Security and privacy
Status controls access to people, questionnaires, answers, dashboards and other resources. Security also depends on your organization's identity, device and hosting configuration.
Sign-in and access
Professional sign-in can use your organization's identity provider through single sign-on. Multi-factor authentication and account policies depend on the configured identity provider and instance; do not assume that every installation uses identical sign-in requirements.
Access rights determine who can read or edit a resource. Group membership and inherited rights can provide access in addition to direct grants. Sharing a dashboard does not by itself share every person's underlying answers.
A person's connection QR code is a credential, not just an identifier. Deliver it directly to the intended person and keep it out of screenshots, tickets and shared documents. Answer Now releases your professional session locally before a first-party handover; sign back in afterward.
Identifying information
When your installation uses the separate identity vault, identifying fields can be kept in the customer-controlled identity zone while the central application works with pseudonyms. This is a configured deployment boundary, not a guarantee that all entered content is anonymous. Administration configures the IdentityVault for the instance or for a single group.
Names entered into aliases, answers, tags or free-text fields may still identify a person. Follow your organization's rules on what belongs in each field.
Working with sensitive results
- Check the person and date range before displaying a dashboard or sharing results.
- Use read access when colleagues do not need to change data or permissions.
- Protect downloaded or printed information under the same rules as the source records. Revoking application access does not recall copies already made.
- Lock shared devices and avoid handing over a browser that still has professional access.
- Group chat messages show a self-chosen alias, but they are stored in readable form and are not end-to-end encrypted. Treat them as internal correspondence.
For unexpected access or a suspected disclosure, contact your organization's administrator through its approved incident-reporting channel. Record the affected resource and time without sending answers or connection credentials unnecessarily.
Hosting and responsibilities
See Data processing and hosting for processing boundaries, encryption, backups and responsibilities. This documentation is not a security certification or a substitute for your installation's contractual security measures.