Is Intercom Fin ISO 27001 certified?
YesIntercom · Customer support
Yes. Intercom is ISO/IEC 27001 certified for Intercom Fin, the international information-security management standard.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- ISO/IEC 27001
- Confirmed
- Intercom reports ISO/IEC 27001 certification. Ask for scope and current certificate dates before treating it as supplier assurance.
- SOC 2
- Confirmed
- Intercom also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
- Default data training
- Opt-out required
- Intercom's own fin-cx models are trained on anonymized Customer Data from active workspaces; workspaces with a HIPAA BAA, on EU or AU regional hosting, or on trial are auto-excluded, and you can self-serve opt out in Settings.
- Business-tier training
- No by default
- Third-party LLMs (OpenAI, Anthropic, Google) are contractually barred from training.
Practical risk: On the top Expert plan with Regional Data Hosting and a signed BAA, Fin holds SOC 2 Type II and ISO 27001, keeps third-party LLMs out of training, and offers EU residency. Lower plans train Intercom's own models on anonymized data unless you opt out.
How to make a decision
Check the precise account tier, written contract and intended data before approving Intercom Fin. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Intercom Fin
Is Intercom Fin HIPAA compliant?Is Intercom Fin GDPR compliant?Is Intercom Fin SOC 2 compliant?Does Intercom Fin train on your data?
See the full Intercom Fin risk profile, with every data-handling fact and its source, or browse all rated AI tools.