Small groups

No one can be singled out, even in a small group.

Removing names is not enough to protect a respondent when the reader already knows the population.

An employer may know who works in a particular office, function, team or tenure band. Combine enough of those characteristics and an apparently aggregate result can describe only a handful of people, or one. That is the real risk SafePorter is built to remove, not just the obvious identifiers.

How SafePorter protects them

A few protections keep results accurate and useful while making sure no result can point to one person.

SafePorter never holds identity

Names and email addresses stay on your own systems. SafePorter receives responses tied only to a one-way code it cannot reverse, so there is no identity on our side to expose in the first place.

Small and rare responses are rolled up

Responses from small or rare groups are combined and rolled up into broader categories, not discarded, so the insight stays accurate while no single person ever stands behind a number.

No combined or intersectional breakdowns

Even aggregated demographic results can identify people when they are combined across office, region, role and tenure. SafePorter does not report those combinations, which is where re-identification actually happens.

Patterns, not head counts

Results are shown as percentages and patterns, not individual records, so you cannot work back to any one person who answered.

How this applies to demographic data →