Security Statement

Effective date: September 4, 2026

It is extremely important for us to protect your information and your customers' information. We know you have questions about how we protect this information, so details about some frequently requested information about the information security of PaperSurvey are provided below.

Data Centers

We store our data and databases in datacenters in the European Union, and encrypted backup copies are held in additional EU datacenters with more than one independent storage provider. The providers we use are named in our Technical and Organizational Measures and in the sub-processor list in our privacy policy.

Our hosting providers operate from established datacenter facilities with physical security and environmental controls that protect the infrastructure from physical threat. Each site is staffed 24/7/365 with on-site physical security against unauthorized entry, and the operators hold ISO 27001 certification.

Development

Our development team uses secure coding techniques and best practices focused on the top ten OWASP. Developers are formally trained in secure web application development methods.

Development, testing, and production environments are separated. All changes are peer reviewed and logged for performance, audit, and forensic purposes prior to deployment into the production environment.

Encryption

We encrypt your data in transit using secure TLS 1.2+ cryptographic protocols. All data is also encrypted at rest, including uploaded files, survey responses, and backups.

Authentication Security

We support multiple authentication methods to protect your account:

  • Two-factor authentication (2FA): TOTP-based authentication with recovery codes. Team administrators can enforce 2FA for all team members.
  • Passkeys (WebAuthn/FIDO2): Passwordless login using hardware security keys, biometrics, or device authenticators.
  • SAML 2.0 SSO: Single Sign-On is available for Enterprise Plus customers on annual billing, enabling integration with your organization's existing identity provider.
  • Session security: All active sessions are invalidated immediately upon password change. A short grace period after login reduces unnecessary re-authentication prompts.

Rate Limiting and Abuse Prevention

All authentication endpoints, including login, two-factor authentication, registration, and password reset, are rate-limited to prevent brute-force and credential stuffing attacks. Repeated failed attempts result in temporary lockouts.

Security Audit Logs

Key security events are logged and retained, including:

  • Successful and failed login attempts
  • Password changes and account setting updates
  • Two-factor authentication events (enable, disable, use)
  • Data exports and bulk deletions
  • Unauthorized access attempts

These logs are available to authorized personnel and can be shared with customers in the event of a security incident affecting their account.

Breach Notification

Despite best efforts, no method of transmission over the Internet and no method of electronic storage is perfectly secure. We cannot guarantee absolute security. However, if PaperSurvey learns of a security breach, we will notify affected users so that they can take appropriate protective steps. Our breach notification procedures are consistent with our obligations under applicable country level, state and federal laws and regulations, as well as any industry rules or standards applicable to us. We are committed to keeping our customers fully informed of any matters relevant to the security of their account and to providing customers all information necessary for them to meet their own regulatory reporting obligations.

Uptime

We strive for 99.9% uptime across all our products and to support that, we employ a variety of tools to accurately monitor and report on any anomaly that could impact the delivery of our services.

Logging and monitoring

Application and infrastructure systems log information to a centrally managed log repository for troubleshooting, security reviews, and analysis by authorized personnel. Logs are preserved in accordance with regulatory requirements. We will provide customers with reasonable assistance and access to logs in the event of a security incident impacting their account.

Backups

Encrypted database backups are taken daily and held with more than one independent EU provider, retained for up to 3 months. Backups are encrypted using public-private key encryption, and the private key is held on offline storage that is only accessed for a critical incident or a customer-requested restore. A restore returns the database to the most recent daily backup, so the recovery point objective is 24 hours; we do not offer recovery to an arbitrary moment in time. Uploaded scans and generated files are held in EU object storage with the redundancy that storage applies, and are not part of the database backups. A survey deleted in the application can be restored from the 90-day trash, which is the usual route to recovering deleted work.

Data Retention Policy

A deleted survey is soft-deleted and held for 90 days before permanent removal, so an accidental deletion can be recovered. After 90 days it is permanently removed from production systems. Individual responses, entries and uploaded files are deleted immediately, with no recovery period.

Encrypted offsite backups are retained for up to 3 months as part of our disaster recovery procedures. After 3 months, backups are automatically purged.

Security Documentation

This page is a summary. The full detail sits in a set of documents we keep current and send on request:

  • Technical and Organizational Measures (TOMs): the measures we apply under Article 32 GDPR, covering encryption, access control, logging, backups, sub-processors, retention and incident response. It forms Annex 2 to our Data Processing Agreement.
  • Information Security Policy: how security is governed, and the standards development and operations work to.
  • Data Processing Agreement: the Article 28 contract, including the current sub-processor list. It applies to every customer collecting personal data, whether or not it has been separately signed, and a copy naming your organisation is available for signature.
  • AI Disclosure Statement: where AI is used and where it is not, what happens to your data, and how uncertain readings are reviewed. Also published at papersurvey.io/ai-disclosure.

Ask for any of these at gdpr@papersurvey.io. If your organisation uses its own security questionnaire, we will usually be able to answer it from the documents above. Completing a questionnaire in your own format is included for Enterprise Plus, and is available to other plans as a paid service.

Reporting Security Issues

We understand that security is essential in maintaining the trust you place in us to provide products and services to you. Although our team works vigilantly to help keep customer information secure, we recognize the important role that security researchers and our user community play in helping to keep our users secure. If you are a security researcher and have discovered a security vulnerability in our website or service, we ask for your help in disclosing it to us in a responsible manner. If you discover a vulnerability or are a customer who is concerned your account has been compromised, please notify us via sec@papersurvey.io.

Data Removal

If you wish to stop using our services, you may delete all your surveys from our platform, or delete your entire account. Deleting your account stops web survey collection and ends billing immediately. Erasure of the surveys, responses, uploaded files and team data held under the account is then carried out on request to gdpr@papersurvey.io and confirmed in writing.

When you delete a survey, data is removed from our production databases after the 90-day trash period. Encrypted offsite backups may retain deleted data for up to 3 months as part of our disaster recovery procedures, after which they are automatically purged.