Skip to main content
Security & architectureSecurity reviewersReviewed by Security

Threat model

Heads up: This page lists what we design for (DB leak, insider, small n , access codes) and honest limits . For the behavior spec, see Zero-knowledge…

1 MIN READUPDATED AUG 17, 2026MAINTAINED BY SECURITY
On this page

InviziPoll is designed for respondent anonymity and confidentiality by design: the platform cannot read plaintext answers or access admin key material without secrets that stay on the client or with trusted admins.

What the architecture protects against

ThreatHow we address it
Database breachEncrypted blobs; no service plaintext
Insider access to sensitive dataOps role cannot read ciphertext/keys
Small-group deanonymizationLocked until 3+; cohorts need 5+
Linking access codes to responsesNo reversible link to submissions stored
Ordering inferenceCiphertext returned in random order
Manager sees more than their teamSnapshot links, never the poll key
Answers sent to an AI providerSummaries run in the admin's browser

What we do not claim to prevent

LimitationNotes
Compromised admin deviceUnlocked admin sees decrypted views
Weak backup passwordsLow-entropy passwords remain guessable
Social engineeringUsers may share backup secrets
Server-assisted checksEligibility checks; no answer decrypt
AvailabilityOutages do not imply breach
Self-identifying free textContent can identify its writer
Small on-device modelMay restate one person; read as a draft