Security and compliance
Built to pass your vendor risk assessment
Everything your information security and legal teams need to evaluate SurveyNode, on one page. ESJ Software Limited is registered with the UK Information Commissioner's Office and Cyber Essentials certified. Where data residency or control obligations apply, SurveyNode is deployed as a dedicated instance in the region your regulator requires, on AWS or the cloud provider you choose. Where a control is on the roadmap rather than in place, it says so.
Customer-side invitations: your contact list never leaves you
Where required, SurveyNode is deployed so that no customer data is shared with us. You send the invitations yourself, from your own SMS gateway, WhatsApp account or mail servers, inserting the survey link into your own message, so your contact list and personalisation stay entirely on your infrastructure. SurveyNode receives and processes only the feedback a respondent chooses to give. This model is ready today and available to any customer, in any country, whose regulator or policy requires it.
Hosting and data residency
Where a customer's regulator or data protection law requires it, or where a customer needs unlimited capacity and full control, we deploy a dedicated SurveyNode instance in a compliant region, on AWS or the cloud provider you require, so data is processed and stored there and nowhere else. This is a standard implementation option, open to any customer in any country. Every enterprise deployment is specified against your compliance requirements and signed off by your security and legal teams before go-live. Where no compliant region exists in-country, we document the transfer basis with you for the data protection authority.
Encryption
All traffic is encrypted in transit (TLS 1.2 or higher). Data is encrypted at rest. On dedicated AWS instances, keys are managed by AWS KMS, with customer-managed keys available.
Access control
Four-level role-based access per organisation (owner, admin, designer, analyst). Two-factor authentication with an authenticator app. Audit log of sign-ins, user and role changes, survey lifecycle and plan changes. API and MCP access is per-user, with scoped permissions. Single sign-on (SAML/OIDC) is on the enterprise roadmap.
AI providers and what they see
Conversational and analysis AI is provided by Anthropic (Claude), accessed over its API. The AI processes survey questions and the answers respondents choose to give, in order to ask follow-ups and produce analysis. Your contact lists are never sent to the AI provider, and Anthropic does not use API data to train its models.
Sub-processors
A current list of sub-processors, their role and their location is provided with the DPA and on request, and customers are notified 30 days before any change.
Retention and deletion
Response data is retained for the period the customer sets, then deleted. Full deletion on request or at contract end, with written confirmation.
Availability and continuity
Daily automated backups. Availability commitments and an SLA are agreed in each enterprise contract as part of the deployment sign-off.
Incident response
Named security contact, notification to affected customers within 72 hours of a confirmed incident, sooner where the law requires it.
Fit for purpose in any jurisdiction
SurveyNode is built to GDPR standards, the reference model for most data protection law written since 2018. For each country we operate in, we map the local Act to that baseline and document the differences in a DPA addendum. Three deployment options cover every regime we have met: the shared service, a dedicated instance in a compliant region, and the customer-side invitation model in which no contact data reaches SurveyNode at all.
| Jurisdiction | Law | Status | Deployment options |
|---|---|---|---|
| Eswatini | Data Protection Act 2022 | Customers live | Shared service or in-region instance |
| Zambia | Data Protection Act 2021 | Customers live | Shared service, in-region instance or customer-side invitation model |
| Ghana | Data Protection Act 2012 (Act 843) | Available | In-region instance or customer-side model |
| Nigeria | Nigeria Data Protection Act 2023 | Available | In-region instance or customer-side model |
| South Africa | POPIA | Available | Dedicated in-region instance (e.g. AWS Cape Town) |
| Kenya | Data Protection Act 2019 | Available | In-region instance or customer-side model |
| United Kingdom and EU | UK GDPR, GDPR | Available | Dedicated in-region instance (e.g. AWS London or EU) |
| Other | Mapped to the GDPR baseline on request | On request | Chosen with your data protection officer |
Security overview
Architecture, controls and policies in one document for your assessors.
Request the overviewData processing agreement
Our standard DPA is based on GDPR Article 28, with an addendum for the local Act of your country. We will review yours.
Request the DPAQuestionnaires
We complete your standard vendor questionnaires (e.g. CAIQ, SIG Lite) and bespoke assessments. Contact: security@surveynode.com
Start an assessment