Security Overview

Trust & Security
Reference
Updated Sep 25, 2026

Security Overview

This is a general overview of how Opionate approaches security, written for anyone evaluating the platform who wants the broad picture rather than a component-by-component technical audit. If your organization needs a deeper review as part of a formal vendor assessment, reach out via Opionate's support channel.

Account Access

Sign-in supports both standard email/password authentication (with email verification required before an account is usable) and Google sign-in. Account access is protected by standard modern authentication practices, and bot-protection measures are in place on account-creation and public-facing forms to reduce automated abuse.

Data in Transit and at Rest

Your data - survey structures, responses, and account information - is transmitted and stored using industry-standard practices for a modern web application. Payment processing runs through an established third-party payment provider rather than through custom-built infrastructure, so card details never need to pass through or be stored by Opionate directly.

Respondent-Facing Protections

Public survey links and shared report links include bot-protection and access-control measures appropriate to what they expose - a survey take link is protected against automated abuse, and a shared report link supports optional password protection and login requirements on top of its own unique, non-guessable link. See Sharing a Report Publicly for the specifics of report-level access control.

Staff Access to Your Data

Opionate staff do not casually browse customer survey data. Access by platform staff is limited to what's needed to operate the platform, resolve support requests you've raised, and handle specific cases - like a Panel Recruitment submission report - where you've explicitly asked for help with something staff need to look into.

Third-Party Services

Opionate relies on established third-party infrastructure for specific functions - payment processing, respondent recruitment, and AI-assisted features among them - rather than building every piece of underlying infrastructure from scratch. These are reputable, widely used providers, integrated in a way that keeps your data handling consistent with the practices described here.

Reporting a Concern

If you believe you've found a security issue, or have a question that isn't answered here, reach out via Opionate's support channel directly rather than posting details publicly - the team will follow up.

FAQ

Is Opionate SOC 2 or ISO 27001 certified?
For current certification status, reach out via Opionate's support channel - this page is a general overview rather than the authoritative source for formal compliance certifications.

Can I request a security questionnaire be completed for a vendor review?
Yes - reach out via support with what your organization's review process requires.

Does Opionate share my survey data with third parties?
Third-party services are used for specific functional purposes (like payment processing), not for sharing your survey content or respondent data beyond what's necessary to provide the service you've signed up for.

How is my account password stored?
Passwords are stored using standard modern security practices for a web application, not in plain text or a reversible format.

For how consent and respondent data specifically are handled, see Data Privacy and Consent Management.

security trust data protection account security

We value your privacy

We use cookies and similar technologies to improve your experience, analyze site traffic, and personalize content. Learn more