Security and data protection
Encryption
All traffic is encrypted in transit with TLS 1.2 or higher. Data at rest — including database storage and backups — is encrypted with AES-256.
Tenant isolation
Every record is scoped to an immutable organisation identifier and enforced at the database layer with row-level security policies, not just in application code. One customer cannot read another customer's data even if application logic were bypassed.
Respondent anonymity
Survey responses are not linked to identifiable individuals in reporting. Results stay locked behind a minimum response threshold, and administrators are warned before any configuration that would risk re-identification.
Access control
Role-based access across employee, manager and administrator, with managers restricted to aggregated results for their own team. Server-side authorisation checks apply on every privileged operation.
Data residency
Customer data is stored in Australian infrastructure.
Shared responsibility
We secure the platform, infrastructure and data layer. Customers are responsible for who they invite, the roles they grant, and keeping their own account credentials safe.
Security questions or a vendor assessment to complete? Contact us.