Security

Security & Data Protection

We understand that data is a responsibility. That is why security is built into every layer of SurveyNinja — from infrastructure to interface.

GDPR compliant
TLS 1.3 encryption
99.9% uptime
AES-256 at-rest

Data Storage

All SurveyNinja data is stored on servers located in certified Tier III data centers across the EU and US, depending on your region preference.

This ensures compliance with international data residency requirements and allows enterprises, regulated industries, and government-adjacent organisations to use SurveyNinja without restrictions.

  • Tier III data centers with full redundancy
  • Geographic replication for high availability
  • Physical security: access control, video surveillance
  • Regular infrastructure audits
EU GDPR compliant Tier III data centers EU / US geo-distributed SOC 2 audited

Encryption & Protection

Encryption in transit

All data between the browser and server is transmitted via HTTPS using TLS 1.3. Interception by third parties is impossible.

Encryption at rest

Data on disk is encrypted with AES-256. Even with physical access to the server, your information remains protected.

Audit logs

All user actions are logged. You can always track who made changes, when, and to which surveys or settings.

Access Control

Role-based access

Flexible permissions management: admin, editor, viewer. Each team member sees only what they are permitted to access.

Single Sign-On (SSO)

Supports single sign-on via corporate identity providers. Secure authentication without extra passwords (Premium plan).

Two-factor authentication

An extra layer of account protection. Even if a password is compromised, your data remains safe.

Session control

See who accessed your account and what actions were performed. Full login history and active session management.

Backup & Recovery

Automatic backups of all data are performed daily. Backups are stored in a geographically separate data center to protect against disasters.

  • Daily automatic backups
  • Backups stored in a separate, geographically remote data center
  • Point-in-time restore available on request
  • Survey versioning (automatic form snapshots)
DC1 EU DC2 Backup Replication Versions Today −1 day −2 days −7 days history... 1-click restore Daily auto-backups Geo-replication backup DC Versioning of surveys

Compliance & Certifications

GDPR

Full compliance with the General Data Protection Regulation. Personal data is processed and stored in accordance with EU privacy law requirements.

SOC 2

SurveyNinja follows SOC 2 principles covering security, availability, and confidentiality. Security audits are conducted regularly to maintain compliance.

ISO 27001

Our information security management practices align with ISO 27001 standards, ensuring a systematic approach to managing sensitive company and customer information.

On-Premise Option for Maximum Security

For organizations with the highest security requirements, SurveyNinja is available as an on-premise deployment. The platform is installed on your own servers — data never leaves your perimeter.

  • Complete data isolation within your infrastructure
  • Works without internet access (air-gapped mode)
  • Supports Linux, Windows, and Docker deployments
  • Deploy behind your own firewall
Learn about On-Premise
Firewall Your isolated perimeter No internet Linux / Docker On-Premise your server Full data isolation Air-gapped isolated mode

Frequently Asked Questions about Security

Still have questions about security?

Our team is ready to discuss your security requirements, provide NDA documentation, and answer questions from your IT department.