Protect your data

All of your data, and your respondents' data, is by default securely stored in ISO 27001 certified data centres in London. If you require a different place of data residency, contact us to enquire about an Enterprise plan. To protect your data from malicious attackers, we encrypt all data in transit using Hypertext Transfer Protocol Secure (HTTPS) and enforce HTTP Strict Transport Security (HSTS).

GDPR controls

Keep your data safe and compliant by using a platform designed by researchers, with privacy and transparency in mind from the beginning. All personal information and data collected from your respondents or participants belongs entirely to you. We make it easy to quickly comply with GDPR right to erasure requests. All it takes is one button click to remove all of a participant's personal data from their record, or any survey responses they have completed.

How it is protected

Encrypted in transit and at rest TLS is terminated at the edge and internal service traffic stays on private networks. Data in all of our databases is encrypted at rest with Linux Unified Key Setup.
Segmented network The platform API has no public route. It sits on an internal network reachable only by the application itself, and administrative interfaces are restricted to named engineers.
Access by role Editing, participant management, bulk export and audit viewing are each restricted to specific roles. Fields marked sensitive require a further privilege before they can be exported.
Account protection Passwords are hashed with bcrypt by the identity service, a verified email address is required before sign-in, and sign-in responses do not reveal whether an address is registered. Sessions expire after 24 hours, and an unattended screen is prompted after 15 minutes of inactivity and signed out if nobody answers. Signing in, verifying a second factor, and changing a password, email address or second factor are each written to the audit trail, and an account can only be signed in at one place at a time.
Immutable audit trail Creates, updates and deletes are recorded with actor, timestamp, target, IP address and user agent, written centrally so no code path can skip them. Bulk exports are logged explicitly as data leaving the platform, and study and organisation audit logs are readable in the application by authorised users.
Abuse protection Request rate limits are partitioned by authenticated user or client address, and new anonymous survey responses are required to pass a bot check.

Consent and participant rights

Consent statements are versioned, and each captured consent stores a hash of the exact text that was shown, with an optional typed signature. Revocation is timestamped rather than deleted, so the record of what someone agreed to, and when they changed their mind, survives. Participants can see the responses they have given, study by study. The only details we require for an account are a name and an email address; everything else on a profile is optional.

Who we rely on

DigitalOcean provides hosting and the managed database in London. Postmark delivers transactional email — account and notification messages only. Cloudflare sits in front of the platform as our DNS and reverse proxy, providing DDoS protection and the bot check on anonymous responses. Cloudflare Regional Services keeps that traffic inside Cloudflare's UK data centres before it reaches our servers in London. GitHub Container Registry stores application images, which hold no personal data. Our subprocessor list sets out exactly what each one handles. Identity is handled by Ory — Kratos for accounts and sign-in, Oathkeeper for authorisation. We run both on our own servers in London rather than using Ory's hosted service, so Ory as a company never receives your data. It is software we operate, not a provider we send anything to. DigitalOcean's cloud platform holds SOC 2 Type 2 and SOC 3 attestations covering security and availability.
Found a vulnerability? Tell us through the contact form and we will get back to you. Please give us a reasonable window to fix it before disclosing it publicly.