Security & Data Handling

An honest look at how we protect your assessment data today — and our roadmap for enterprise-grade compliance.

1. Infrastructure

Hosted on AWS EC2 with Cloudflare SSL/CDN. All data transmitted over TLS 1.3. Application behind Cloudflare WAF.

2. Data Handling

Item text is processed in memory and persisted to encrypted-at-rest PostgreSQL. For engagement customers, data is retained for the duration of the engagement + 30 days, then deleted unless written consent for retention is provided.

3. AI Processing

LLM analysis is performed via Anthropic's Claude API. Anthropic does not train on API inputs. Item text is sent over TLS to Anthropic's API and is not retained by Anthropic after processing.

4. Access Control

Operator console is protected by form-based authentication with bcrypt-hashed passwords. No customer-facing authentication in the current version — engagement data is accessed via signed URLs.

5. Compliance Roadmap

Standard Status
SOC 2 Type II In Progress — Target Q4 2026
HIPAA BAA Available for Enterprise
GDPR DPA Available on Request
ISO 27001 Roadmap 2027

6. Sub-processors

7. Responsible Disclosure

Found a security issue? We appreciate responsible disclosure.

[email protected]