KeystoneIQ
IntegrationsPricingBlogFree brief
Sign in

KeystoneIQ Security Overview

This document provides security information for vendor reviews and compliance inquiries. KeystoneIQ is the product; Intellibricks Inc. is the operating company.

AI Data Handling

  • Data is transmitted to AI providers via encrypted connections for brief generation only.
  • Under API terms with our providers, customer content is not used for model training.
  • We do not store prompt/completion logs beyond what is needed to deliver the Service.

Data Protection

  • Encryption in transit: All traffic uses TLS (HTTPS).
  • Encryption at rest: Integration credentials are encrypted at rest. Database encryption follows our hosting provider's standards.
  • Keys and tokens are never logged.

Access Controls

  • Authentication: Email/password, Google, Microsoft sign-in. Enterprise SSO (SAML) coming soon.
  • Two-factor authentication: TOTP-based MFA available for all users.
  • Role-based access: Owners manage workspace settings, billing, and team. Members can view and interact with intelligence.
  • Data isolation: All data is scoped to your workspace. Multi-tenant isolation ensures no cross-workspace data access.
  • API keys: Owner-only creation and revocation. Scoped per workspace. Never logged.
  • Share links (messaging): Read-only, expire after 90 days, revocable any time, no workspace login exposed.
  • Context Layer (MCP): Read-only, workspace-scoped keys, every call recorded in the API audit log.

Audit Logging

Sensitive operations are logged for compliance review, including API requests, authentication events, and administrative actions. Logs are append-only with no credentials stored.

Rate Limiting

API endpoints are rate-limited to prevent abuse. Sensitive operations have stricter limits.

Data Retention

  • User data retained while workspace is active.
  • Export and deletion available from account settings, supporting GDPR right to erasure.

Incident Response

  • Report: support@keystoneiq.ai
  • Process: Containment, investigation, notification to affected customers without undue delay per applicable law (including GDPR Art 33/34 where applicable).

Compliance

  • GDPR: Export and delete capabilities; data processing aligned with controller obligations. DPA available upon request.
  • PIPEDA: Accountable under Canadian federal privacy law.
  • CCPA/CPRA: We do not sell personal information.

Infrastructure

  • Application and data processing run on managed cloud infrastructure in the United States with encryption in transit and at rest.
  • Database backups are managed by our hosting provider.
  • Infrastructure providers maintain industry-standard security certifications.
  • KeystoneIQ is responsible for application-level controls: access management, audit logging, credential encryption, and incident response.

Integration Data Access

When you connect an integration, KeystoneIQ syncs data according to each provider's authorization model. All workspace members can see synced data within KeystoneIQ. Integration credentials are encrypted at rest using AES-256-GCM.

Access scoping varies by provider. Some providers grant portal-wide or org-wide access once a user authorizes the connection (HubSpot, Gong); others honor the connecting user's row-level permissions (Salesforce, Pipedrive, Zoho); others are strictly per-user (Notion, Confluence). Review the Authorization Scope column carefully, and for regulated environments, connect a dedicated integration user with least-privilege scopes (see guidance below).

IntegrationAuth MethodAuthorization ScopeData AccessedWorkspace Visibility
HubSpotOAuth 2.0Portal-level: once authorized, KeystoneIQ can read all objects matching the granted scopes across the entire HubSpot portal, regardless of the connecting user's in-app permissionsDeals, companies, contacts (scopes: crm.objects.deals.read, crm.objects.companies.read, crm.objects.contacts.read)All workspace members
SalesforceOAuth 2.0User-level: respects the connecting user's profile, role hierarchy, sharing rules, and field-level securityOpportunities and accounts visible to the connecting user (scopes: api, id, refresh_token)All workspace members
PipedriveOAuth 2.0User-level: respects the connecting user's visibility groupsDeals visible to the connecting userAll workspace members
Zoho CRMOAuth 2.0User-level: respects the connecting user's role and data-sharing rulesDeals visible to the connecting userAll workspace members
CopperOAuth 2.0User-level: respects the connecting user's permissionsOpportunities visible to the connecting userAll workspace members
GongOAuth 2.0 (or API key)Org-level: access is authorized across the Gong org, not a specific userCall transcripts (last 14 days), competitor mentionsAll workspace members
ZendeskAPI TokenAgent-level: scoped to the agent whose token is issued; inherits that agent's ticket visibilitySupport tickets visible to the token's agentAll workspace members
IntercomAccess TokenWorkspace-level: token authorizes read access across the Intercom workspaceConversations, competitor mentionsAll workspace members
NotionOAuth 2.0 (per-user)Per-user, per-page: each KeystoneIQ user connects individually; only pages explicitly shared with their integration are accessiblePages explicitly granted during OAuth authorizationOnly the connecting user's pages sync, but results are visible to all workspace members
ConfluenceOAuth 2.0 (per-user)Per-user, space-scoped: each KeystoneIQ user connects individually; access follows that user's Confluence space permissionsPages in spaces accessible to the connecting userOnly the connecting user's pages sync, but results are visible to all workspace members
Cloud file storage (Drive / SharePoint / OneDrive / Dropbox / Box)OAuth 2.0 (per-account)User-level: honors the connecting account's folder and file permissions in the underlying providerFiles and folders visible to the connecting accountAll workspace members
SlackOAuth 2.0 (webhook)Channel-level: webhook posts to a specific channel; KeystoneIQ never reads Slack messagesOutbound notifications only, no data is read from SlackN/A (outbound only)
Microsoft TeamsWebhook URLChannel-level: webhook posts to a specific channel; KeystoneIQ never reads Teams messagesOutbound notifications only, no data is read from TeamsN/A (outbound only)
Google Analytics 4OAuth 2.0Property-level: respects the connecting user's GA4 property accessAggregated traffic metrics for the configured propertyAll workspace members
KlaviyoAPI KeyAccount-level: read scopes on the Klaviyo accountAggregated list/campaign metricsAll workspace members
SEMrushAPI KeyAccount-level: read scopes on the SEMrush accountCompetitor keyword and traffic dataAll workspace members
G2API KeyAccount-level: G2 review feedCompetitor review dataAll workspace members
Company Enrichment (Clearbit)API KeyService-level: enrichment lookups on domains you providePublic firmographic data for competitors you trackAll workspace members

Dedicated Integration User (recommended for regulated environments)

For enterprise deployments, we strongly recommend connecting KeystoneIQ using a dedicated integration user rather than a named employee's account. This provides predictable, auditable access scoping, avoids disruption if the employee leaves, and maps cleanly to least-privilege principles.

  • HubSpot: Create a user with only the required crm.objects.*.read scopes enabled. Because HubSpot grants portal-level access on authorization, the scopes are the only real boundary. Keep them minimal.
  • Salesforce: Create a dedicated Integration User profile with a permission set limited to read access on Opportunity and Account. Apply sharing rules and field-level security to further restrict what KeystoneIQ can see.
  • Pipedrive / Zoho / Copper: Create a read-only user assigned to only the visibility groups / roles whose deals should flow into KeystoneIQ.
  • Gong: Use a scoped API key rather than an admin-level key if available on your plan.
  • Zendesk: Issue an API token for a dedicated agent whose ticket views match the tickets you want KeystoneIQ to analyze.
  • Notion / Confluence / cloud file storage: These are already per-user or per-account scoped. Share only the spaces/folders containing competitive material with the KeystoneIQ integration.
  • GA4: Grant the dedicated user Viewer role on only the properties whose traffic data should flow into briefs.

Data Processing Agreement

If your organization requires a DPA for GDPR or similar regulatory compliance, contact support@keystoneiq.ai.

Public API (/api/v1/*) CORS policy

The public REST API at /api/v1/* returns Access-Control-Allow-Origin: * to allow integrations (Zapier, Make, custom scripts) to call it from any origin. This is safe by design because:

  • No cookie-based auth. The API accepts Bearer tokens only (Authorization: Bearer sk_...). Access-Control-Allow-Credentials is explicitly false, so browsers will not attach cookies on cross-origin requests even if an attacker tries to force them.
  • API keys are workspace-scoped and revocable. Every call is authenticated with an HMAC-SHA256-hashed key tied to a single workspace; owners can rotate or revoke at any time from Developer page.
  • Per-IP rate limiting. /api/v1/* is guarded by a 60-req/min sliding-window limit (see lib/ip-rate-limit.ts) to prevent brute-force key guessing.
  • Session-cookie routes are NOT part of this policy. All user-session APIs (/api/workspace/*, /api/invites/*, etc.) rely on same-origin cookie delivery under Next.js defaults and do not emit a wildcard CORS header.

AI assistant connectors (MCP Context Layer)

KeystoneIQ exposes a read-only Model Context Protocol server at /api/mcp so customers can connect Claude, Cursor, and other AI assistants to their own workspace. Security properties:

  • Same keys, same isolation. The connector authenticates with the workspace-scoped sk_ API key (HMAC-SHA256 hashed at rest, owner-managed, revocable). Every tool call resolves to exactly one workspace and every query the server runs carries an explicit workspace filter (the connector uses a service connection, so isolation is enforced per query rather than by row-level security); there is no cross-workspace query path.
  • Read-only by construction. Version 1 ships only read tools, each declared with readOnlyHint: true. No tool can create, modify, or delete workspace data.
  • Plan gates mirror the app. Each tool enforces the same plan check as the in-app feature it reads from, so a connector can never see more than the same user would see in the browser.
  • Prompt-injection framing. The corpus contains text crawled from third-party websites. Every response carries a _provenance block that labels the payload as external data, not instructions, and the demo connector (when enabled) serves only a curated sample workspace.
  • Metered and audited. Every tool call is written to the workspace's append-only API audit log with tool name, status, and timestamp; the monthly usage meter is computed from that same log. Per-workspace hourly burst limits and, for keyless demo traffic, per-IP limits apply.
  • No AI provider in the loop. Serving an MCP request sends workspace data only to the customer's own MCP client. KeystoneIQ does not forward connector traffic to any AI provider; the search tool sends the query text alone to the embedding provider, as in-app search does.
  • Stateless transport. The endpoint is stateless streamable HTTP with no server-side session or event stream. /api/mcp does not emit a wildcard CORS header; browser-hosted assistants that require OAuth are not supported in this release.

Related policies

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Last updated: September 7, 2026

KeystoneIQ

Product

For PMMsIntegrationsFor AI assistantsMessaging & positioningCompareSample reportsSample briefBattlecard templateFree competitive briefPricingBlogDocsSupport

Reviews

Review us on G2Capterra

Legal

SecurityPrivacyTermsCookies

© 2026 Intellibricks Inc.