Security and compliance

Built to pass your vendor risk assessment

Everything your information security and legal teams need to evaluate SurveyNode, on one page. ESJ Software Limited is registered with the UK Information Commissioner's Office and Cyber Essentials certified. Where data residency or control obligations apply, SurveyNode is deployed as a dedicated instance in the region your regulator requires, on AWS or the cloud provider you choose. Where a control is on the roadmap rather than in place, it says so.

GDPR baselineLocal-law alignment per countryDedicated in-region instancesCustomer-side invitation modelUK ICO registeredCyber EssentialsDPA available
ICO Registered, Ref ZA908334Registered with the UK Information Commissioner's OfficeESJ Software Limited · ZA908334 · valid to 19 April 2027Verify on ico.org.uk
Cyber Essentials CertifiedCyber Essentials certifiedUK Government-backed cyber security certificationVerify certificate

Customer-side invitations: your contact list never leaves you

Where required, SurveyNode is deployed so that no customer data is shared with us. You send the invitations yourself, from your own SMS gateway, WhatsApp account or mail servers, inserting the survey link into your own message, so your contact list and personalisation stay entirely on your infrastructure. SurveyNode receives and processes only the feedback a respondent chooses to give. This model is ready today and available to any customer, in any country, whose regulator or policy requires it.

Hosting and data residency

Where a customer's regulator or data protection law requires it, or where a customer needs unlimited capacity and full control, we deploy a dedicated SurveyNode instance in a compliant region, on AWS or the cloud provider you require, so data is processed and stored there and nowhere else. This is a standard implementation option, open to any customer in any country. Every enterprise deployment is specified against your compliance requirements and signed off by your security and legal teams before go-live. Where no compliant region exists in-country, we document the transfer basis with you for the data protection authority.

Encryption

All traffic is encrypted in transit (TLS 1.2 or higher). Data is encrypted at rest. On dedicated AWS instances, keys are managed by AWS KMS, with customer-managed keys available.

Access control

Four-level role-based access per organisation (owner, admin, designer, analyst). Two-factor authentication with an authenticator app. Audit log of sign-ins, user and role changes, survey lifecycle and plan changes. API and MCP access is per-user, with scoped permissions. Single sign-on (SAML/OIDC) is on the enterprise roadmap.

AI providers and what they see

Conversational and analysis AI is provided by Anthropic (Claude), accessed over its API. The AI processes survey questions and the answers respondents choose to give, in order to ask follow-ups and produce analysis. Your contact lists are never sent to the AI provider, and Anthropic does not use API data to train its models.

Sub-processors

A current list of sub-processors, their role and their location is provided with the DPA and on request, and customers are notified 30 days before any change.

Retention and deletion

Response data is retained for the period the customer sets, then deleted. Full deletion on request or at contract end, with written confirmation.

Availability and continuity

Daily automated backups. Availability commitments and an SLA are agreed in each enterprise contract as part of the deployment sign-off.

Incident response

Named security contact, notification to affected customers within 72 hours of a confirmed incident, sooner where the law requires it.

Fit for purpose in any jurisdiction

SurveyNode is built to GDPR standards, the reference model for most data protection law written since 2018. For each country we operate in, we map the local Act to that baseline and document the differences in a DPA addendum. Three deployment options cover every regime we have met: the shared service, a dedicated instance in a compliant region, and the customer-side invitation model in which no contact data reaches SurveyNode at all.

JurisdictionLawStatusDeployment options
EswatiniData Protection Act 2022Customers liveShared service or in-region instance
ZambiaData Protection Act 2021Customers liveShared service, in-region instance or customer-side invitation model
GhanaData Protection Act 2012 (Act 843)AvailableIn-region instance or customer-side model
NigeriaNigeria Data Protection Act 2023AvailableIn-region instance or customer-side model
South AfricaPOPIAAvailableDedicated in-region instance (e.g. AWS Cape Town)
KenyaData Protection Act 2019AvailableIn-region instance or customer-side model
United Kingdom and EUUK GDPR, GDPRAvailableDedicated in-region instance (e.g. AWS London or EU)
OtherMapped to the GDPR baseline on requestOn requestChosen with your data protection officer

Security overview

Architecture, controls and policies in one document for your assessors.

Request the overview

Data processing agreement

Our standard DPA is based on GDPR Article 28, with an addendum for the local Act of your country. We will review yours.

Request the DPA

Questionnaires

We complete your standard vendor questionnaires (e.g. CAIQ, SIG Lite) and bespoke assessments. Contact: security@surveynode.com

Start an assessment