For institutions¶
Material for procurement, security review, and IRB processes.
Assessments and agreements¶
- HECVAT. A completed HECVAT 4 self-assessment is available on request, this is the standard vendor-security questionnaire for higher education, and self-assessment is the normal path for research tools of this size.
- Data Processing Agreement. A standard DPA reflecting the researcher-as-controller model described in Data handling is available for signature per institution.
- Breach notification. Commitment to notify affected institutional contacts without undue delay after confirming a personal-data breach, with scope, impact, and remediation steps.
- Certifications. No SOC 2 or ISO 27001 certification is held, the HECVAT self-assessment documents the actual controls instead. No commissioned third-party penetration test to date, stated plainly, and available as a roadmap item where an institution requires it.
- Accessibility. A VPAT has not yet been produced, the interface is built with keyboard operability and contrast-aware theming, and a formal conformance report is on the roadmap.
Facts reviewers usually need¶
- Researcher-as-controller model, the institution's researcher owns and controls collected data, the platform processes it. Participants need no accounts.
- US hosting, single region. Subprocessor list published here.
- Self-service export (XLSX, CSV, Stata, SPSS, files ZIP) and self-service deletion with byte-level file erasure, including full account deletion with per-project transfer options. No vendor lock on the data.
- Only strictly necessary cookies, no advertising or analytics trackers anywhere in the product.
- Not a payment-card processor, not a student-records system, not a HIPAA business associate, surveys must not collect data subject to those regimes unless separately agreed.
- Security posture summarized in Security overview, transport hardening, hashed credentials, object-level authorization, confidential file isolation, integrity-pinned third-party assets.
Privacy law¶
The Privacy Policy (footer of every page) covers GDPR legal bases, data-subject rights, and transfer safeguards for the EEA and UK, plus CCPA/CPRA rights for California residents with an explicit statement that personal information is neither sold nor shared for cross-context behavioral advertising, and Global Privacy Control is honored by that same fact.
Contact¶
Use the published security and privacy contact for questionnaires, DPA signature, or any review the institution needs.