10 protections built into the platform, each with what it does not cover. The technical detail is on the Security and AI governance pages; if you answer surveys for your employer, start with Employee data ethics.
AI requests do not carry who you are
Before a request goes to an AI model, the names of your company, workspace and the people the platform knows about, file names, your own sensitive terms, and detected email addresses, web addresses, phone numbers, account numbers and record IDs are swapped for placeholders. The real values are put back only inside Transformics.
What it does not cover. This is pseudonymization, not anonymization. People the platform was never told about, and the content itself, can still point to an organization. Checking the live AWS account is still pending.
You control what AI reads
Administrators can switch off AI reading of uploaded documents and AI analysis of survey free text, and can add their own list of sensitive terms that are always replaced.
What it does not cover. Turning a switch off stops new AI processing of that kind. Evidence that was already extracted stays until you delete it.
Sensitive answers are locked per organization
Survey free-text answers, uploaded evidence files and your sensitive-terms list are encrypted with a key that belongs to your organization alone. Deleting the organization destroys that key. Integration tokens and webhook secrets are sealed separately.
What it does not cover. The key is protected by an application master key today; a managed key service is a later step. Backups keep the encrypted data and the wrapped key for the 30-day recovery window.
Small groups stay hidden
Department, level and function breakdowns are shown only for groups of five or more people. A smaller group is hidden, and the remaining groups are checked so a hidden group cannot be worked out by subtraction.
What it does not cover. This hides small groups in what is displayed; stored scores and the overall score do not change. Every results page that shows these breakdowns also says they are not for judging individuals.
Consent comes first
A survey answer is not saved until the respondent's consent has been recorded. If consent cannot be recorded, the answer is not accepted.
What it does not cover. Consent is recorded for the survey being answered; it does not extend to other uses of the data.
Access, export and erasure that complete
Requests to access, export or erase personal data are tracked from start to finish. Erasure also covers free-text answers, stored quotes and survey links. Export links expire after 72 hours and are logged. A trial workspace that never becomes a subscription is deleted 90 days after the trial ends, and deleting an organization also removes its stored files.
What it does not cover. Interview transcripts record a stakeholder by name rather than by email address, so they are handled on request. Aggregated scores remain in anonymized form, and backups age out over the 30-day recovery window.
A person decides
An assessment report whose evidence is weak, or could not be measured, is held until an administrator other than the person who ran the assessment approves it. Where governed agent actions are enabled, the person who ran the agent cannot approve its proposals, a proposal expires after 14 days, and nothing is applied until a person approves it.
What it does not cover. No setting yet requires review of every report; reports that pass the check are delivered without manual sign-off. Governed agent actions are a Business and Enterprise capability that is off by default.
Locked down at the database
Every table is protected by row-level security, and an automated check fails the build when a table is added without it. Sensitive tables and storage buckets are closed to direct client access, and outside collaborators can only read.
What it does not cover. The application reaches the database with a service key, so separation between organizations is also enforced in application code on every request; row-level security is a second layer, not the only one.
Documents are screened before they are read
Uploaded PDFs are checked for text a person cannot see, such as invisible or white text, and are rejected if they contain it. This closes one common way of slipping hidden instructions to the AI.
What it does not cover. This is one layer among several, alongside verbatim excerpt matching and review of high-impact claims, and not a complete defence.
AI summaries are checked against your scores
The scores cited in an AI-written executive summary are compared with your own results, and a reference the data does not support is removed before you see it.
What it does not cover. The check covers score references in executive views and module names in cross-module insights; it does not judge the quality of the writing.