Trust center

Your research data is your competitive edge. Here is exactly how we protect it: the architecture, the policies, and the parts we're still building. No black boxes.

Encrypted in transit & at rest GDPR & CCPA operations built in Participants anonymous by default 99.9% uptime SLA

How we earn your trust

Six areas, each documented in plain language. Click through for the full detail.

≤ 1 hr
Recovery point objective: backups run hourly
1–3 hrs
Recovery time objective, documented & rehearsable
99.9%
Uptime SLA for Team & Enterprise, with credits
0
Advertising or tracking cookies on participant surveys

Security controls

The measures below are shipped and running today, and expanded in the security overview.

Row-level securityThe database itself refuses cross-tenant reads, so isolation never depends on app code
Encryption in transit & at restTLS everywhere with two-year HSTS; encrypted databases and backups
Two-factor administrationPlatform admin console requires TOTP 2FA and is invisible to everyone else
Enforcing CSP & security headersContent-Security-Policy, HSTS, frame and referrer protections on every response
Bot & abuse protectionTurnstile challenges on signup and participant entry, plus rate limiting
Breached-password screeningNew passwords are checked against the Have I Been Pwned corpus
Hourly independent backupsEncrypted, stored with a separate provider from the database, restore-verified
Live monitoringPublic status page, health endpoint, weekly full-stack canary, RLS integrity checks
No card data on our systemsPayments handled end-to-end by Stripe with signature-verified webhooks

Sub-processors

Every third party that touches personal data, and why. We give 30 days' notice before any change. Details on the sub-processors page.

ProviderPurposeLocation
SupabaseDatabase, authentication, hostingUS
VercelApplication hosting and deliveryUS
AnthropicPowers the Graham AI assistant, with no training on your dataUS
StripePayment processing; card numbers never touch our systemsUS
ResendTransactional and support emailUS
CloudflareBot protection and encrypted off-site backup storageUS
PureSpectrumOptional panel recruitment; receives session outcomes only, never identitiesUS

EEA/UK/Swiss transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

Documents

The commitments behind this page are contractual, not decorative.

Where we are on certifications

We don't yet hold SOC 2 or ISO 27001, and we won't put a badge here until we do. An independent penetration test is planned as part of our commercial launch, and SSO/SAML for Enterprise is on the roadmap. In the meantime, everything above is verifiable: our security commitments are written into the DPA and SLA, and Enterprise customers can request deeper documentation at sales@sortedresearch.com.

Common questions

Who owns the research data I collect?
You do. Your studies, responses, and results are your data. We process participant study data only on your instructions as a processor under the DPA, and you can export everything at any time.
Is my data used to train AI models?
No. Graham is powered by Anthropic's Claude via API, and under Anthropic's commercial terms API inputs and outputs are not used to train models. More in Responsible AI.
Are you GDPR compliant?
We support GDPR compliance as a processor: a DPA with SCCs and the UK Addendum, participant anonymity by default, per-participant data-access exports, full portability exports, deletion with a 30-day grace period, breach notification commitments, and a published retention schedule. As the controller of your participant data, your own lawful basis and notices remain your responsibility. See Data protection.
Where is data stored?
In the United States, with the vendors on our sub-processor list. EEA/UK/Swiss transfers are protected by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
What happens to my data if I cancel?
You get a 30-day grace period to export everything, after which your data is permanently and automatically purged. On request we will delete or return participant data per the DPA.
Do participants have to hand over personal details?
No. Participants are anonymous by default: no names, no emails. The platform only collects identifying details if a researcher deliberately adds a screener question asking for them, and that choice is the researcher's responsibility as controller.
Do you have SOC 2 or ISO 27001?
Not yet, and we say so plainly above. Our security program is documented in the security overview and contractually committed in the DPA; formal certification is on our roadmap as the business grows.
How do I report a security vulnerability?
Email security@sortedresearch.com. Our responsible disclosure policy covers scope, response times, and safe harbor for good-faith research.

Security review coming up?

We're happy to walk your security, legal, or procurement team through the platform, complete questionnaires, and provide a countersigned DPA.