Security & Data Handling
Last updated July 26, 2026
Overview
Account isolation
Encryption
All traffic to and from the platform is encrypted in transit (TLS), enforced automatically by our hosting provider on every request.
Data at rest is encrypted on our database provider, Neon, which encrypts stored data using AES-256 and holds its own SOC 2 Type II certification as an infrastructure provider.
Authentication
Respondent links
Data deletion
Subprocessors
We use a small, named set of subprocessors, each receiving only what its function needs:
- Vercel — hosting
- Neon — database
- Anthropic— AI survey generation, translation, and (only when an analyst requests it) open-end response coding — the one place respondent-submitted free-text answers are sent to a third party for processing
- Resend — email delivery
- Twilio — SMS delivery
- Sentry — error monitoring
We never sell contact information, and never use one client's contact lists or response data for any other client or purpose.
SMS and email consent
What we can't yet claim
Two things worth being direct about. First, Neon holding SOC 2 Type II certification is Neon's certification as our infrastructure provider — Wavefield Research itself does not currently hold SOC 2 or ISO 27001 certification as a company. Our infrastructure is SOC 2-backed; we are not (yet) independently certified.
Second, we don't have a standing, pre-signed Data Processing Agreement template. If your organization requires one contractually (common for GDPR-subject or enterprise clients), write to support@wavefieldresearch.com and we'll work through it with you.