Security and GDPR
How Sift protects your data, where it can be stored, and how to put an agreement in place. Security is a day-one requirement here, because the whole product rests on a trusted link from raw feedback to a decision. For the broader data practices, see the Privacy Policy.
Security posture
Data is encrypted in transit and at rest. Access is scoped to your workspace, with role-based permissions, and our own team works under least-privilege access. Feedback content has PII scrubbed by default before synthesis, so personal identifiers are removed early in the pipeline. You can review scrubbing and other controls under Data and privacy in your account.
SOC 2 (planned, year 2)
Sift is built to the controls a SOC 2 Type II audit expects: access control, change management, monitoring, and incident response. Formal certification is planned for year 2, and we publish the report status here as it progresses. The exact audit window is confirmed as the program matures.
Data residency (EU option)
Our primary markets are the United States and Europe. EU workspaces can have their data stored in the EU to meet residency requirements under GDPR. Choose your region at workspace setup, or contact us to move an existing workspace.
Request a DPA
If your organization requires a Data Processing Agreement, we are ready to sign one. A DPA covers roles, sub-processors, security measures, and breach notification under GDPR. Request one at dpa@sift.app and we will send our standard agreement. Our current sub-processor list is available on request and finalized before launch.
Contact
For security questions or a DPA, contact security@sift.app. To manage scrubbing and export or delete your data, open Data and privacy in your account.