Your research is your competitive edge. We protect it.
Market research reveals your strategy, pricing, and positioning. We built AudiAInce® knowing that your data is as sensitive as it gets.
Account Scoping
Current assurance status
AudiAInce® is not currently presented as SOC 2 certified; its Type II program is in progress. Customer records use logical account and tenant controls within shared application systems. Requested features may send relevant product, audience, survey, and research content to the AI providers identified below. Provider processing and retention depend on the applicable service, configuration, and terms.
Understand how your data is used.
Brand Memory is yours alone
Brand Memory content and account-level research are scoped through account and tenant access controls in shared application systems.
Aggregated outcome metrics
Eligible outcome records may be combined across accounts to calculate aggregate performance and calibration metrics. Account-level content and results are not displayed publicly. Review the privacy notice for current details and available controls.
Your edge remains your edge
Your account-level research and reports are not displayed to other customers. Aggregate metrics do not expose account-level content or results.
How third-party AI providers process requests
AudiAInce® sends the context needed to perform requested AI tasks. Provider terms, retention, and processing controls vary by service and configuration.
Anthropic
Processes persona responses and analysis under the API terms and account settings applicable at the time of use.
- API processing terms apply
- Review current provider assurance documentation
OpenAI
Provides additional model options for specific research tasks under the applicable API terms and account settings.
- API processing terms apply
- Review current provider assurance documentation
Google Gemini
Provides additional model capabilities under the API terms and account settings applicable at the time of use.
- API processing terms apply
- ISO 27001 certified
Perplexity
Supports reference searches and may receive relevant product name, description, audience, category, and research context.
- Relevant query context may be sent
- Review content before submission
Relevant product descriptions, audience information, survey content, and other task context may be sent to third-party AI providers to generate requested results. Do not submit information you are not authorized to share.
Security controls and infrastructure
Built on cloud infrastructure with documented application and platform security controls.
Encryption at rest
Supported storage services use encryption controls according to their current configuration. Contact us for the current system scope.
Encryption in transit
HTTPS is enforced for public application endpoints. Service-specific transport controls vary by system and provider.
Isolated environments
Customer records use account- and tenant-scoped access controls within shared application systems.
Regular backups
Backup coverage, recovery windows, and encryption depend on the current service configuration. Contact us for documented scope and restore-test status.
Monitoring & alerting
Automated infrastructure monitoring and alerts cover configured anomalies and security events.
Secure development
Our development process includes code review and dependency-vulnerability scanning. Contact us for the current control scope.
Defense-in-depth application security
Multiple layers of protection built into every request, from authentication to audit logging.
CSRF Protection
Cryptographically secure tokens protect against cross-site request forgery. Single-use tokens invalidated after each request.
Rate Limiting
Intelligent rate limiting on all endpoints. Stricter limits on authentication endpoints to prevent brute force attacks.
Security Headers
Content Security Policy, HSTS, X-Frame-Options, and other headers help reduce XSS, clickjacking, and injection risk.
Session Security
30-minute inactivity timeout with automatic session invalidation. Sessions tied to device fingerprints.
Security Alerts
Email notifications for failed login attempts, password changes, new device logins, and suspicious activity.
Password History
Prevents password reuse by tracking previous passwords. Configurable password expiration policies.
Verified security posture
Automated and external tools can provide signals about configured security controls. They do not constitute an independent compliance certification.
Continuous Scanning
Access controls for teams
Control access and review supported administrative and security events.
Audit Log
Sample data — simulated persona panel
Tamper-evident audit logs
Supported audit events include timestamps, user attribution, and integrity metadata. Chain verification can help detect changes when the log is checked.
- Checksums on supported audit entries
- Chain-linked integrity verification
- Before/after state capture for supported changes
- Export to XLSX, CSV for compliance
- Retention defined by data class and current policy
SSO Integration
SAML 2.0 single sign-on for enterprise identity providers. Okta, Azure AD, Google Workspace supported.
Multi-Factor Authentication
Enforce MFA across your organization. Support for authenticator apps and hardware security keys.
Role-Based Access Control
20+ granular permissions across 5 categories. Super Admin, Admin, User, and Read-Only roles out of the box.
Terms of Service Tracking
Track ToS acceptance by version. Automatic prompts when terms are updated. Complete acceptance audit trail.
Built with compliance in mind
Our platform is designed to support your regulatory requirements.
GDPR
Designed to support GDPR requirements including data minimization, right to access, right to erasure, and data portability.
CCPA
Built with CCPA principles in mind. Support for do-not-sell requests, disclosure requirements, and deletion rights.
SOC 2
Controls aligned with SOC 2 Trust Services Criteria including audit logging, access controls, rate limiting, and session management. Type II certification in progress.
Data-Processing Terms
Contact us to review currently available data-processing terms, subprocessors, and transfer safeguards for your use case.
Compliance is an ongoing process. Contact us for detailed documentation on specific requirements.
You control your data lifecycle
Retention
Retention varies by data class, account configuration, legal requirements, and backup lifecycle. Contact us for the current retention schedule.
Deletion
You may request account-data deletion. Requests are processed under the applicable data-class retention schedule, while protected backup copies expire through their normal lifecycle.
Export
Export all your data in standard formats. Survey results, brand profiles, and analysis available as JSON, CSV, or PDF.
Questions about security?
Our team can discuss current security controls, subprocessors, retention practices, and available enterprise documentation for your requirements.
To report a vulnerability, please use our contact form. We appreciate responsible disclosure and respond within 24 hours.