🎓Verified students save over 50% on the Student Research plan.View student offer
SierraTec Secure
Audience Integrations Pricing Security
Security

Built for teams that take identity seriously

An overview of how sign-in, provisioning, and account activity work under the hood.

SSO

SAML 2.0 or OpenID Connect, both SP- and IdP-initiated.

SCIM

Automatic user and group provisioning from your identity provider.

Two-factor auth

TOTP-based MFA with one-way-hashed, single-use recovery codes.

Audit logs

Searchable log of sign-ins, role changes, and config changes.

API tokens

Bearer tokens scoped to your account, shown once, revocable anytime.

1. Purpose

This Security Policy summarizes SierraTec Survey's customer-facing security commitments and practices. It does not disclose confidential defensive details and does not replace an Enterprise security exhibit, BAA, DPA, SLA, or other negotiated security terms.

2. Shared Responsibility

SierraTec is responsible for safeguarding the Service and infrastructure within its control. Customers are responsible for secure account configuration, user access, survey sharing, credentials, integrations, endpoints, exported data, and lawful collection practices.

3. Access Control

  • Role-based access controls where supported.
  • Least-privilege administrative access.
  • Workspace roles and permissions.
  • Prompt removal of access when personnel no longer require it.
  • Additional Enterprise identity controls where available.

4. Authentication

SierraTec may support strong password requirements, multi-factor authentication, SSO, SAML, OpenID Connect, and other identity controls depending on plan and configuration. Customers should enable the strongest appropriate authentication options available to them. Organizations on Business plans and above can connect either SAML 2.0 or OpenID Connect - SAML assertions are signature-verified against your identity provider's X.509 certificate, and OpenID Connect uses the full authorization-code flow with PKCE, state, and nonce checks, with ID tokens verified against your provider's live JWKS. Both creator and administrator accounts can also enable TOTP-based two-factor authentication, with one-time recovery codes stored as one-way hashes and consumed on use.

5. Encryption

SierraTec uses encryption and transport security appropriate to the information and systems involved. Specific encryption, key-management, and architecture details may be provided through applicable Enterprise security documentation where appropriate.

6. Infrastructure and Hosting

SierraTec may use reputable cloud and infrastructure providers. Hosting regions, redundancy, availability architecture, and data-residency commitments may vary by product configuration and written agreement.

7. Logging and Monitoring

SierraTec may maintain security, authentication, administrative, application, and infrastructure logs to detect abuse, troubleshoot issues, investigate incidents, and support compliance. Organization owners on Business plans and above get a searchable log of security-relevant events - sign-ins, role changes, SSO/SCIM configuration changes, invite activity, API token and webhook changes - each entry recording the actor, IP address, and timestamp. Log access and retention are limited according to operational and legal needs.

8. Vulnerability Management

SierraTec maintains risk-based processes for vulnerability identification, dependency management, remediation prioritization, patching, and response.

9. Secure Development

SierraTec incorporates security considerations into software development and change management, including access controls, code review, dependency management, secret handling, testing, and deployment controls appropriate to the risk of the change.

10. Backups and Recovery

SierraTec may maintain backups and recovery procedures for operational resilience. Backup architecture and recovery objectives may vary by service tier and Enterprise agreement. Backups are not a substitute for a Customer's own archival obligations unless expressly agreed.

11. Incident Response

SierraTec maintains an incident-response process addressing identification, containment, investigation, recovery, documentation, and legally or contractually required notifications.

12. Personal Data Breaches

Where SierraTec acts as a processor, it will notify the applicable controller of qualifying personal-data breaches as required by the DPA and applicable law. Where SierraTec acts as controller, it will make required regulator or individual notifications.

13. Personnel Security

Access to production systems and sensitive information is limited to authorized personnel based on job responsibilities. SierraTec uses confidentiality, onboarding, access-review, and offboarding practices appropriate to the Service.

14. Third-Party Risk and Subprocessors

SierraTec assesses material service providers based on the nature of access and risk and uses contractual, privacy, security, and confidentiality requirements appropriate to the services they provide. SierraTec will make subprocessor information available where legally or contractually required.

15. Enterprise SSO and SCIM

Eligible plans may support SSO, domain verification, just-in-time provisioning, SCIM 2.0 group provisioning, and other administrative controls - synced groups can be mapped to automatically grant the Admin role to their members, staying in sync as group membership changes upstream. Customers remain responsible for identity-provider configuration, provisioning logic, certificates, secrets, and role mappings.

16. API and Webhook Security

API access uses bearer tokens scoped to your account, shown once at creation and revocable at any time. Outbound webhooks are signed with your webhook secret using HMAC-SHA256 on every delivery, so you can verify a payload genuinely came from us before trusting it. Customers must protect API keys, webhook secrets, service-account credentials, and integration tokens - SierraTec may rate-limit, rotate, revoke, or disable credentials where necessary to protect the Service.

17. Data Retention and Deletion

Security-related logs and records may be retained for periods appropriate to fraud prevention, investigations, legal obligations, and operational needs. Customer Content follows the applicable retention, deletion, and backup rules described in the Terms, Privacy Policy, and applicable agreements.

18. HIPAA and FERPA

SierraTec Survey is not automatically approved for PHI. HIPAA-regulated use requires an expressly approved configuration and a BAA where required, with applicable subcontractors and security controls included within that approved environment. Education customers should use appropriate role, sharing, retention, and identity controls - FERPA applicability depends on the institution's use and legal basis, not merely on use of SierraTec Survey.

19. Customer Security Responsibilities

  • Use strong authentication and MFA where available.
  • Restrict administrative privileges.
  • Review workspace membership regularly.
  • Configure survey links and access controls appropriately.
  • Protect exported files.
  • Use approved integrations.
  • Rotate compromised credentials promptly.
  • Notify SierraTec promptly of suspected account compromise or security incidents.

20. Security Reporting

Suspected vulnerabilities or security incidents may be reported to info@sierratecsecure.com until SierraTec publishes a dedicated security contact.

No online service can guarantee absolute security, and this page describes our security architecture, not a compliance certification. SierraTec's security measures are designed to reduce risk and evolve with the threat environment. We don't currently hold formal certifications such as SOC 2 or ISO 27001. If your organization requires a specific certification, contact us before you rely on this page for a compliance decision.

Questions about rolling this out for your team?

Talk to us about SSO, SCIM, or Enterprise plans.