Your respondents trusted you. We take that seriously.
Every survey response is someone's honest answer, given in confidence. This page documents — specifically, not in slogans — how SurveyRock protects that data, what we comply with today, and what's on our compliance roadmap.
Operating since 2012
Infrastructure and security
- Encryption in transit
- TLS on all surfaces. HTTPS is enforced across the application, API, and marketing site.
- Access controls
- Role-based access within accounts, including a staff and client seat model for agencies. Multi-factor authentication is built in — authenticator app (TOTP), email one-time codes, SMS one-time codes, backup codes, and trusted devices. SSO via SAML 2.0 is available on Enterprise.
- Audit logs
- User-action audit logging is available on Growth tier and above.
- Payment security
- Payments are processed by Paddle as Merchant of Record. SurveyRock never receives or stores card data — PCI DSS obligations sit with Paddle.
Data privacy
- Data ownership
- Your survey data and your respondents’ answers are yours. We don’t sell them, we don’t mine them for advertising, and we don’t train AI models on them. AI governance detail →
- Deletion requests
- Data-subject deletion requests are honored under our GDPR data-subject request process.
- Sub-processors
- Every third party that processes data on our behalf is listed publicly, with what each one does and where. This includes our AI providers and our analytics provider. View sub-processors →
Compliance — what we hold, what we're building toward
AI and data governance
AI features in SurveyRock operate under three commitments: your response data never trains AI models; AI runs only when you invoke it; and AI providers never gate your data — collection and exports work even if every AI provider is down.
Full AI governance disclosure →Responsible disclosure
Found a security issue? Tell us directly and we'll respond fast — we commit to acknowledging reports within 2 business days. We don't operate a paid bounty program, but we credit researchers who report responsibly, with permission, and we don't pursue good-faith research.
Report a security issue →Data Processing Agreement
EU customers, and anyone processing personal data through SurveyRock, can put a DPA in place with us — it covers processing scope, sub-processors, security measures, and breach notification. Available on request.
Request a DPA →Questions?
Security questionnaires, vendor reviews, specific control questions — send them. We'd rather answer precisely than have you guess generously.
Contact us