Skip to main content

Trust center

Trust & security

Written for the security, privacy, and procurement reviewers who evaluate this platform before an agency rolls it out. It describes what we collect, where it goes, who can reach it, and how long we keep it. For consumer-facing language, see our privacy notice.

What this product does with data

An employer answers questions about their benefits program and receives an educational score and benchmark comparison. If they ask for a copy of the report, they give us a name and work email. Those responses are routed to one licensed broker organization, which is the only organization that can see them.

We do not sell audit data, do not share a lead with multiple agencies, and do not collect health information about individual employees. The audit asks about plan design and program economics, not about any person's medical condition, diagnosis, or claims.

Data map and retention

Every category of data the platform stores, why it exists, and how long it lives.

Categories of data collected, their source, and retention period
CategoryExamplesSourceRetention
Audit responsesCompany size, state, industry, coverage snapshot, plan details, prioritiesSubmitted by the employer completing the auditKept while the broker relationship is active; deleted on request
Contact detailsName, company, work email, optional phoneProvided by the employer when they ask for their report by emailKept while the broker relationship is active; deleted on request
In-progress draftsPartial answers and the step reached, so an audit can be resumedCaptured automatically as the form is filled inPurged after 90 days if never completed
Marketing attributionCampaign parameters, referring page, coarse click recordQuery string on inbound linksPurged after 13 months
Broker account dataUser identity, organization membership, access levelCreated at invitation and sign-inRemoved when the member is removed from the organization
Administrative audit logWho changed access, routing, or organization settings, and whenRecorded automaticallyRetained as an immutable record for security review

Security controls

Database-enforced tenant isolation
Every broker record is protected by row-level policies in the database itself, not just by application code. A member of one agency cannot read another agency's leads even if an application bug tried to ask for them.
Least-privilege access levels
Organization access is owner, manager, producer, or read-only, enforced per action on the server. Read-only members cannot write, and only owners and managers can change team access.
Invitation-only broker accounts
There is no public broker sign-up. Accounts are created from an invitation issued by an organization owner, manager, or the platform administrator.
Immutable administrative audit log
Access changes, routing changes, and organization setting changes are written to an append-only log that no application role can edit or delete.
Encryption in transit and at rest
All traffic is served over TLS, and stored data is encrypted at rest by the hosting platform.
Abuse and rate controls
Public endpoints are rate limited and screened for automated submissions, so the audit form cannot be used to flood a broker's pipeline.
Backups and recovery
The database is backed up continuously by the hosting platform with point-in-time recovery. Restores are exercised before major releases.
Change management
Scoring, benchmark, and schema changes are versioned; every report records the scoring engine and benchmark dataset version used to produce it.

Subprocessors

Service providers that may process data on our behalf. We will give notice before adding a new category of subprocessor for customers under a signed agreement.

  • Application and database hostingRuns the site and stores audit dataUnited States
  • Transactional email deliverySends report copies and account emailUnited States
  • Advertising measurementConversion counting for paid campaignsUnited States

Access requests, export, and deletion

Anyone who completed an audit can ask for a copy of their data or ask us to delete it. Email privacy@employeebenefitaudit.com from the address used on the audit, or include enough detail to identify the submission. We acknowledge within five business days and complete verified requests within thirty days.

Deletion removes the audit response, the generated report, and contact details from the broker's workspace. Entries in the administrative audit log are retained, because a security log that can be edited is not a security log; those entries reference identifiers, not audit answers.

Incident response

Suspected security issues are triaged the same business day. If an incident affects customer data we notify affected organization owners without undue delay, with what we know, what we have done, and what we are still investigating, followed by a written summary once the investigation closes.

To report a vulnerability, email privacy@employeebenefitaudit.com. We will not pursue good-faith researchers who avoid privacy violations and service disruption.

Access reviews and offboarding

Organization owners and managers can see every member and pending invitation on their team page and change or revoke access immediately. We recommend a quarterly review; removal takes effect on the next request, because access is checked by the database on every read.

Accessibility

We target WCAG 2.1 AA. The audit form uses programmatic labels and grouping, announces validation errors in context rather than only as transient toasts, moves focus to each new step, and is operable by keyboard throughout. If you hit a barrier, tell us at privacy@employeebenefitaudit.com and we will prioritize a fix.

Compliance posture

We are able to sign a data processing agreement and complete standard security questionnaires. We are not currently SOC 2 certified; the controls above are the foundation we are building that program on, and we will say so plainly rather than imply a certification we do not hold.

The audit is an educational assessment, not legal, tax, or insurance advice, and does not create a broker of record relationship. See methodology for how scores are produced and what they do not claim.