No badges. A verifiable design instead.
InviziPoll does not currently hold SOC 2, ISO 27001, or a published third-party pen-test. Rather than imply otherwise, this page gives you the thing certifications summarize: the actual architecture, threat model, and data-handling facts, specific enough to check our claims against the design.
Everything here is written to be pasted into a vendor assessment. If a question isn't answered, and we'll answer it in writing.
What we claim
- Responses are encrypted client-side; servers persist ciphertext only
- Decryption keys are generated and held by the customer
- Respondent identity, IP, and device are never persisted on ballot/respondent flows
What we don't claim
- Certifications we haven't earned (no SOC 2 or ISO badge yet)
- "Zero risk" (residual risks are listed below, not hidden)
- That cryptography fixes bad questionnaire design (it can't)