Trust & Security
Security
Steradian is built for sensitive leadership input. We follow industry-standard practices for infrastructure hardening, transport security, access control, and aggregate reporting. We do not hold SOC 2, ISO 27001, or other third-party compliance certifications at this time.
Infrastructure
- AWS cloud hosting — Application and database run on Amazon Web Services in the United States.
- TLS in transit — Traffic to the platform is served over HTTPS with modern TLS configuration.
Access & audit
- Company- and role-scoped access — Platform, company, and campaign roles control who can administer accounts, manage participation, and access team reports within an engagement.
- Audit logging — Authentication and administrative actions are logged for investigation and review.
- Session security — Production sessions use signed, HTTP-only cookies over HTTPS.
- Password hashing — Passwords are hashed with bcrypt and not stored in plain text.
Reporting & non-attribution
- Minimum reporting floor — Leadership and organization-insight reports require at least 3 participants before aggregate results are shown. Item-level distributions are withheld below n = 5. Reports show respondent counts so readers can judge sample size.
- Non-attribution in team reports — Sponsors and facilitators see who has completed the assessment and aggregated, team-level reports; individual answers are not shown attributably in those flows. Platform operations personnel retain role-restricted, logged access to systems for support and service operation; that access is not used to produce attributed reporting. Aggregate reporting and unattributed comments can still carry re-identification risk in small leadership teams — Steradian does not promise absolute anonymity. See Privacy, Confidentiality and Reporting.
Data retention & deletion
Our stated retention policy (described on our Pricing page and not yet enforced automatically in the product): customer data retention follows the commercial terms agreed for the engagement; paid customers retain access for the duration of their subscription. Account and data deletion requests are fulfilled manually per our Privacy Policy — email privacy@steradianinsights.com (same mailto as Settings → Request account deletion); there is no automated self-serve deletion today. Module 2 sealed comment originals become purge-eligible 30 days after pulse close under current configuration; automated purge is not yet running.
Security questions
For security inquiries, vendor questionnaires, or responsible disclosure, contact security@steradianinsights.com. For general product questions, use Contact.
Last updated: July 21, 2026