Skip to main content
Security

Your research is your competitive edge. We protect it.

Market research reveals your strategy, pricing, and positioning. We built AudiAInce® knowing that your data is as sensitive as it gets.

Account Scoping

Edge request filtering
Encrypted transport
Identity and access controls

Current assurance status

AudiAInce® is not currently presented as SOC 2 certified; its Type II program is in progress. Customer records use logical account and tenant controls within shared application systems. Requested features may send relevant product, audience, survey, and research content to the AI providers identified below. Provider processing and retention depend on the applicable service, configuration, and terms.

Understand how your data is used.

Brand Memory is yours alone

Brand Memory content and account-level research are scoped through account and tenant access controls in shared application systems.

Aggregated outcome metrics

Eligible outcome records may be combined across accounts to calculate aggregate performance and calibration metrics. Account-level content and results are not displayed publicly. Review the privacy notice for current details and available controls.

Your edge remains your edge

Your account-level research and reports are not displayed to other customers. Aggregate metrics do not expose account-level content or results.

How third-party AI providers process requests

AudiAInce® sends the context needed to perform requested AI tasks. Provider terms, retention, and processing controls vary by service and configuration.

Anthropic

Processes persona responses and analysis under the API terms and account settings applicable at the time of use.

  • API processing terms apply
  • Review current provider assurance documentation
Privacy Policy

OpenAI

Provides additional model options for specific research tasks under the applicable API terms and account settings.

  • API processing terms apply
  • Review current provider assurance documentation
Privacy Policy

Google Gemini

Provides additional model capabilities under the API terms and account settings applicable at the time of use.

  • API processing terms apply
  • ISO 27001 certified
Privacy Policy

Perplexity

Supports reference searches and may receive relevant product name, description, audience, category, and research context.

  • Relevant query context may be sent
  • Review content before submission
Privacy Policy

Relevant product descriptions, audience information, survey content, and other task context may be sent to third-party AI providers to generate requested results. Do not submit information you are not authorized to share.

Security controls and infrastructure

Built on cloud infrastructure with documented application and platform security controls.

Encryption at rest

Supported storage services use encryption controls according to their current configuration. Contact us for the current system scope.

Encryption in transit

HTTPS is enforced for public application endpoints. Service-specific transport controls vary by system and provider.

Isolated environments

Customer records use account- and tenant-scoped access controls within shared application systems.

Regular backups

Backup coverage, recovery windows, and encryption depend on the current service configuration. Contact us for documented scope and restore-test status.

Monitoring & alerting

Automated infrastructure monitoring and alerts cover configured anomalies and security events.

Secure development

Our development process includes code review and dependency-vulnerability scanning. Contact us for the current control scope.

Defense-in-depth application security

Multiple layers of protection built into every request, from authentication to audit logging.

CSRF Protection

Cryptographically secure tokens protect against cross-site request forgery. Single-use tokens invalidated after each request.

Rate Limiting

Intelligent rate limiting on all endpoints. Stricter limits on authentication endpoints to prevent brute force attacks.

Security Headers

Content Security Policy, HSTS, X-Frame-Options, and other headers help reduce XSS, clickjacking, and injection risk.

Session Security

30-minute inactivity timeout with automatic session invalidation. Sessions tied to device fingerprints.

Security Alerts

Email notifications for failed login attempts, password changes, new device logins, and suspicious activity.

Password History

Prevents password reuse by tracking previous passwords. Configurable password expiration policies.

Verified security posture

Automated and external tools can provide signals about configured security controls. They do not constitute an independent compliance certification.

SecurityScorecard continuous external scanning
SSL Labs TLS configuration grading
Mozilla Observatory HTTP security headers

Continuous Scanning

OWASP ASVS checks
Security header review
Continuous control monitoring

Access controls for teams

Control access and review supported administrative and security events.

Audit Log

Sample data — simulated persona panel

Tamper-evident audit logs

Supported audit events include timestamps, user attribution, and integrity metadata. Chain verification can help detect changes when the log is checked.

  • Checksums on supported audit entries
  • Chain-linked integrity verification
  • Before/after state capture for supported changes
  • Export to XLSX, CSV for compliance
  • Retention defined by data class and current policy

SSO Integration

SAML 2.0 single sign-on for enterprise identity providers. Okta, Azure AD, Google Workspace supported.

Multi-Factor Authentication

Enforce MFA across your organization. Support for authenticator apps and hardware security keys.

Role-Based Access Control

20+ granular permissions across 5 categories. Super Admin, Admin, User, and Read-Only roles out of the box.

Terms of Service Tracking

Track ToS acceptance by version. Automatic prompts when terms are updated. Complete acceptance audit trail.

Built with compliance in mind

Our platform is designed to support your regulatory requirements.

1

GDPR

Designed to support GDPR requirements including data minimization, right to access, right to erasure, and data portability.

2

CCPA

Built with CCPA principles in mind. Support for do-not-sell requests, disclosure requirements, and deletion rights.

3

SOC 2

Controls aligned with SOC 2 Trust Services Criteria including audit logging, access controls, rate limiting, and session management. Type II certification in progress.

4

Data-Processing Terms

Contact us to review currently available data-processing terms, subprocessors, and transfer safeguards for your use case.

Compliance is an ongoing process. Contact us for detailed documentation on specific requirements.

You control your data lifecycle

Retention

Retention varies by data class, account configuration, legal requirements, and backup lifecycle. Contact us for the current retention schedule.

Deletion

You may request account-data deletion. Requests are processed under the applicable data-class retention schedule, while protected backup copies expire through their normal lifecycle.

Export

Export all your data in standard formats. Survey results, brand profiles, and analysis available as JSON, CSV, or PDF.

Questions about security?

Our team can discuss current security controls, subprocessors, retention practices, and available enterprise documentation for your requirements.

To report a vulnerability, please use our contact form. We appreciate responsible disclosure and respond within 24 hours.