Your respondents trusted you. We take that seriously.

Every survey response is someone's honest answer, given in confidence. This page documents — specifically, not in slogans — how SurveyRock protects that data, what we comply with today, and what's on our compliance roadmap.

Operating since 2012

Infrastructure and security

Encryption in transit
TLS on all surfaces. HTTPS is enforced across the application, API, and marketing site.
Access controls
Role-based access within accounts, including a staff and client seat model for agencies. Multi-factor authentication is built in — authenticator app (TOTP), email one-time codes, SMS one-time codes, backup codes, and trusted devices. SSO via SAML 2.0 is available on Enterprise.
Audit logs
User-action audit logging is available on Growth tier and above.
Payment security
Payments are processed by Paddle as Merchant of Record. SurveyRock never receives or stores card data — PCI DSS obligations sit with Paddle.

Data privacy

Data ownership
Your survey data and your respondents’ answers are yours. We don’t sell them, we don’t mine them for advertising, and we don’t train AI models on them. AI governance detail →
Deletion requests
Data-subject deletion requests are honored under our GDPR data-subject request process.
Sub-processors
Every third party that processes data on our behalf is listed publicly, with what each one does and where. This includes our AI providers and our analytics provider. View sub-processors →

Compliance — what we hold, what we're building toward

GDPRAlignedData-subject request handling in place; DPA available on request. Details →
SOC 2 Type IIOn our roadmapNot yet certified, and we won’t imply otherwise. We’re happy to complete security questionnaires and walk through our controls directly in the meantime.
ISO 27001On our roadmapPlanned alongside SOC 2.
HIPAAAvailable on EnterpriseScoped and built out as part of Enterprise’s custom, sales-led onboarding — raise it during the sales conversation so the relevant controls and BAA are in place before your data flows.

AI and data governance

AI features in SurveyRock operate under three commitments: your response data never trains AI models; AI runs only when you invoke it; and AI providers never gate your data — collection and exports work even if every AI provider is down.

Full AI governance disclosure →

Responsible disclosure

Found a security issue? Tell us directly and we'll respond fast — we commit to acknowledging reports within 2 business days. We don't operate a paid bounty program, but we credit researchers who report responsibly, with permission, and we don't pursue good-faith research.

Report a security issue →

Data Processing Agreement

EU customers, and anyone processing personal data through SurveyRock, can put a DPA in place with us — it covers processing scope, sub-processors, security measures, and breach notification. Available on request.

Request a DPA →

Questions?

Security questionnaires, vendor reviews, specific control questions — send them. We'd rather answer precisely than have you guess generously.

Contact us