Security Policy
This policy provides a customer-facing overview of SierraTec Survey's security practices, shared responsibilities, identity controls, incident response, vendor risk, and regulated-data limitations.
1. Purpose
This Security Policy summarizes SierraTec Survey's customer-facing security commitments and practices. It does not disclose confidential defensive details and does not replace an Enterprise security exhibit, BAA, DPA, SLA, or other negotiated security terms.
3. Access Control
- Role-based access controls where supported.
- Least-privilege administrative access.
- Workspace roles and permissions.
- Prompt removal of access when personnel no longer require it.
- Additional Enterprise identity controls where available.
4. Authentication
SierraTec may support strong password requirements, multi-factor authentication, SSO, SAML, OpenID Connect, and other identity controls depending on plan and configuration. Customers should enable the strongest appropriate authentication options available to them.
5. Encryption
SierraTec uses encryption and transport security appropriate to the information and systems involved. Specific encryption, key-management, and architecture details may be provided through applicable Enterprise security documentation where appropriate.
6. Infrastructure and Hosting
SierraTec may use reputable cloud and infrastructure providers. Hosting regions, redundancy, availability architecture, and data-residency commitments may vary by product configuration and written agreement.
7. Logging and Monitoring
SierraTec may maintain security, authentication, administrative, application, and infrastructure logs to detect abuse, troubleshoot issues, investigate incidents, and support compliance. Log access and retention should be limited according to operational and legal needs.
8. Vulnerability Management
SierraTec maintains risk-based processes for vulnerability identification, dependency management, remediation prioritization, patching, and response.
9. Secure Development
SierraTec incorporates security considerations into software development and change management, including access controls, code review, dependency management, secret handling, testing, and deployment controls appropriate to the risk of the change.
10. Backups and Recovery
SierraTec may maintain backups and recovery procedures for operational resilience. Backup architecture and recovery objectives may vary by service tier and Enterprise agreement. Backups are not a substitute for a Customer's own archival obligations unless expressly agreed.
11. Incident Response
SierraTec maintains an incident-response process addressing identification, containment, investigation, recovery, documentation, and legally or contractually required notifications.
12. Personal Data Breaches
Where SierraTec acts as a processor, it will notify the applicable controller of qualifying personal-data breaches as required by the DPA and applicable law. Where SierraTec acts as controller, it will make required regulator or individual notifications.
13. Personnel Security
Access to production systems and sensitive information is limited to authorized personnel based on job responsibilities. SierraTec uses confidentiality, onboarding, access-review, and offboarding practices appropriate to the Service.
14. Third-Party Risk
SierraTec assesses material service providers based on the nature of access and risk and uses contractual, privacy, security, and confidentiality requirements appropriate to the services they provide.
15. Subprocessors
SierraTec will make subprocessor information available where legally or contractually required.
16. Enterprise SSO and SCIM
Eligible plans may support SSO, domain verification, just-in-time provisioning, SCIM, and other administrative controls. Customers remain responsible for identity-provider configuration, provisioning logic, certificates, secrets, and role mappings.
17. API and Webhook Security
Customers must protect API keys, webhook secrets, service-account credentials, and integration tokens. SierraTec may rate-limit, rotate, revoke, or disable credentials where necessary to protect the Service.
18. Data Retention and Deletion
Security-related logs and records may be retained for periods appropriate to fraud prevention, investigations, legal obligations, and operational needs. Customer Content follows the applicable retention, deletion, and backup rules described in the Terms, Privacy Policy, and applicable agreements.
19. HIPAA-Regulated Use
SierraTec Survey is not automatically approved for PHI. HIPAA-regulated use requires an expressly approved configuration and a BAA where required. Applicable subcontractors and security controls must be included within that approved environment.
20. FERPA and Education Data
Education customers should use appropriate role, sharing, retention, and identity controls. FERPA applicability depends on the institution's use and legal basis, not merely on use of SierraTec Survey.
21. Customer Security Responsibilities
- Use strong authentication and MFA where available.
- Restrict administrative privileges.
- Review workspace membership regularly.
- Configure survey links and access controls appropriately.
- Protect exported files.
- Use approved integrations.
- Rotate compromised credentials promptly.
- Notify SierraTec promptly of suspected account compromise or security incidents.
22. Security Reporting
Suspected vulnerabilities or security incidents may be reported to info@sierratecsecure.com until SierraTec publishes a dedicated security contact. SierraTec may publish a dedicated vulnerability-disclosure or security-reporting channel as the Service evolves.
23. No Absolute Security Guarantee
No online service can guarantee absolute security. SierraTec's security measures are designed to reduce risk and should evolve with the threat environment, product architecture, and applicable obligations.
24. Changes
SierraTec may update this Security Policy as controls, infrastructure, certifications, vendors, or legal requirements change. Material contractual security commitments remain governed by the applicable written agreement.