Security Practices
Protect your data and minimise compliance risks by using Indacas to manage your studies.Protect your data
All of your data, and your respondents' data, is by default securely stored in ISO 27001 certified data centres in London. If you require a different place of data residency, contact us to enquire about an Enterprise plan. To protect your data from malicious attackers, we encrypt all data in transit using Hypertext Transfer Protocol Secure (HTTPS) and enforce HTTP Strict Transport Security (HSTS).GDPR controls
Keep your data safe and compliant by using a platform designed by researchers, with privacy and transparency in mind from the beginning. All personal information and data collected from your respondents or participants belongs entirely to you. We make it easy to quickly comply with GDPR right to erasure requests. All it takes is one button click to remove all of a participant's personal data from their record, or any survey responses they have completed.How it is protected
Encrypted in transit and at rest TLS is terminated at the edge and internal service traffic stays on private networks. Data
in all of our databases is encrypted at rest with Linux Unified Key Setup.
Segmented network The platform API has no public route. It sits on an internal network reachable only by the
application itself, and administrative interfaces are restricted to named engineers.
Access by role Editing, participant management, bulk export and audit viewing are each restricted to
specific roles. Fields marked sensitive require a further privilege before they can be
exported.
Account protection Passwords are hashed with bcrypt by the identity service, a verified email address is
required before sign-in, and sign-in responses do not reveal whether an address is
registered. Sessions expire after 24 hours, and an unattended screen is prompted after 15
minutes of inactivity and signed out if nobody answers. Signing in, verifying a second
factor, and changing a password, email address or second factor are each written to the
audit trail, and an account can only be signed in at one place at a time.
Immutable audit trail Creates, updates and deletes are recorded with actor, timestamp, target, IP address and user
agent, written centrally so no code path can skip them. Bulk exports are logged explicitly
as data leaving the platform, and study and organisation audit logs are readable in the
application by authorised users.
Abuse protection Request rate limits are partitioned by authenticated user or client address, and new
anonymous survey responses are required to pass a bot check.