Security & trust

How we protect, isolate, and retain your data.

This page tells you where your data is stored, who can access it, how it is encrypted, and when it is deleted. If you need more detail, request the procurement pack below.

What we read

The documents you upload (SOWs, proposals, invoices) and the program data you connect (for example, Microsoft Partner Center or your Pax8 account). We read them to compute eligibility, deadlines and claim evidence. We do not read data outside the scope you grant.

What we store

Your eligibility results, claim records and the evidence attached to them. We keep this data while your account is active. You can export it at any time. We delete it within 30 days of account closure, or sooner on request.

What we never do

We do not sell your data. We do not share it with vendors or distributors unless you turn that sharing on. We do not publish aggregate data that identifies you.

// The specifics

Where your data lives

  • Hosted entirely on Microsoft Azure — no third-party clouds.
  • Stored in a single, defined region. The standard hosting region is West US.
  • EU, AU and other in-region deployments are available for regulated customers.

Who can access it

  • Access is least-privilege, enforced down to the database credential. The customer application's database login cannot read staff or administrative tables.
  • Internal administration is a separate application with its own credentials. There is no global-admin backdoor in the customer app.
  • Staff sign in with Microsoft Entra ID (SSO). Staff have no standing admin access. Emergency access is just-in-time, MFA-gated, and logged.

Encryption

  • In transit: TLS 1.2+ across all connections.
  • At rest: AES-256 on database, file storage, and backups.
  • Integration credentials (OAuth tokens, API secrets) are stored encrypted and deleted on disconnect.

AI & your data

  • Document analysis uses Azure OpenAI, hosted entirely within Azure.
  • Your prompts and content are never used to train any model.
  • Azure holds AI processing data for up to 30 days, for abuse monitoring only.

Integrations

  • Every integration is optional and read-only. We do not write into a connected system.
  • Your workspace makes each connection with your own credentials (for example, Partner Center OAuth or your Pax8 API keys).
  • You can disconnect at any time. We then delete the stored credentials.

Distributor sharing

  • You control what a connected distributor sees, from your own settings, scope by scope.
  • Earnings, payouts, and referral line items are never shared with distributor workspaces.
  • You can disconnect at any time. The distributor keeps only the data they entered themselves.

// Retention & deletion

This table shows how long we keep each category of data, and what happens at end of life. We keep data for the term of your agreement and remove it on a defined schedule after offboarding.

Uploaded documents

SOWs, agreements, source files

Term of agreement

Deleted within 30 days of contract end, or sooner on request.

Analysis results

Opportunities, uplift, readiness reports

Term of agreement

Deleted within 30 days of contract end. You can delete individual analyses at any time.

Account & organisation data

Users, contacts, connections

Term of agreement

Deleted within 30 days of contract end, after any requested export.

Audit & security logs

35 days rolling

Removed automatically. Logs are kept through the deletion window as evidence of the deletion.

Backups

35 days rolling

Deletions propagate as backups age out. All copies are gone within 35 days of the primary deletion.

AI processing data

Prompts & responses

Up to 30 days

Held by Azure OpenAI for abuse monitoring only. Not used to train models.

// Continuity, compliance & your rights

Backups & availability

  • Zone-redundant high availability on the database.
  • Daily backups, with restore to a specific day. Recovery targets: RPO 24 hours, RTO 4 hours.
  • File storage has soft-delete enabled to protect against accidental loss.

Compliance

  • Built on Azure services covered by Microsoft's ISO 27001 and SOC 2 platform certifications.
  • Our own SOC 2 audit is not complete. We target completion by the end of FY27.
  • Until then, we supply this page, the data governance brief, and a completed security questionnaire on request.

Sub-processors

  • Microsoft Azure — hosting, database, storage, AI (Azure OpenAI).
  • Resend — transactional email delivery.
  • PostHog — product analytics, hosted in the EU region, GDPR compliant.

Your data rights

  • You own everything you upload. We process it only to deliver the service.
  • You can export a copy of your organisation's data at any time, including at contract end.
  • You can request deletion. We complete it within 30 days. Questions: privacy@incentrix.io.

Security questions: security@incentrix.io

Procurement pack

The pack contains the security summary, a data-processing agreement template, the sub-processor list, and insurance certificates — in one download.

Request the pack

Privacy

We collect only the data you give us, and we use it to produce estimates and claims. We do not sell it. You can export or delete it. Read the privacy policy.

Terms

Plans are annual subscriptions, billed monthly. Optional service engagements are agreed in writing before work starts. The full legal documents come with your onboarding pack. Read the terms.

See what you're owed.

Run an estimate on your own documents. Each result cites its program document. Your data stays yours.