Trust & security

What SafePorter can help your organization see. And what it can never access.

The clearer the boundary, the more candid the answers. Here is exactly what your organization can access, and what SafePorter never can.

What each party can access

InformationYour organizationSafePorter
Names and email addressesHeld on your systemsNo access
Individual responsesNo accessHeld without names or email addresses
Aggregate resultsYesYes
Results for groups below the disclosure thresholdWithheldWithheld before publication

Certifications and recognition

Certified B Corporation

Independently verified by B Lab.

PICCASO EU Privacy Award, 2023

ESG Privacy Initiative.

Vulnerability disclosure policy

Published, with an explicit safe harbour for good-faith security research.

Architecture and data handling

Deployment model

On-premises client software you run, plus a hosted service that receives answers and publishes aggregated percentages.

Identity

Names and email addresses are held only by your own systems. SafePorter has no access to either.

Data residency

Raw answers are held in the respondent's own region, in systems separate from other regions.

Disclosure controls

Results below the reporting threshold are withheld before they reach a dashboard.

Automated decision-making

None. SafePorter makes no automated decisions about any individual.

Website tracking

SafePorter's public websites do not use cookies for behavioral tracking, do not run advertising technology, and do not track people across sites. Analysis of submitted feedback is part of the product; behavioral tracking of website visitors is a different question.

Documents

What a procurement team asks for, in one place, so nobody has to email for it.

Privacy notice

Layered by relationship: survey participants, admin users, clients, suppliers and website visitors. Read it →

Vulnerability disclosure

Published policy with a safe harbour for good-faith research. Read it →