Trust Center

Security, Privacy, and Compliance at ICM Desk

A detailed look at how ICM Desk protects your data — written for the compliance teams who need to know exactly how it works before they sign.

TLS
In transit
At rest
Storage layer
RLS
Tenant isolation
Aligned
SOC 2 & ISO 27001

Data Handling

How Your Data Flows

Requests never go straight from a browser to an AI provider. They pass through ICM Desk’s own secure gateway, so we control and can audit the path.

Encryption

All data is encrypted in transit with TLS. Stored data is encrypted at rest at the storage/platform layer of our cloud providers.

Tenant Isolation

Row-level security enforces that each organization can only ever reach its own data. There is no shared, co-mingled view across customers.

Access Control & Logging

Access is governed by role-based permissions with multi-factor authentication. Authentication and administrative activity is logged.

Gateway Observability

AI requests route through our gateway, which retains usage logs inside our own infrastructure, under our controls and our agreement with you. This retention is configurable for firms with specific requirements.

Sub-Processors

The Vendors Behind ICM Desk

ICM Desk relies on a small set of established providers to deliver the service. Each processes data only as needed to perform its function, under contract.

ProviderPurposeLocation
SupabaseApplication database, authentication, and storageUnited States
CloudflareHosting, content delivery, and AI request gatewayGlobal edge network
AnthropicAI model provider (Claude) for document assistanceUnited States
OpenAIAI model provider (GPT) for document assistanceUnited States
ResendTransactional email deliveryUnited States
StripePayment processing for AI Credit purchasesUnited States

Standards Alignment

Built to Recognized Frameworks

ICM Desk is designed and operated with the SOC 2 Type II and ISO 27001 frameworks in mind. These describe how we build; they are not a claim of certification.

SOC 2 & ISO 27001 Aligned

Our architecture, access controls, and data-handling practices are built to align with the principles of SOC 2 Type II and ISO 27001. We do not currently hold certification under either.

GDPR & LGPD Roles

In data-protection terms, your firm is the controller, ICM Desk is the processor, and our AI and infrastructure providers are sub-processors bound by contract.

Your Confidentiality Duty

Professional confidentiality remains your obligation to your clients. ICM Desk provides the technical and contractual safeguards that support you in meeting it.

AI Confidentiality

How AI Handles Your Data

ICM Desk’s AI features run on the commercial APIs of Anthropic and OpenAI — not the consumer chat apps — which changes how data is treated.

Never Used for Training

Under the commercial API terms, neither Anthropic nor OpenAI uses your inputs or outputs to train their models. This is contractual, not a setting.

Isolated and Encrypted

Requests are processed in isolation and encrypted in transit and at rest. Your data is never exposed to other customers or made public.

Minimal Provider Retention

By default, providers retain data only briefly (typically up to ~30 days) for abuse monitoring, then delete it — the same posture as Azure, Google Cloud, and AWS.

Zero Data Retention on Request

For engagements that require it, we can pursue a Zero Data Retention agreement with our AI providers, subject to their approval. Raise it early so it can be arranged.

Availability & Support

Kept available, and backed up

How we keep the platform available, protect your data against loss, and support your team.

Automated Backups

Your data lives in a managed database that our infrastructure providers back up automatically, so the platform can be restored in the event of a failure. You do not have to manage your own backups.

Platform Availability

ICM Desk runs on established cloud infrastructure (Supabase and Cloudflare), and we use commercially reasonable efforts to keep it available. Where a specific availability commitment applies to your account, it is set out in your Platform Service Agreement.

Support

Reach our team at support@icmdesk.com for help with the platform. Any applicable service levels are governed by your Platform Service Agreement.

Get in Touch

Questions About Security or Privacy?

We’re happy to walk your compliance team through how ICM Desk handles data — and to put a Data Processing Agreement in place if your firm needs one.