Survetify
PrivacySupportOpen Survetify
SECURITY

Security & Responsible Disclosure

How Survetify protects multi-tenant survey operations information and how to report a suspected vulnerability safely.

Role-based accessPrivate file deliveryServer-side secrets
SECURITYPlatform controlsAI handlingShared responsibilityReport a vulnerabilityIncident response

Platform security controls

Survetify applies layered controls appropriate to a cloud business application. Current controls include:

  • encrypted HTTPS/TLS transport for web, API and mobile connections;
  • Supabase authentication with expiring sessions and server-enforced database row-level security;
  • organisation, project and role-based access boundaries;
  • private file delivery through authenticated API paths rather than public file URLs;
  • server-side storage of service-role, AI and signing secrets;
  • audit records for important user, manager and AI-assisted actions;
  • mobile release signing through Apple, Google and EAS credential systems;
  • dependency and release checks, including a native-only control that rejects WebView use; and
  • operational review of risk, access and deletion requests.

Security controls evolve with the service. This page describes the current approach but is not a certification or guarantee that no incident can occur.

AI and project information

AI features send only the context reasonably required for the requested task to the configured AI provider. Customer project content is not intentionally used to train a public or general-purpose AI model without express written agreement. AI findings are stored with source context and require human review before professional or field reliance.

Customer shared responsibility

Security also depends on each customer organisation. Customers should:

  • assign the least privilege necessary and review memberships regularly;
  • remove former staff and revoke lost-device access promptly;
  • protect email accounts, devices and passwords, and enable available identity protections;
  • classify files before upload and avoid unnecessary sensitive information;
  • verify recipients before exporting or sharing project records; and
  • report suspicious behaviour immediately.

Responsible vulnerability disclosure

Email security@survetify.com with a clear description, affected URL/feature, reproduction steps and impact. Use test or fictional data wherever possible.

Safe research boundaries: do not access another customer's data, disrupt service, use social engineering, perform denial-of-service testing, upload malware, exfiltrate files or publicly disclose an unresolved issue. Stop immediately if you encounter personal or confidential information.

We will acknowledge credible reports, investigate in good faith and keep the reporter informed where practical. This is not a paid bug-bounty program and no reward is promised.

Incident response

Our response follows four practical stages: contain, assess, notify where required, and review. We preserve relevant evidence, restrict access, work with affected providers/customers and assess obligations under the Australian Notifiable Data Breaches scheme where applicable.

For an active account compromise, email security@survetify.com and ask your organisation Owner or Survey Manager to remove affected access immediately.

© 2026 Survetify · Melbourne, Australia
PrivacyTermsSecuritySupportData deletion