Intercom AI Vendor Risk Profile
Customer service platform with Fin, an AI agent that resolves customer queries using company knowledge bases. Built on GPT-4 with retrieval-augmented generation for accurate, brand-consistent responses.
Risk overview
Risk score: 31/100
Risk tier: Moderate
Safety rating: 69/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 28/100 |
| IP Exposure | 31/100 |
| Jurisdiction | 13/100 |
| Security | 22/100 |
| Regulatory Compliance | 50/100 |
| Transparency | 70/100 |
| Business Stability | 37/100 |
| Dependency Chain | 28/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Intercom's Fin AI is a customer service-focused AI agent built on top of OpenAI and Anthropic with zero-retention subprocessor agreements. Intercom's mature SaaS compliance posture (SOC 2, ISO 27001, GDPR, HIPAA BAA) applies to AI features within existing Intercom customer deployments.
Bottom line: Natural AI extension for existing Intercom customers; not a standalone AI vendor for non-Intercom buyers.
Strengths
- No training on customer conversation data; zero-retention with upstream LLM providers
- SOC 2 Type II and ISO 27001 certified
- GDPR DPA with EU data residency options
- HIPAA BAA available for eligible plans
- Customer retains ownership of conversation data and AI-generated responses
Concerns
- AI capability depends entirely on upstream OpenAI and Anthropic (inherits their risk)
- No FedRAMP authorization disclosed
- Pricing model for AI-resolved conversations can escalate quickly
- Value is primarily unlocked for existing Intercom customers
Best for
- Existing Intercom customers adding AI to customer support workflows
- SaaS and e-commerce companies with conversational customer service needs
- Customer support teams needing AI that respects existing privacy and compliance posture
Avoid if
- You are not on Intercom (the AI alone is not a reason to adopt it)
- You need FedRAMP authorization for government customer service
- You want a generic customer service AI without the Intercom platform
- You need custom model fine-tuning on domain-specific data
Citations
- Data Handling — Hipaa Baa Available
Intercom offers HIPAA Business Associate Agreements on eligible plans for customers handling protected health information.
- Data Handling — Third Party Data Sharing
Fin AI routes conversations to OpenAI and Anthropic models under zero-retention, no-training subprocessor agreements.
- Data Handling — Trains On User Data
Intercom does not use customer conversation data to train its own foundation models; Fin AI uses upstream providers with zero-retention contracts.
- Ip Profiles — User Owns Outputs
Customer retains ownership of Customer Data, including conversations and AI-generated responses handled by Fin AI on behalf of Customer.
- Jurisdiction Profiles — Incorporation Country
Intercom, Inc. is a Delaware corporation with its global headquarters in San Francisco and EMEA operations in Dublin, Ireland.
- Security Compliance — Gdpr Compliant
Intercom offers a GDPR-compliant Data Processing Addendum and operates EU data residency for European customers.
- Security Compliance — Iso 27001
Intercom is ISO/IEC 27001 certified.
- Security Compliance — Soc2 Type2
Intercom maintains SOC 2 Type II compliance audited annually, with reports available to customers under NDA.