Your respondents’ data, handled properly
Encrypted in transit and at rest, isolated per workspace, and never sold or used to train anything. Here is exactly how it works.
- TLS 1.3 in transit
- AES-256 at rest
- EU and US data regions
- SSO and SAML
How it is protected
Data protection
Every response is encrypted in transit with TLS 1.3 and at rest with AES-256. Uploaded files are stored separately with signed, expiring URLs.
Access control
SSO, SAML and role-based permissions per workspace. Personal API keys are scoped, revocable and never shared across members.
Infrastructure
Isolated environments, least-privilege service accounts, automated patching and continuous monitoring with alerting on anomalies.
Privacy by default
Your data is yours. It is never sold, never shared with advertisers and never used to train a model without explicit opt-in.
What we actually do
The practices behind the claims above, stated plainly.
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Workspace-level data isolation with no shared tables
- Signed, expiring URLs for every uploaded file
- Role-based permissions and per-key API scopes
- SSO and SAML on business plans
- Audit log of every workspace and form change
- Automated dependency scanning and patching
- Least-privilege access for internal systems
- Regular third-party penetration testing
- Documented incident response with customer notification
Compliance and documentation
The documents your procurement and security teams usually ask for, ready to send.
GDPR
Lawful basis, data subject rights and deletion on request.
Data processing agreement
Standard DPA available to every paid workspace.
Sub-processors
A current, versioned list with change notifications.
Penetration testing
Summary reports available under NDA.
Need something for your security review?
Send us the questionnaire and we will turn it around.