Security
How we protect the feedback firms trust us with.
Client Culture is an independent client and employee experience measurement platform for professional services firms. Client feedback data is held onshore in Sydney on certified infrastructure, and our security posture is independently assessed by the security teams of the firms we serve.
Updated 18 August 2026
Data residency
Client feedback data – survey responses, verbatim comments and consent records – is stored and processed in Sydney, Australia: the database in AWS ap-southeast-2 and application compute in the Sydney region. Ancillary sub-processors and their regions are disclosed in full below.
Sub-processors
The third parties that process client data on our behalf, where they do it, and the assurance they hold. This is the same register we provide to client firms in security assessments.
| Provider | Purpose | Region | Assurance |
|---|---|---|---|
| Neon (Databricks, Inc.) | Primary database platform | AWS Sydney, Australia (ap-southeast-2) | SOC 2 Type II · ISO/IEC 27001:2022 · ISO/IEC 27701:2019 · direct data processing agreement |
| Vercel | Application hosting and compute | Sydney, Australia (syd1) | SOC 2 Type II |
| Anthropic, PBC | AI processing – operator-triggered custom report drafting | United States | Enterprise data processing agreement · no training on our data |
| Google Australia Pty Limited | Custom report preparation environment (Google Workspace – Slides, Sheets, Drive) on a Client Culture business account | Global Google data centres | Google Workspace business account |
| Resend | Transactional and survey email delivery | Tokyo, Japan | Operates on AWS |
| Upstash | Rate-limiting counters (IP-derived, short time-to-live, no content) | Singapore | Operates on AWS |
| GitHub (Microsoft) | Encrypted backup storage – ciphertext only; the key is held by Client Culture | United States | SOC 2 Type II |
Firm users sign in through their own identity provider (Microsoft Entra ID or Google Workspace). That provider is the firm’s, not our sub-processor.
Neon, Vercel, Resend and Upstash all operate on Amazon Web Services; client feedback data is stored in the AWS Sydney region. Each provider’s own downstream sub-processors are listed in its trust documentation.
Separately from the processors above, our GROW Visibility Tracker measures how firms appear in AI-generated answers by querying OpenAI, Perplexity and Google Gemini with public, search-style queries naming the firm. These engines are the subject of measurement, not processors of client data – no client feedback or client identifiers beyond the firm’s own public name are sent.
Encryption
- At rest: AES-256 at the database platform (database instances via AWS KMS; object storage via SSE-S3).
- In transit: TLS 1.2 or higher for all connections – browser to platform, platform to database, and platform to our email provider.
- Sensitive stored credentials such as SSO client secrets are encrypted at the application layer with AES-256-GCM.
- Backups are encrypted on our side before they are stored; the storage provider holds ciphertext only.
Access control
- Firm users authenticate through enterprise single sign-on (Microsoft Entra ID or Google Workspace). No local passwords for SSO-enforced firms.
- For SSO-enforced firms, sign-in is refused at domain level for any non-approved identity provider.
- No automatic account provisioning: only staff a firm has deliberately loaded onto the platform can sign in.
- Every platform query is firm-scoped, isolating each firm’s data. Within a firm, access is scoped by role, office and team.
- Multi-factor authentication is required on the administrative consoles we operate, including the database platform at organisation level.
- Least privilege: single-purpose service credentials, and administrative and impersonation actions are audit-logged.
Application security
- Rate limiting on public submission, authentication and expensive operations.
- Request bodies validated with typed schemas at the route boundary; type-safe, parameterised database access throughout – no raw SQL.
- CSRF protection on every mutating route (origin check plus a custom-header challenge) and host-bound session cookies.
- Server-side outbound requests pass an egress guard that restricts where the platform will connect.
- Survey links use unique, expiring tokens; submissions carry honeypot and datacentre-IP bot protection.
- SPF and DKIM authentication on our sending domain; an opt-out link in every survey email, honoured permanently.
AI processing
Most of the platform uses no third-party AI at all: dashboards, trend charts, benchmarks and longitudinal reports run on structured data we hold ourselves.
- Anthropic is the sole AI processor of client data, under an enterprise data processing agreement with no training on our data.
- Processing is operator-triggered and transient on our side – it runs only when a Client Culture analyst invokes it, and the platform stores nothing from the exchange beyond the report draft. The provider is contractually prohibited from training on the data and handles it only as the enterprise agreement permits.
- Identifiers sent for report drafting are limited to what attribution requires.
- Pseudonymisation is being rolled out: client, firm and professional names and identifying details are replaced with neutral references before content is sent to the AI provider, with real identities resolved only within Client Culture systems. The foundations shipped in August 2026; full rollout is gated on quality verification against real report output.
- AI output is a drafting input, not the deliverable. Every report’s themes, interpretations and recommendations are developed and finalised by Client Culture analysts.
AI-related claims we publish must match implemented behaviour. We do not claim that no personal information reaches the AI provider; we describe exactly what does, and the contractual and technical limits around it.
Retention and deletion
- Each firm configures a retention period for verbatim (free-text) feedback.
- A daily automated process deletes verbatim comments once they pass the firm’s retention period, recording only counts in the audit log – never content.
- The more privacy-protective interpretation prevails: shortening a retention period applies retroactively to existing comments; lengthening it never restores content already due for deletion.
- NPS scores, loyalty driver selections and response metadata (dates and the assigned professional) persist as structured data for trend analysis and contain no free text.
- Expired employee survey invitations are anonymised daily.
Backup and recovery
- The database platform provides point-in-time restore with a 30-day history window.
- Independently, an automated nightly backup runs on separate infrastructure, is encrypted client-side (the storage provider holds ciphertext only), and is restore-tested on every run against a disposable database with integrity checks. Backups are retained for 30 days.
- Recovery point: near-zero via point-in-time restore; no more than 24 hours if the database provider itself were lost.
- A restore drill was most recently performed on 18 August 2026, winding a copy of production back to a chosen minute and verifying every table. Recovery drills, including a break-glass procedure for administrative lockout, are performed and recorded; decrypt-and-recover drills of the independent backup run quarterly.
Continuous monitoring
- Dependencies are monitored continuously with automated advisory alerting on every production repository.
- Static application security testing and dependency, secret and misconfiguration scanning run weekly and on every change to the main branch of all three production repositories, with reports retained for 90 days.
- Vulnerabilities are triaged by exploitability and reachability against the platform’s authentication middleware and egress controls, not by severity label alone. Accepted risks carry a dated review obligation.
Independent assessment
Our security posture is independently assessed by the security teams of the firms we serve, most recently in August 2026 against the NSW Cyber Security Policy framework. Our Information Security Policy is mapped to ISO/IEC 27001:2022 Annex A.
We are not ISO 27001 certified and do not claim to be. Our infrastructure providers hold the certifications listed above, and we hold their reports.
Privacy
Client Culture operates under the Australian Privacy Act 1988 and the Australian Privacy Principles, and, for firms in the United Kingdom and European Economic Area, UK GDPR and EU GDPR. We act as a data processor on behalf of our firm clients, handling feedback data according to each firm’s instructions and our data processing agreements.
Responsible disclosure
If you believe you have found a security issue in the Client Culture platform, please tell us. Email security@clientculture.com; we acknowledge reports promptly and will keep you informed as we investigate. Our contact is also published at /.well-known/security.txt. For privacy questions, contact privacy@clientculture.com. Our full privacy policy, including regional addenda, is at app.clientculture.com/privacy.
Evidence pack for client firms
A full evidence pack is available to client firms under NDA: our Information Security Policy (with the ISO/IEC 27001:2022 Annex A mapping), Security and Privacy Strategic Plan, an extract of our risk, incident and asset registers, the sub-processor register, our infrastructure providers’ SOC 2 reports and certificates, and drill records.
Request the evidence packOr email security@clientculture.com.