Trust & security
Trust is built into the system, not added around it.
A plain account of how The Intent Ledger handles project data, recordings, access and payments — including what we've verified and what we're still validating.
Last reviewed: October 2026
Overview
How we protect project information
The Intent Ledger holds a design team's working memory: decisions, risks, open questions, and the recordings behind them. That is sensitive by nature, so the protections described here are part of how the system is built, not something added around it.
This page describes what we have configured and what we have verified. Where a protection is verified, we say what it is. Where work is still being completed, we say that too. It does not restate the security commitments of our infrastructure providers, which each provider publishes itself.
Access
Data access & isolation
Sign-in
Accounts use email and password sign-in through Supabase Authentication. A password-reset request receives the same response whether or not an account exists for that address, so the form cannot be used to find out who has an account.
Database access
Core customer-data tables use database-level row-level security to scope access to the appropriate account. It is one layer among several: reaching your account also requires signing in, and plan and usage limits are enforced on the server.
Recordings
Uploaded audio is stored in a private bucket. Storage policies limit access to the account that uploaded it, and the application checks project and session ownership before it authorises an upload.
Payments
Card details are entered on Stripe's hosted payment pages. The Intent Ledger does not receive or store your full card number; we keep only the billing references and subscription status needed to run your account.
Tested against production
In September 2026 we tested cross-account access directly against production using two test accounts. Neither could read the other's project or session recording, and unauthenticated requests could read neither. This was a point-in-time test of those two boundaries. It is not a claim that every access path has been tested.
Infrastructure
Infrastructure & storage
We build on a small number of established providers, each with a defined role.
Supabase
Database, authentication, and private storage for uploaded audio.
Vercel
Application hosting and delivery.
Stripe
Checkout, subscription billing, and payment processing.
OpenAI
Transcription and structured analysis of material you choose to submit.
Cloudflare
Separate storage used by our independent session-recording backup infrastructure.
Some providers may process or store information outside Australia. The Privacy Policy describes how.
Recovery
Backups & recovery
Project memory and session recordings are stored in different places, so they are backed up in different ways.
Verified
- Project-memory database: automated daily backups, provided by Supabase.
- Session recordings are stored separately from the database.
- An independent backup path for session recordings has been built.
- Its infrastructure, access controls and safe orchestration have been production-tested using synthetic data: a test object was written, integrity-checked and deleted, and a full dry run completed without changing anything.
- A dry run in our hosted automation environment, using real production configuration, passed.
Still being completed
- Copying real session recordings through the backup path.
- End-to-end restore validation.
- Live scheduling. The backup path is not yet running on an ongoing schedule.
We would rather describe this exactly than round it up. We will update this section as real-recording backup and restore validation are completed.
Open work
What we're still improving
Two things we are still completing, stated plainly.
Restore validation
We have verified the backup infrastructure and safe orchestration, but real-recording copy and end-to-end restore validation are still being completed before live scheduling is enabled.
CSP enforcement
The application currently sends a Content Security Policy (CSP) in report-only mode, which flags would-be violations in the browser without blocking anything. Enforcement is a separate hardening step.
AI
AI & project content
AI processing happens as part of features you explicitly invoke.
Audio is sent for transcription only when you choose to transcribe it, and a transcript or set of notes is sent for analysis only when you choose to run an analysis. Neither is triggered by uploading or pasting content alone. The other analysis tools in the product work the same way: they run when you start them.
Your action is what starts the processing. Once started, it can continue until it completes; that is part of the feature you invoked, not a separate use of your content.
We do not use your uploaded project content to train proprietary models. Our AI and transcription provider is OpenAI. What its own systems retain after a request is governed by its terms, and we do not claim that it retains nothing.
AI-generated output can contain mistakes. ILM Records keep references to the source material they came from, so findings can be checked rather than taken on trust.
Operations
Operational safeguards
- Server-side credentials and privileged keys are kept out of client-side code. A few identifiers, such as the public project address and public client key for our database, are deliberately visible to the browser. They do not grant privileged access on their own; the database's own access rules decide what they can reach.
- Billing operations are restricted to narrowly scoped database functions rather than broad table access.
- All traffic between your browser and The Intent Ledger uses HTTPS.
- Our pages carry standard browser protections: they cannot be embedded in other sites, content-type guessing is disabled, and browser features the product does not use are switched off.
- Deleting a project removes its uploaded audio and cascades to its sessions and ILM Records. Backups and provider systems may retain data for a limited time afterwards; the Privacy Policy explains how retention and deletion work.
Disclosure
Security questions & responsible disclosure
If you believe you've found a security issue, contact us at support@theintentledger.com with a clear description of the issue and steps to reproduce it. Please don't include real client data, passwords or payment details in your report.
Documents