An anonymous suggestion box the platform can't read.
Most digital suggestion boxes store submissions as plain text next to a timestamp and an account. InviziPoll encrypts each submission in the browser before it is uploaded. We store ciphertext only - so there is no readable backlog for anyone to search, subpoena, or leak. A suggestion box only works if people believe that.
Illustrative admin dashboard: aggregate recommendation percentages above, individual response rows shown as ciphertext only below.
sealed before it reaches usEveryone can speak up. No one is singled out.
Are submissions really unreadable?
Yes, by design. Poll responses are encrypted client-side; our servers persist ciphertext, not plaintext answers. Workspace admins decrypt aggregate analytics in authorized clients. For the full encryption model, see Security & encryption.
Evaluating another tool? Not sure if your survey is anonymous? Here's how to tell. For the confidential vs anonymous distinction, see our definition guide.
Feature snapshot
Built for candour, not for a shared inbox.
InviziPoll vs a typical digital suggestion box or shared feedback form.
Ciphertext only - encrypted in the respondent browser before upload.
Often server-readable plaintext or optional anonymity modes - verify each vendor's architecture.
Aggregate analytics in authorized clients; no per-response timelines on admin surfaces.
May include per-response views, export trails, or moderation dashboards depending on plan.
Post-quantum-capable hybrid designs (X-Wing KEM + ML-DSA-65) documented on /security.
TLS in transit is standard; end-to-end encryption for survey payloads varies widely.
Zero respondent telemetry on ballot flows - marketing analytics are separate.
May include session analytics, device fingerprints, or third-party trackers on survey pages.
What teams use it for
Anywhere someone hesitates before hitting send.
Ideas & process improvements
Safety and near-miss reports
Manager and leadership feedback
Anonymous questions for all-hands
Common questions
Common questions
Is an online anonymous suggestion box really anonymous?
It depends entirely on what the tool stores. Most digital suggestion boxes keep submissions as readable text alongside a timestamp, an IP address, or the account that submitted them. InviziPoll encrypts each submission in the browser before upload, so the server holds ciphertext and there is no plaintext record to look up.
How is this different from a shared inbox or a form?
A shared inbox or a standard form gives whoever administers it the ability to read every submission and, usually, to see who sent it. That is confidential, not anonymous. Here the submission is unreadable to the platform, and admins work from aggregates and released text rather than an identifiable feed.
Can we still act on individual suggestions?
Yes. Admins decrypt in their own browser and can publish a response without ever learning who submitted. The you-said-we-did flow is designed for exactly this: close the loop publicly so people can see that submitting was worth it.
What stops a small team from being identified?
Minimum group thresholds. Results and free text stay suppressed until enough people have responded, with a hard floor of three. On a small team that threshold matters more than the encryption, because a distinctive story identifies someone even when the record does not.
Do employees need an account to submit?
No. Respondents open a signed link with no login, no cookies, no IP logging, and no browser fingerprinting. Anonymity that requires trusting a login prompt is the thing employees are usually suspicious of.
Open a suggestion box people will actually use.
Workspace in under two minutes. No credit card, no submitter tracking, no plaintext suggestions on our servers.