How it works

Your organization already has the names and contact information. We never have access to them.

SafePorter separates the system that knows who was invited from the system that receives what people say.

Respondents names & answers SafePorter stores under a code, suppresses small groups, aggregates Organization safe aggregates identity never crosses to the right

Your organization holds names and email addresses on infrastructure it controls and sends the invitation. The respondent answers using a code. SafePorter receives the response without the person's name or email address. Your organization receives aggregate results rather than individual responses. The identity and the answer are deliberately kept apart.

  1. You invite

    Software runs on your own infrastructure, inside your network, holding the names and email addresses in a local database. It generates a code for each person and sends the invitation through your own mail server.

    SafePorter has no access to the names, the addresses, or the mail server.
  2. They answer

    They open a separate portal, entering your organization's key and their code rather than a name or an email address. They answer what they choose to answer.

    No account, no password, no profile.
  3. SafePorter protects the response

    Responses are stored under a value derived from that code using a secret held separately from the data. Raw answers are kept in the respondent's own region.

    The organization has no access to individual responses at any point.
  4. You see the pattern

    Results are assembled and published to your dashboard as aggregated percentages, with groups too small to report safely withheld before anything reaches you.

    Dashboards show a published snapshot rather than a live feed, so a person joining or leaving never opens a visible gap.

Two design decisions worth understanding

Both look like constraints. Both are the reason the promise holds.

The software runs on your infrastructure

Most vendors would rather host everything: it is simpler to sell and simpler to run. Holding your people's names and addresses on our servers would also make the central claim of this page impossible.

So the component that holds identity runs where you already run things, under your access controls, with no inbound ports open to us.

Dashboards are published, not live

A live dashboard leaks. If results updated the instant someone answered, deleted their data or left, the change itself would point at a person.

Publishing a snapshot instead means the trend survives while the individual stays invisible.

What each side can see

 Your organizationSafePorter
Names and email addressesYes, on your own systemsNo access, at any point
Individual responsesNo accessHeld under a code, never with a name
Aggregated percentagesYes, in your dashboardYes
Results for very small groupsWithheldWithheld before publication

How small groups are protected →