public bug-bounty programme.

Limits and review

No internet transmission or storage method is perfectly secure. The safeguards described here are proportionate to the current public website and limited research workflow; they must be reassessed before any production product, customer data, user accounts or operational integration is introduced.