Security & data protection

How we protect your data and earn your trust

StatQuestions is built for enterprise CX teams handling sensitive customer data. We treat security as a core product requirement, not an afterthought.

Encrypted in transit & at rest

Role-based access controls

Org-level data isolation

No data sold, ever

Infrastructure & hosting

StatQuestions runs on enterprise-grade cloud infrastructure with high availability, automatic failover, and geo-redundant backups.

  • All data is hosted on SOC 2 Type II certified cloud infrastructure. StatQuestions' own SOC 2 audit is in progress.
  • Automatic daily backups with point-in-time recovery
  • Database and storage layers are fully isolated per organization
  • 99.9% uptime SLA for production environments
  • Infrastructure is never shared between tenants at the data layer

Encryption

  • All data in transit is encrypted using TLS 1.2 or higher, no unencrypted connections accepted
  • All data at rest is encrypted using AES-256, including uploaded files, email content, and classification outputs
  • Encryption keys are managed separately from the data they protect
  • Passwords are never stored, authentication uses industry-standard hashed tokens only

Access controls

Access to your data follows the principle of least privilege, only authorized users and system processes can access data relevant to their role.

  • Role-based access control (RBAC) with Admin, Analyst, and Viewer tiers
  • Row-level security (RLS) enforced at the database layer, not just the application layer
  • Admins can grant and revoke individual user access at any time
  • Platform owner staff access to customer data requires explicit authorization and is logged
  • Session tokens expire automatically; forced logout is available at any time

Your data, your control

You own your data. We act as a processor on your behalf, we never use your customer data for any purpose other than delivering the service you've contracted for.

  • Your data is never sold, rented, or shared with third parties for their own commercial purposes
  • Your uploaded email and survey content is never used to train publicly released AI models
  • AI analysis is performed on-demand, not stored in AI provider systems beyond the processing call
  • You can export your data at any time in standard formats
  • You set how long uploaded content is kept. After an account closes, data is kept for 30 days so you can export it, then permanently deleted

AI & LLM data handling

StatQuestions uses large language models (LLMs) for classification and analysis features. Here's exactly how your data is handled:

  • We use enterprise API tiers of AI providers that do not use your data for model training by default
  • Email content sent to AI models is done so only within the analysis pipeline, for the task you triggered
  • No personally identifiable information (PII) is deliberately enriched or indexed by AI providers
  • AI-generated outputs (classifications, summaries) are stored only within your organization's isolated data space
  • You can view exactly which fields are submitted for classification in our audit logs
Your responsibility: If your data contains sensitive personal data, you should apply appropriate masking or pseudonymization before uploading. StatQuestions is an analytics tool, not a PII vault.

Compliance & standards

  • GDPR-aligned data processing with Standard Contractual Clauses available on request
  • CCPA-compliant data handling for California residents
  • Data Processing Agreements (DPAs) available for enterprise customers
  • We support your right to access, rectify, and erase personal data within 30 days of request
  • Security incident notification within 72 hours of confirmed breach, per GDPR requirements

Incident response

  • Dedicated security monitoring with anomaly detection on authentication and data access
  • Formal incident response process with defined escalation paths
  • Customers notified within 72 hours of any confirmed data breach affecting their organization
  • Post-incident reviews conducted and findings shared with affected customers

Our ongoing commitment

Security is not a checkbox, it's a continuous process. We review our controls regularly as the threat landscape evolves.

  • Regular internal security reviews and access audits
  • Dependencies and infrastructure kept up-to-date with security patches
  • Security considerations are part of every new feature review

Questions about our security practices?

We're happy to provide a Data Processing Agreement, answer specific compliance questions, or walk you through our architecture.

security@statquestions.com