Feedback
Help Center

GetFeedback and Security

GetFeedback has been ISO 27001 certified since 2019, and has maintained SOC 2 Type 2 compliance since 2021. We undergo annual third-party audits to assess whether our security controls are consistently met and continuously improved.

For self-service purchases of GetFeedback, SurveyMonkey validates the applicable checkout flow under PCI DSS v4.0.1 SAQ A. We use Stripe as our payment processor and maintain payment security controls, including recurring assessments and scanning where applicable.

The ISO 27001 certificate is an internationally recognized information security standard defined by the International Organization for Standardization (ISO).

It provides requirements for an Information Security Management Systems (ISMS) and prescribes a set of rules on how organizations should manage and securely handle data to safeguard its integrity, confidentiality, and availability.

We take the security of your information seriously and have implemented sophisticated security measures to safeguard it.

Complying with information security best practices and standards means we work hard to keep your data safe. The ISO 27001 certificate means that GetFeedback has implemented processes to:

  • manage information security risks,
  • protect information assets, and
  • maintain compliance with applicable information security standards and practices.

Contact us to request a copy of the certificate or learn more by chatting with us.

Industry standards such as System and Organization Controls (SOC) for Service Organizations reports developed by the American Institute of Certified Public Accountants (AICPA), are designed to provide customers with information about how their vendors manage and process data. SOC 2 is an independent auditing procedure that assures the systems and processes that a service organization uses to process customer data and the confidentiality and privacy of the information being processed. Unlike a Type 1 report, which assesses controls at a single point in time, a Type 2 report evaluates the operating effectiveness of those controls over an extended period (12-month observation period for GetFeedback). GetFeedback has been SOC 2 Type 2 compliant since 2021.

Three trust service principles fall under the SOC 2 criteria for managing customer data: security, availability, and confidentiality. 

  • Security refers to how the service organization protects system resources against unauthorized access. 
  • Availability addresses whether the service organization supports system or service availability as stipulated by a contract or service-level agreement.
  • Confidentiality addresses whether the data is restricted to a specific set of persons or organizations and encrypted to protect the data during transmission.

At GetFeedback, we take our responsibility to protect and secure your enterprise information seriously. Security is built-in across our products, infrastructure, and processes.

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard for organizations that store, process, or transmit cardholder data. It’s maintained by the PCI Security Standards Council and defines a set of technical and operational requirements designed to protect payment card data throughout the transaction lifecycle. For self-service purchases of GetFeedback, SurveyMonkey uses Stripe as its PCI-compliant payment processor and validates the applicable checkout flow under PCI DSS v4.0.1 SAQ A.

We take the security of your payment data seriously. For self-service purchases, cardholder data is processed through Stripe’s PCI-compliant payment environment. This helps keep sensitive payment card information out of GetFeedback’s direct systems and supports secure automated checkout for self-service customers.

For the applicable self-service checkout flow, SurveyMonkey maintains processes designed to:

  • securely process cardholder data through the Stripe integration,
  • maintain secure payment flows,
  • monitor and test our environment on an ongoing basis, and
  • maintain compliance with applicable PCI DSS requirements for the validated checkout flow.