An honest look at how we protect your assessment data today — and our roadmap for enterprise-grade compliance.
Hosted on AWS EC2 with Cloudflare SSL/CDN. All data transmitted over TLS 1.3. Application behind Cloudflare WAF.
Item text is processed in memory and persisted to encrypted-at-rest PostgreSQL. For engagement customers, data is retained for the duration of the engagement + 30 days, then deleted unless written consent for retention is provided.
LLM analysis is performed via Anthropic's Claude API. Anthropic does not train on API inputs. Item text is sent over TLS to Anthropic's API and is not retained by Anthropic after processing.
Operator console is protected by form-based authentication with bcrypt-hashed passwords. No customer-facing authentication in the current version — engagement data is accessed via signed URLs.
| Standard | Status |
|---|---|
| SOC 2 Type II | In Progress — Target Q4 2026 |
| HIPAA BAA | Available for Enterprise |
| GDPR | DPA Available on Request |
| ISO 27001 | Roadmap 2027 |
Found a security issue? We appreciate responsible disclosure.
[email protected]