Trust Center
Last updated: August 1, 2026
Single-page summary of every regulatory framework, security control, and compliance status that applies to Intelloro.
Privacy
Multi-jurisdiction policy stack: GDPR + UK GDPR + CCPA + 6 US state laws + PIPEDA + Quebec Law 25 + LGPD + PDPO. Children-specific frameworks (UK Children's Code, CA AADC, GDPR Art. 8, Brazil ECA Digital) in progress — will activate when age-detection is deployed.
Platform Regulation
EU Digital Services Act (Art. 15-21 documented; Art. 30 vendor verification in progress), EU AI Act (limited-risk classification + Art. 4 + 50 disclosure), DMCA, CAN-SPAM — documented and live.
Security
TLS encryption in transit (Vercel) + encryption at rest (MongoDB Atlas) + restricted admin access. SOC 2 + ISO 27001 in progress.
Compliance Matrix
Status Legend
- Compliant — Framework is fully implemented and documented; user-facing rights are active.
- In Progress — Implementation is underway; baseline obligations are met but full conformance is being completed.
- Self-Declared — Internal controls aligned with the framework; no external audit completed yet.
- Partial — Some elements implemented; gaps identified and prioritized for remediation.
- Not Applicable — Framework does not apply to Intelloro's current operations.
These statuses reflect Intelloro's own self-assessment, not a government certification. Data-protection regulations such as GDPR, CCPA, LGPD and PDPO have no official certification scheme — a “Self-Declared” row means we have implemented the framework's requirements ourselves and have not undergone an independent third-party audit. Rows naming a specific external certification (SOC 2, ISO 27001) show their true audit status, and encryption rows describe a factual technical control provided by our infrastructure vendors.
Quick Links
Need More Detail?
Enterprise customers, security teams, and regulators may request the underlying documents (Transfer Impact Assessment, Privacy Impact Assessments, DPA templates, security questionnaire responses) by emailing info@intelloro.com with the subject “Trust Center Request”.
Response SLA: 5 business days for security questionnaires; 30 days for DSAR / data export.