Trust Center
Security, Privacy, and Compliance at ICM Desk
A detailed look at how ICM Desk protects your data — written for the compliance teams who need to know exactly how it works before they sign.
Data Handling
How Your Data Flows
Requests never go straight from a browser to an AI provider. They pass through ICM Desk’s own secure gateway, so we control and can audit the path.
Encryption
All data is encrypted in transit with TLS. Stored data is encrypted at rest at the storage/platform layer of our cloud providers.
Tenant Isolation
Row-level security enforces that each organization can only ever reach its own data. There is no shared, co-mingled view across customers.
Access Control & Logging
Access is governed by role-based permissions with multi-factor authentication. Authentication and administrative activity is logged.
Gateway Observability
AI requests route through our gateway, which retains usage logs inside our own infrastructure, under our controls and our agreement with you. This retention is configurable for firms with specific requirements.
Sub-Processors
The Vendors Behind ICM Desk
ICM Desk relies on a small set of established providers to deliver the service. Each processes data only as needed to perform its function, under contract.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Application database, authentication, and storage | United States |
| Cloudflare | Hosting, content delivery, and AI request gateway | Global edge network |
| Anthropic | AI model provider (Claude) for document assistance | United States |
| OpenAI | AI model provider (GPT) for document assistance | United States |
| Resend | Transactional email delivery | United States |
| Stripe | Payment processing for AI Credit purchases | United States |
Standards Alignment
Built to Recognized Frameworks
ICM Desk is designed and operated with the SOC 2 Type II and ISO 27001 frameworks in mind. These describe how we build; they are not a claim of certification.
SOC 2 & ISO 27001 Aligned
Our architecture, access controls, and data-handling practices are built to align with the principles of SOC 2 Type II and ISO 27001. We do not currently hold certification under either.
GDPR & LGPD Roles
In data-protection terms, your firm is the controller, ICM Desk is the processor, and our AI and infrastructure providers are sub-processors bound by contract.
Your Confidentiality Duty
Professional confidentiality remains your obligation to your clients. ICM Desk provides the technical and contractual safeguards that support you in meeting it.
AI Confidentiality
How AI Handles Your Data
ICM Desk’s AI features run on the commercial APIs of Anthropic and OpenAI — not the consumer chat apps — which changes how data is treated.
Never Used for Training
Under the commercial API terms, neither Anthropic nor OpenAI uses your inputs or outputs to train their models. This is contractual, not a setting.
Isolated and Encrypted
Requests are processed in isolation and encrypted in transit and at rest. Your data is never exposed to other customers or made public.
Minimal Provider Retention
By default, providers retain data only briefly (typically up to ~30 days) for abuse monitoring, then delete it — the same posture as Azure, Google Cloud, and AWS.
Zero Data Retention on Request
For engagements that require it, we can pursue a Zero Data Retention agreement with our AI providers, subject to their approval. Raise it early so it can be arranged.
Availability & Support
Kept available, and backed up
How we keep the platform available, protect your data against loss, and support your team.
Automated Backups
Your data lives in a managed database that our infrastructure providers back up automatically, so the platform can be restored in the event of a failure. You do not have to manage your own backups.
Platform Availability
ICM Desk runs on established cloud infrastructure (Supabase and Cloudflare), and we use commercially reasonable efforts to keep it available. Where a specific availability commitment applies to your account, it is set out in your Platform Service Agreement.
Support
Reach our team at support@icmdesk.com for help with the platform. Any applicable service levels are governed by your Platform Service Agreement.
Get in Touch
Questions About Security or Privacy?
We’re happy to walk your compliance team through how ICM Desk handles data — and to put a Data Processing Agreement in place if your firm needs one.
