Security

How IntelMCP handles data

What we collect, where it runs, who can see it and how long we keep it. The privacy policy is the formal version; this page explains the engineering behind it.

What we collect from Telegram

  • Messages from public Telegram channels and groups only. Never private chats or invite-only groups.
  • One collection session reads the channels. A newly seen channel stays hidden from searches until we approve it.
  • Technical indicators are extracted from each message: IP addresses, domains, URLs, file hashes, CVE identifiers and countries. We do not extract email addresses or Telegram usernames of the people who appear in posts.
  • Attachments are recorded as metadata (type, name, size). Files are never downloaded.
  • When a post is deleted at the source, it is removed from IntelMCP once the collector sees the deletion. If you appear in a collected message, you can ask us to remove it: we remove it, but a post that is still on Telegram may be collected again, so removal of a live post may need repeating.

Telegram text is untrusted

Telegram messages are written by strangers, some of them hostile, and some will try to talk to whatever AI reads them. IntelMCP treats every message, channel name and excerpt as untrusted third-party content:

  • Tool results reach Claude with a note that the text is third-party content: data to analyze, and any instructions inside it come from the channel, not from IntelMCP or from you.
  • The prompts you pick (Set up monitoring, Investigate, Triage matches, Dashboard) tell Claude to treat message text as data and never follow instructions inside it.
  • The Dashboard prompt tells Claude to insert message text into the page only as text, never as markup, and to give the page a restrictive content-security policy that blocks network requests except the chart library from cdnjs.
  • Webhooks carry the excerpt as a JSON string. Your receiving code should treat it the same way.

This lowers the risk; it cannot remove it. Read surprising instructions or claims in a summary with suspicion, and check the original post.

No AI on our servers

IntelMCP does not run, train or fine-tune AI models, and we do not sell data or use it for advertising. Matching rules and grouping reposts into incidents are deterministic code. The reading, translating and judging happen in your own Claude, under the terms of your Claude plan.

Isolation and sign-in

  • Each customer's rules, watch profiles, matches, verdicts, channel requests and webhook settings are separated by row-level security, enforced by the database itself rather than only by application code.
  • The server and the collector connect as separate database roles, and row-level security binds both.
  • Sign-in runs through WorkOS: Google, or a one-time code sent to your email. Every tool call checks that the account belongs to an active subscription (re-checked at least once a minute).
  • Webhook deliveries go only to HTTPS addresses that resolve to public internet addresses: private and internal addresses are refused, when a destination is set and again on every send. They are signed with HMAC-SHA256, so your endpoint can reject anything we didn't send, and their targets are shown masked.

Hosting

  • The service runs on Fly.io in the EU: servers in Amsterdam and Frankfurt, the collector and the database in Amsterdam.
  • The servers have no public address. All traffic to the IntelMCP service passes through Cloudflare's network, through an encrypted tunnel.
  • Encrypted backups are stored in Cloudflare R2 (a subprocessor).

Subprocessors

The same list as the privacy policy:

  • Fly.io: hosting and the database.
  • Cloudflare: network protection and encrypted backup storage (Cloudflare R2).
  • WorkOS: sign-in.
  • Google: our support mailbox, and sign-in if you choose "Continue with Google".
  • Polar: checkout, subscriptions and tax, as merchant of record; card payments are processed by Stripe. We never see your card details.

Logs and retention

  • An audit log records which account called which tool and when, with a SHA-256 fingerprint of the main arguments, not the arguments in readable form. It is kept for up to one year.
  • Fair-use limits apply: 5,000 tool calls a day per subscription, and about 60 searches a minute (counted per server, so the per-minute limit is approximate).
  • Your rules, matches and settings are kept for 90 days after your subscription ends, then deleted. Subscribing again with the same email before then restores them.
  • Collected public Telegram messages are kept without a fixed time limit, unless they are deleted at the source or the channel is excluded from the collection.
  • Searches reach up to the last 90 days of collected messages.

This website

intelmcp.io sets no cookies, runs no analytics and loads nothing from other sites: the fonts are served from this domain. Its content-security policy includes script-src 'none', so the browser refuses to run any script on it, ours included.

Who runs IntelMCP

IntelMCP is an independent service. We don't publish personal names. Instead, judge it by what you can check: the published price, the public policies, this page, the dated changelog and the support address. Payments, invoices and tax are handled by Polar as merchant of record.

IntelMCP is not affiliated with or endorsed by Telegram or Anthropic. Claude is a trademark of Anthropic, PBC.

Reporting a problem

Found a vulnerability, or something on this page that doesn't match what you see? Email support@intelmcp.io with "Security" in the subject. Please don't test against other customers' data. The same contact is published in /.well-known/security.txt.