Decorative blur effect
Security & Privacy

Security and Privacy at Infa

Security is at the heart of what we do—helping our customers improve their security and compliance posture starts with our own.

Governance

Infa's Security and Privacy teams establish policies and controls, monitor compliance with those controls, and prove our security and compliance to third-party auditors.

Our policies are based on the following foundational principles:

01.

Access should be limited to only those with a legitimate business need and granted based on the principle of least privilege.

02.

Security controls should be implemented and layered according to the principle of defense-in-depth.

03.

Security controls should be applied consistently across all areas of the enterprise.

04.

The implementation of controls should be iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability, and decreased friction.

Security and Compliance at Infa
Infa has successfully achieved SOC 2 Type II certification, demonstrating our commitment to the highest security standards and comprehensive data protection. Our SOC 2 Type II report is available via our Trust Center.

We maintain compliance with leading data protection frameworks and continue to work towards additional certifications to ensure our customers' data is protected at the highest level.
SOC 2 Type II Certified
Google Web Store Verified

Data Protection

Data at Rest
All datastores with customer data, in addition to cloud storage buckets, are encrypted at rest. Additionally, sensitive data is protected with field-level encryption.

This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information.
Data in Transit
Infa uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. We also use features such as HSTS (HTTP Strict Transport Security) to maximize the security of our data in transit. Server TLS keys and certificates are managed by cloud providers and deployed via secure load balancers.
Secret Management
Encryption keys are managed via secure cloud key management systems. These systems store key material in Hardware Security Modules (HSMs), which prevents direct access by any individuals, including employees of cloud providers and Infa. The keys stored in HSMs are used for encryption and decryption via secure APIs.

Application secrets are encrypted and stored securely via cloud secret management services, and access to these values is strictly limited.

Chrome Extension Security

Google Web Store Verification
Our Chrome extension has been thoroughly reviewed, verified, and approved by the Google Web Store. This process includes comprehensive security checks and compliance with Google's strict policies for browser extensions.
Minimal Code Injection
Unlike many other Chrome extensions, Infa does not inject code into every webpage you visit. We have developed an advanced system that only injects our component highlighting functionality when the side panel is actively being used.

This approach significantly reduces our security footprint and ensures that our extension only interacts with web screens when you explicitly choose to use Infa's features. When the side panel is inactive, our extension remains completely dormant.
Privacy-First Design
Our Chrome extension is designed with privacy as a core principle. We collect only the minimal data necessary to provide our services, and we never track your browsing behavior across websites.
  • Based on the codebase, the minimal data we collect includes:

    • User Authentication Data:
      • Email and name (when you sign in)
      • Authentication tokens (securely stored in Chrome's local storage)
    • Component and Design Token Data:
      • Boards, components, and design tokens you create
      • Component views with XPaths and URLs for components you identify
      • Screenshots that you explicitly capture of components or screens
      • Code snippets that you explicitly capture
    • User Preferences:
      • UI theme settings (light/dark mode)
      • Banner preference states (which banners you've closed)
      • Selected board and view states
    • Analytics Data (with minimal identifiable information):
      • Extension installation source
      • Feature usage patterns to improve the product
      • Error states for troubleshooting
  • All data processing happens locally when possible:

    • Component identification and analysis happens directly in the browser
    • Design token extraction and analysis is performed locally within content scripts
    • Board and component data is stored in Chrome's local storage by default
    • Only data you explicitly choose to sync is sent to our servers
  • We only access the content of the currently active tab when:

    • You explicitly use a feature that requires page analysis (like component selection)
    • You request a screenshot of a component or page
    • You use the AI assistant to analyze page content
  • Unlike many extensions, we do not:

    • Track your browsing history
    • Collect data from screens you're not actively using with our extension
    • Share your data with third parties for advertising or marketing purposes
    • Use persistent identifiers to follow you across websites
Data Synchronization
The extension follows a "local-first" approach, with server interactions happening only when you explicitly trigger cloud features or when using functionality that requires server-side processing.
  • Based on the codebase, data is sent to servers only in these specific scenarios:

    • User Authentication
      • When you explicitly sign in
      • When refreshing your authentication token (to maintain your session)
      • When you sign out (to invalidate tokens)
    • Cloud Synchronization (only with user action)
      • When you explicitly click to sync a board to the cloud
      • When you fetch boards you've previously synced to the cloud
      • When updating cloud-stored components or boards
    • Media Storage
      • When you capture and choose to upload a screenshot
      • When uploading page screenshots using the page screenshot feature
      • When saving code snippets to cloud storage
    • AI Assistant Interactions
      • When sending messages to the AI chat assistant
      • When the AI assistant processes page content (only happens when you initiate it)
    • Analytics
      • Basic usage metrics sent to Amplitude (extension installation, feature usage)
      • Error states for troubleshooting product issues
    • Community Features
      • When importing community boards
      • When sharing your boards with the community

    All local board and component data remains in your browser's local storage until you choose to sync it to the cloud.

AI and Data Processing

Zero Data Retention Policy
We do not save any of your information when using our AI features. For detailed information about our data handling practices, please review our Privacy Policy.
No Surveillance Infrastructure
Unlike many other startups, we do not add any middle layers for evaluations, logs, or monitoring of your AI interactions. Our focus is on listening to user feedback during interview sessions rather than checking on your prompts or conversations.

We believe in transparent and ethical AI practices that respect your privacy and give you full control over your data.
Azure OpenAI Security
We use Azure OpenAI services with training settings turned off, ensuring that your data is never used to train or improve AI models. Your conversations and prompts remain private and are not retained by our AI providers.

This configuration provides an additional layer of protection, ensuring that your sensitive information never becomes part of any training dataset.