How Public Survey and Report Links Stay Protected¶
Your account login protects everything behind it, but a survey take link and a shared report link are built to work without a login at all - that's the whole point of them. Since anyone with the link can open it, both are protected in ways specifically designed for a link, not a password-protected account.
Survey Take Links¶
Every published survey gets its own unique link for respondents. It isn't tied to any predictable pattern based on your survey's name or your account, and automated attempts to guess or repeatedly probe a link are detected and slowed down - a normal respondent opening the link they were sent is unaffected, but scripted attempts to find valid survey links by trial and error don't get very far.
AI Follow-up Questions and Bot Protection¶
Where AI Follow-up Questions are enabled, the follow-up generation itself includes bot-protection running invisibly in the background - a genuine respondent never sees an extra step, but automated abuse of the feature (repeatedly triggering AI generation without actually taking the survey) is guarded against.
Shared Report Links¶
A shared report link (see Sharing a Report Publicly) is, by default, a unique link that isn't guessable from your report's name or your account. On top of that baseline, you can add a password requirement, a login requirement, or both - giving you a second and third layer of control for anything more sensitive than "anyone with the link can see it."
Why This Matters More for Public Links Than for Your Account¶
Your account itself is protected by standard login security. A public link is a different kind of surface - it's designed to be opened by people who were never going to create an account, which means it can't rely on login-based protection by default. The measures above exist specifically to keep that openness from becoming a liability.
FAQ¶
Can I turn off bot protection on my survey's take link?
No - it's a baseline protection applied consistently across published surveys, not an optional setting.
Does bot protection ever block a real respondent by mistake?
It's designed to act on patterns consistent with automated abuse, not on normal one-time link access - a respondent opening their own survey link the way it was shared with them shouldn't notice anything different.
Is a report link's uniqueness enough on its own, or should I always add a password?
For most internal or low-sensitivity sharing, the link's own uniqueness is enough. For anything you'd consider sensitive - financial results, unreleased plans, anything you wouldn't want to end up somewhere unintended - add a password, a login requirement, or both.
Does this protection apply to preview links I use while building a survey?
This is about the respondent-facing take link for a published survey and shared report links specifically - a builder preview is a separate context meant only for your own testing.
For the broader picture of how Opionate handles security generally, see Security Overview.