CCandorKit

Evaluate secure survey software

A secure survey is a chain of controls, not a badge. Evaluate the fields collected, every person and system with access, every exported copy, and the consequence of failure.

1

Translate secure into controls

“Secure” is incomplete unless the vendor explains what is protected, from whom, and by which operational controls. Transport encryption matters, but so do authentication, owner access, staff privileges, logs, backups, deletion, and incident response.

Ask for current documentation that matches the exact product tier and deployment you will use. A certification, marketing badge, or parent-company policy may not cover every feature or data flow.

  • How are owner credentials protected?
  • Is staff access role-based and logged?
  • Which subprocessors handle content?
  • What is the incident notice process?
2

Inspect collection and copies

List every field that can identify a respondent, including invitation tokens, account ids, IP addresses, cookies, device data, and answer combinations. Decide which are necessary for the task and disable the rest.

Follow responses beyond the live database. Exports, email notifications, integrations, backups, support systems, and analytics can each create another copy with a separate access and deletion boundary.

3

Match assurance to risk

CandorKit uses a separate owner secret, stores only its hash, omits identity fields by default, and applies a seven-day expiry. It does not provide user accounts, role-based access, enterprise audit logs, formal compliance claims, or protected reporting workflows.

That boundary can suit short, low-consequence feedback. For regulated, legal, medical, safety-critical, or highly sensitive tasks, use software and organizational procedures that are independently reviewed for the applicable requirements.

Put the boundary in the invitation

Tell respondents what is stored, what is not, who can read it, and when it disappears.

Create a bounded survey