Architecture-enforced.
Not just contractual.
Eight commitments that determine how IntelyGo handles your business data. Each one is enforced by design, verified at deployment, and documented in your engagement agreement with DRCC.
How data flows
IntelyGo reads from your accounting system and computes intelligence. It never writes to your accounting system without your explicit approval.
Eight security commitments
Each commitment is documented in the client engagement agreement with Dolphy Ronald Carlo & Co LLP.
Read-only connection
IntelyGo connects to your accounting system via OAuth 2.0 with read-only access scopes. It cannot create, modify or delete records in your accounting system independently. The connection can be revoked from your accounting system settings in one click — instantly and permanently.
OAuth 2.0 · Read-only scopes · Revocable anytime
Nothing installed on-premise
No software is installed on your servers, devices or internal network. IntelyGo communicates entirely via API over HTTPS. Your IT team has nothing to install, maintain or update.
Cloud-only · No VPN · No file transfer · No agents
Tenant isolation
Every client's computed data is isolated at the database level using Row-Level Security. No IntelyGo user can access another client's data — this is enforced by the database architecture, not by application policy alone.
Row-Level Security · Database-enforced isolation · Verified at deployment
AI privacy
Your financial questions to the Owner Copilot are not used for AI model training. Conversation data is not stored or retained beyond the active session. IntelyGo processes your queries to answer them — nothing more.
Not used for model training · Session-only processing
Data deletion on request
A written request to DRCC triggers deletion of all computed intelligence within 7 working days. This is confirmed in writing. Your accounting system records are never affected — they remain in your accounting system throughout and after.
Written request · 7 working days · Confirmed in writing · Policy commitment
Execution audit trail
Every PO, invoice and receipt processed through Business Execution is logged — who approved, when, the exact amount, account and full context. A complete record of every action taken through IntelyGo is available at any time.
Complete log · Timestamped · Full context recorded per action
Secure cloud hosting
IntelyGo infrastructure runs on enterprise cloud platforms with industry-standard security controls, encryption at rest and in transit, and strict access management. The specific hosting configuration for your deployment is confirmed during implementation.
Enterprise cloud · Encryption in transit and at rest · Access-controlled
Owner approval on every transaction
Business Execution never acts without your explicit confirmation. An approval card shows exactly what will be posted before any action is taken. You can cancel at any point — nothing changes until you confirm.
Approval-gated · Owner-only confirmation · No autonomous writes
Need a detailed security brief?
A full security document including data flow diagrams, API permission scopes, data retention policy and hosting configuration is available on request from DRCC.
Request the security brief