Trust center
Trust & security
Written for the security, privacy, and procurement reviewers who evaluate this platform before an agency rolls it out. It describes what we collect, where it goes, who can reach it, and how long we keep it. For consumer-facing language, see our privacy notice.
What this product does with data
An employer answers questions about their benefits program and receives an educational score and benchmark comparison. If they ask for a copy of the report, they give us a name and work email. Those responses are routed to one licensed broker organization, which is the only organization that can see them.
We do not sell audit data, do not share a lead with multiple agencies, and do not collect health information about individual employees. The audit asks about plan design and program economics, not about any person's medical condition, diagnosis, or claims.
Data map and retention
Every category of data the platform stores, why it exists, and how long it lives.
| Category | Examples | Source | Retention |
|---|---|---|---|
| Audit responses | Company size, state, industry, coverage snapshot, plan details, priorities | Submitted by the employer completing the audit | Kept while the broker relationship is active; deleted on request |
| Contact details | Name, company, work email, optional phone | Provided by the employer when they ask for their report by email | Kept while the broker relationship is active; deleted on request |
| In-progress drafts | Partial answers and the step reached, so an audit can be resumed | Captured automatically as the form is filled in | Purged after 90 days if never completed |
| Marketing attribution | Campaign parameters, referring page, coarse click record | Query string on inbound links | Purged after 13 months |
| Broker account data | User identity, organization membership, access level | Created at invitation and sign-in | Removed when the member is removed from the organization |
| Administrative audit log | Who changed access, routing, or organization settings, and when | Recorded automatically | Retained as an immutable record for security review |
Security controls
- Database-enforced tenant isolation
- Every broker record is protected by row-level policies in the database itself, not just by application code. A member of one agency cannot read another agency's leads even if an application bug tried to ask for them.
- Least-privilege access levels
- Organization access is owner, manager, producer, or read-only, enforced per action on the server. Read-only members cannot write, and only owners and managers can change team access.
- Invitation-only broker accounts
- There is no public broker sign-up. Accounts are created from an invitation issued by an organization owner, manager, or the platform administrator.
- Immutable administrative audit log
- Access changes, routing changes, and organization setting changes are written to an append-only log that no application role can edit or delete.
- Encryption in transit and at rest
- All traffic is served over TLS, and stored data is encrypted at rest by the hosting platform.
- Abuse and rate controls
- Public endpoints are rate limited and screened for automated submissions, so the audit form cannot be used to flood a broker's pipeline.
- Backups and recovery
- The database is backed up continuously by the hosting platform with point-in-time recovery. Restores are exercised before major releases.
- Change management
- Scoring, benchmark, and schema changes are versioned; every report records the scoring engine and benchmark dataset version used to produce it.
Subprocessors
Service providers that may process data on our behalf. We will give notice before adding a new category of subprocessor for customers under a signed agreement.
- Application and database hosting— Runs the site and stores audit dataUnited States
- Transactional email delivery— Sends report copies and account emailUnited States
- Advertising measurement— Conversion counting for paid campaignsUnited States
Access requests, export, and deletion
Anyone who completed an audit can ask for a copy of their data or ask us to delete it. Email privacy@employeebenefitaudit.com from the address used on the audit, or include enough detail to identify the submission. We acknowledge within five business days and complete verified requests within thirty days.
Deletion removes the audit response, the generated report, and contact details from the broker's workspace. Entries in the administrative audit log are retained, because a security log that can be edited is not a security log; those entries reference identifiers, not audit answers.
Incident response
Suspected security issues are triaged the same business day. If an incident affects customer data we notify affected organization owners without undue delay, with what we know, what we have done, and what we are still investigating, followed by a written summary once the investigation closes.
To report a vulnerability, email privacy@employeebenefitaudit.com. We will not pursue good-faith researchers who avoid privacy violations and service disruption.
Access reviews and offboarding
Organization owners and managers can see every member and pending invitation on their team page and change or revoke access immediately. We recommend a quarterly review; removal takes effect on the next request, because access is checked by the database on every read.
Accessibility
We target WCAG 2.1 AA. The audit form uses programmatic labels and grouping, announces validation errors in context rather than only as transient toasts, moves focus to each new step, and is operable by keyboard throughout. If you hit a barrier, tell us at privacy@employeebenefitaudit.com and we will prioritize a fix.
Compliance posture
We are able to sign a data processing agreement and complete standard security questionnaires. We are not currently SOC 2 certified; the controls above are the foundation we are building that program on, and we will say so plainly rather than imply a certification we do not hold.
The audit is an educational assessment, not legal, tax, or insurance advice, and does not create a broker of record relationship. See methodology for how scores are produced and what they do not claim.