Security

Last Updated: June 14th, 2024

Security is built into the fabric of our products, team, infrastructure, and processes, so you can rest assured your data is safeguarded.

Compliance

SOC 2 Type I

Iterate is SOC 2 Type I compliant. We have undergone a rigorous audit of our internal controls related to security, availability, processing integrity, confidentiality, and privacy. This audit confirms that we have effective controls in place to safeguard clients‘ data and maintain the availability and security of our services. Report available upon request.

SOC 2 Type II

Iterate is proud to announce that we have achieved SOC 2 Type II compliance. Our commitment to data security, availability, processing integrity, confidentiality, and privacy is validated by a thorough and ongoing audit. This comprehensive assessment assures our clients that we maintain robust controls, not only for safeguarding data but also for consistently delivering secure and available services. For a detailed report of our SOC 2 Type II compliance, please feel free to request it.

GDPR

We are committed to the principles inherent to the GDPR and particularly the concepts of privacy by design, the right to be forgotten, and data consent. Iterate customers are in complete control of what user data they collect based on the questions they choose to ask. We provide tools for customers to delete their data as well as customer data, and provide APIs to automate this process. Iterate complies with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce.

View certification

HIPAA

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created guidelines and rules to make sure that healthcare data is protected under US law. Iterate is HIPAA complaint. Iterate‘s data protection standards maintain appropriate safeguards to provide the continued security of protected health information collected through our products.

CCPA / CPRA

For Iterate customers, Iterate is a “service provider” under the CCPA. We process personal information only on behalf of our customers. The personal information that‘s collected is in complete control of the customer, based on what questions they choose to ask. We collect and store that data only for the purpose of providing our services to the customer and we do not sell that information to third parties.

Swiss-US Privacy Shield

Iterate is self-certified under the US & Swiss privacy shield frameworks.

Product Security

Role-Based Access Control (RBAC)

SSO

Single Sign-On (SSO) enables customers’ team members to access Iterate using their existing credentials from their Identify Provider (IdP).

View instructions

Data Security

Data Encrypted At-Rest

All user data is encrypted at rest.

Data Encrypted In-Transit

All user data is encrypted via HTTPS/TLS.

Passwords Encrypted

Customer passwords are encrypted using bcrypt and include a per-user salt.

Privacy

Privacy Policy

View policy

Data Retention Policy

Customer data is stored indefinitely so survey responses can be seen for all historical responses. All data can be requested to be deleted by the customer at any time. We have APIs available to automate customer data deletion in response to CCPA or GDPR requests. Database backups are retained for 30 days and application logs are for 14 days.

Incident Management & Response

Data Breach Notification

Incident Response Plan (IRP)

Availability & Reliability

Data Redundancy

Data is stored across a cluster of servers ensuring high availability and uptime.

Infrastructure Redundancy

Application servers are dynamically added based on load and constantly monitored and replaced in the event of a loss of availability.

Organizational Security

Employee Background Checks

All full-time employees are subject to background checks.

Employee Security Training

Security is built into our engineering process from the start. All full-time employees are trained on our privacy and security best-practices, all code is peer-reviewed and audited to ensure it is secure and we‘re constantly monitoring for new risk mitigation strategies.

Employee Workstations Automatically Locked

Employee Workstations Encrypted

All employee workstations are password protected and enabled with disk encryption.

Limited Employee Access (Principle of Least Privilege)

Employee access is limited to the minimum amount of access needed to perform their job.

Physical Access Control

Business Continuity

Business Continuity Plan

Data Backups

All user data is backed up and retained for 30 days.

Infrastructure Security

Multi-Tenant Architecture

Threat Management

Bug Bounty

Iterate offers financial compensation for self-reported bug and vulnerability reports subject to the discretion of our security team based on the severity of the issue.

AI & Machine Learning

Customer Data Is Never Used for Model Training

Iterate does not use customer data, including survey responses, to train, fine-tune, or otherwise improve any AI or ML model, our own or a third party’s.

AI Processing Stays Within Our AWS Environment

Research Assistant, our umbrella for Iterate’s AI capabilities, runs on Anthropic’s Claude models accessed through Amazon Bedrock inside our existing AWS environment (us-east-1, United States). Calls are inference only and response data is not sent to Anthropic directly. Per AWS, content submitted to Amazon Bedrock is not used to improve the base models and is not shared with any model provider.

Features Covered

Research Assistant covers sentiment scoring, topic and theme extraction, translation, report generation and summarization, trend and trajectory analysis, and follow-up question suggestions.

Subprocessors

SubprocessorPurposeLocation
Amazon Web ServicesApplication hosting, data storageUSA
AnthropicAI processingUSA
Google AnalyticsUser analyticsUSA
MongoDBDatabase hostingUSA
SentryError monitoringUSA
SingleStoreAnalytics databaseUSA

Don’t see what you are looking for?

Let us know how we can help