Executive Summary
AI-generated analysis for Intercom
Intercom (intercom.com) is a well-established SaaS customer communications platform with a 32-year domain history and a Tier 3 (Moderate Risk) rating, reflecting a vendor with meaningful strengths but specific transparency and configuration gaps that warrant attention before granting high-data-access privileges. Intercom presents several positive signals consistent with a mature SaaS operator:
Key Findings
- Domain reputation is clean across all blacklist checks (SURBL, Spamhaus DBL, URLhaus) with no active malware URLs
- Infrastructure exposure is minimal, with only 2 open ports (80, 443) and zero known CVEs — well below the SaaS industry average of 8–12 open ports
- The domain has been registered since 1993 and archived since 1996, confirming a long-established online presence
- No adverse media was found in the past 12 months, and no sanctions or enforcement matches were confirmed
- Intercom claims SOC 2 compliance with a dedicated trust and compliance page, and references GDPR and CCPA obligations in its privacy documentation Several gaps require attention, particularly given this vendor's high data access level:
- Intercom's AI data usage practices — specifically whether customer data is used to train AI models — are not clearly disclosed, a meaningful concern given the vendor's active investment in AI-powered features (Fin AI)
- No publicly accessible subprocessor list was identified, limiting supply chain visibility and raising questions about GDPR Article 28 compliance transparency
- The SOC 2 claim has not been independently verified through a public registry (none exists for SOC 2); the actual Type II report and bridge letter should be requested directly
- HTTP security headers received a grade of C (50/100) from HTTP security scanner, with Content-Security-Policy and X-Frame-Options absent from the main domain
- Certificates are issued across 37 distinct Certificate Authorities, which may indicate inconsistent certificate lifecycle management across Intercom's 79-subdomain infrastructure Overall, Intercom is a credible, established vendor with no critical or high-severity findings, but the combination of unclear AI training practices, missing subprocessor transparency, and unverified compliance claims at a high data access level supports a conditional approval posture pending resolution of key documentation requests.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or input.