Security
1) Overview
Polzy holds feedback people gave in confidence, so security is built into how the product works rather than added around it. This page describes the controls in place today.
2) Encryption
Data is encrypted in transit with TLS and at rest on encrypted storage volumes. Credentials for connected systems — an HR platform, a messaging provider — are encrypted separately before they are stored, so a database copy does not hand over access to anything you connected.
3) Anonymity by design
Results are suppressed below a minimum group size on every grouping, filter, export and API call, including groups built from your own fields. The floor is enforced in the query that computes each result, not in the interface that draws it.
4) Access control
Every workspace is isolated from every other: each query is scoped to the workspace it runs in. Inside a workspace, roles decide what each person can see and change. People can sign in with a password, Google or Microsoft, and add two-step verification with an authenticator app. Organisations can require two-step verification for every administrator, accept members only from their own email domains and set how long a session lasts.
5) Audit and monitoring
Administrative actions are recorded in an append-only audit log: sign-ins, including refused ones; changes to members, roles, API keys, sign-in providers, integrations and settings; plan changes; exports and deletions; and every access by Polzy staff, including “Open as admin” sessions. Each event records who acted, on what, when, from which address, and whether it was allowed. Passwords, keys, tokens and message contents are never recorded. On plans that include the audit log, an organization’s admins can review and export their organization’s events from Settings; nobody, Polzy included, can edit or delete an event. Events are kept for 400 days and then deleted automatically. The platform is monitored continuously, and its current state and past incidents are published on the status page.
6) Your data, your rights
A participant's record can be exported as portable JSON, and erasure severs their answers from them while leaving aggregates intact. A respondent can delete their own answers to an identified survey from the survey's privacy notice. Workspace administrators can export their data at any time, delete a workspace, or close their organisation from Settings; a deletion waits 14 days, read-only and cancellable, before everything is removed.
7) Reporting a vulnerability
If you believe you have found a security issue, write to security@polzy.ai with the details. We reply within two working days and keep you informed until it is fixed. Please do not access data that is not yours or disrupt the service while investigating.