Skip to main content

Trust

Security at Thisys

Where your survey data lives, how it is protected, and who else touches it.

Hosting

Thisys runs on DigitalOcean infrastructure. Where survey definitions, responses, contact lists, uploaded files and backups are stored is listed with DigitalOcean in the sub-processor table below.

The application, database and file store run on hardened Linux hosts behind a reverse proxy. The only services reachable from the internet are HTTP on port 80 (which redirects to HTTPS), HTTPS on port 443, and SSH on port 22 for administration. SSH accepts public-key authentication only, and repeated failed attempts are banned automatically. The database, the application processes and every other port are closed at a cloud firewall that sits outside the machine, so they stay closed even if the host itself is misconfigured.

Encryption

All traffic between your browser and Thisys, and between Thisys and every service it calls, is encrypted with TLS. Plain HTTP requests are redirected to HTTPS.

Account passwords are hashed with Argon2id, the current OWASP recommendation, and never stored or logged in clear text. Passwords migrated from SurveyFace are upgraded to Argon2id when the account next signs in. API keys and tokens are stored as hashes; the clear value is shown once, at creation. A survey's optional results-sharing code is also stored as a salted scrypt hash: it cannot be displayed again once set, only replaced or removed. The one secret held in clear is a collector's respondent access code — the short code you read out to a room before people answer. It is a low-stakes shared gate rather than a credential, and it is never returned to a browser.

At-rest encryption specifically: Thisys does not add its own additional encryption layer on top of the database disk or the file-storage bucket our hosting provider (DigitalOcean) gives us, and the nightly backup files kept on the server are compressed, not separately encrypted; the off-site copy of each night's database backup is encrypted (AES-256) before it leaves the server. If your organisation requires encryption at rest as a contractual control, ask us through the contact page before you rely on this platform for that data.

Access control

Every account has a single owner. Survey results and share links are private by default and are opened to others only when the owner chooses to share them. A shared results dashboard can additionally be put behind an access code. A shared CSV download link has no access code: its protection is an unguessable token you can revoke or rotate at any time, which stops the old link working immediately.

Two-factor authentication guards the email-and-password route. Your authenticator code is required when you sign in with your email and password; signing in with Google or Microsoft does not ask for it, and those sign-ins rely on the security of that account instead, including any two-factor you have set up there. Administrator accounts are the exception: an administrator who signs in with Google or Microsoft must also enter the authenticator code before the session can be used.

Thisys staff do not read customer survey data in the course of normal operations. Administrative access is limited to named staff and is used only to resolve a support request or an incident.

Sign-in is protected against credential stuffing by rate limits, temporary lockout after repeated failures, and email-verified password resets. Two-factor authentication with any authenticator app is available to every account and required for administrators; recovery codes cover a lost phone.

Backups and continuity

The database is backed up every night, and the last 14 days of those backups are kept on the server. An encrypted copy of each night's database backup is also kept for 30 days in separate storage in the same region, and our hosting provider (DigitalOcean) takes a backup of the whole server every day.

Uploaded files (survey images, logos and files that respondents attach) are kept in DigitalOcean Spaces object storage. They are not yet backed up separately from it; a separate backup of uploaded files is planned.

A watchdog restarts the application if it stops responding. Planned maintenance is announced ahead of time on the status page (/status) and in a banner across the site.

Retention and deletion

You control how long responses are kept: each survey can carry a retention period after which responses are purged automatically by a daily job. Deleting a survey asks you to type a confirmation first, then moves it to Deleted surveys on My Surveys for 30 days: its links, shared results and certificates stop at once, and you can restore it until the 30 days are up, when it and its responses are deleted for good. Pages and questions you delete inside a survey wait in that survey's trash for 14 days, so a mistaken edit can be undone.

When you close your account (confirmed through a link sent to your email address), its surveys, responses, contacts and files are deleted from the live system, and from backups within 30 days as those age out.

You can export your survey definitions and responses at any time in CSV, Excel and PDF formats, so your data is never locked in.

AI features and your data

Thisys's AI features (survey generation, translation, response analysis and the assistant) send only the text needed for the task to Thisys's one AI provider, Anthropic, over an encrypted connection. Anthropic processes it in the United States under commercial API terms that do not permit training on it.

Response analysis is off until the survey owner turns it on, and the platform can be configured to disable third-party processing of response data entirely for customers whose contracts require it.

AI output is a suggestion, with one exception you should know about. The AI builder and the home box can create a survey, its suggested skip logic and an open web link in one step; you can review, edit or close the link at any time. Everything else the AI writes, such as reports, themes, translations and flags, is a draft until you accept it.

Incidents and disclosure

If a security incident is likely to result in serious harm to the people whose data is affected, we notify affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and customers in other jurisdictions in line with their laws, as soon as practicable and no later than 72 hours after we confirm the breach.

Security researchers who find a vulnerability, and anyone with a privacy concern, are asked to report it through the contact page: on the "Send a Message" tab, choose "Security or privacy report" as the issue. Those reports go straight to a person rather than to the instant-answer assistant, and the same contact route is published for security tools at /.well-known/security.txt. We acknowledge reports within two business days, do not pursue good-faith research, and credit reporters who want it once the issue is fixed.

Sub-processors

These are the third parties that may process customer data on our behalf. We keep this list up to date.

DigitalOcean, LLCPurpose: Cloud hosting: application servers, database, file storage and backupsData: All account information and Customer DataLocation: Sydney, Australia
Cloudflare, Inc.Purpose: DNS, content delivery and a security proxy (DDoS protection and web application firewall) in front of the siteData: Visitor IP addresses, request metadata (URLs and headers) and the traffic passing through to the siteLocation: Global edge network (United States headquartered)
Resend, Inc.Purpose: Transactional email: sign-in, verification, alerts and survey invitationsData: Recipient email addresses, names and the content of the emailsLocation: United States
Stripe, Inc.Purpose: Payments for paid plans and credit packsData: Billing name, email address and payment details (card numbers never reach Thisys)Location: United States, with Australian acquiring
Google LLC (Sign in with Google)Purpose: Optional single sign-on, only for accounts that choose itData: Email address, name and the Google account identifierLocation: United States
Microsoft Corporation (Entra ID)Purpose: Optional single sign-on, only for accounts that choose itData: Email address, name and the Microsoft account identifierLocation: United States
Anthropic, PBCPurpose: AI features: survey generation, translation, analysis and the assistantData: What you type into the AI features, the survey text, and response text where the survey owner has enabled AI analysisLocation: United States

Agreements

Our Privacy Policy sets out our roles under the Australian Privacy Act and the GDPR: you are the controller of the data your surveys collect and Thisys is your processor. If your organisation needs written data-processing terms, ask us through the contact page.