Security at
Customer Thermometer
Customer Thermometer is trusted by thousands of teams across the world to ask for, log and act on customer and employee feedback. Our product, technical and development teams work hard to ensure that all of Customer Thermometer’s code and infrastructure is secure.
Data Privacy
- We take the security of your data extremely seriously.
- Credentials that you use to connect your accounts to Customer Thermometer are protected with salted and stored as a one-way hash. Customer Thermometer employees have no access to any stored passwords.
- The only action that Customer Thermometer takes within your accounts are those to send and log survey feedback and support you as a user if you request it.
- You can delete any data you wish, at any time. You can also export it either on an automated basis using our API or webhooks, or manually as a CSV.
- Customer Thermometer is registered with the UK’s Information Commissioner’s Office
- For further information on how your data is managed at Customer Thermometer, refer to our Privacy Policy here and our Terms of Use here.
GDPR
Customer Thermometer has been fully GDPR compliant since May 25th, 2018. Read our GDPR Commitment Statement here.
CCPA
Customer Thermometer has been fully CCPA compliant since January 1st, 2020. Read our CCPA Commitment Statement here.
PCI
Our credit card processors, Recurly & Stripe are certified to PCI Service Provider Level 1. This is the most stringent level of certification available.
HIPAA
Customer Thermometer does not claim HIPAA compliance, and cannot advise on how Customer Thermometer usage may or may not comply with your specific requirements.
Account Security
- There are a number of safeguards and access controls in place to ensure the security of access to your Customer Thermometer account
- SAML/SSO – Customer Thermometer provides integration with external identity and Single Sign On providers for our enterprise clients. Our integration partners include PingOne, SiteMinder and Okta and the site is optimised to easily integrate with many other SSO and SAML solutions
Customer Data
Customer Thermometer will never share any customer contact data uploaded to the Customer Thermometer application with third parties.
Customer Thermometer employees will never access any customer contact data uploaded to the Customer Thermometer application, unless specifically authorized to do so by the account holder. Even then, strict controls are in place to ensure security and integrity.
- Firewalls on all servers are set to default-deny. The only services that are allowed are SSH (via a non-standard port) and HTTP/HTTPS (web servers only).
- Database connections are only accepted from other Customer Thermometer servers on the internal network.
- All communication with servers (outside of public HTTP/HTTPS access) is over encrypted secure shell (SSH) and only between a restricted and approved list of white labelled IP addresses.
- Reporting data accessed remotely can only be done via your API key and only via HTTPS.
- All network communication secured with TLS (Version 1.2 and 1.3 available)
- Survey data is processed and stored on Microsoft Azure managed databases, located in the UK
Pentests and Audits
Threat Detection and Management is central to our security approach and external Pentests and audits are regularly carried out with certificates available on request.
Audit & Logging
Customer Thermometer maintains a comprehensive log of all user activities. Surveys and responses are extensively logged internally for troubleshooting and support. These logs are securely stored and only accessible by privileged users. For each log entry, the IP address is captured. Logs are stored for a maximum of 90 days. For responses, we capture the IP address and user-agent string. The IP address is used to geolocate the responder at a city level. All logging data is available within the Customer Thermometer account and exports.
Security Monitoring
Customer Thermometer has a number of quality controls and monitoring in place to ensure the application remains secure. We have a gated release procedure that has strict definitions and requirements to be met prior to a deployment. All changes have in-depth testing carried out with stakeholder and CTO level approval. Peer code reviews are carried out as part of our approval process. Each deployment is tagged and logged and shared via our change log documentation. Penetration and security testing is regularly carried out.
Application Reliability
Domain Name Service (DNS): Our DNS is managed by Cloudflare, one of the fastest, most reliable DNS network in the world.
Application redundancy: hot standby servers, ready for failover in the event of hardware failure of our live database or application servers.
Secure remote offsite database backup is completed every hour with a key strength of 2048 bit RSA.
Our system status page is kept updated with releases and outages.
Available Documentation
We have the following available documentation available on request for our customers’ InfoSec teams:
- Acceptable Use Policy
- Application Architecture
- Backup Test Plans
- Business Continuity Test Plans
- Data Classification Policy
- Datacenter Accreditations
- Incident Reporting Plan
- Information Security Policy
- Logging Policy
- Non Disclosure Agreement
- Patch Management Policy
- Security Requirements Documentation
- Data Retention Policy
- Risk Assessments
- Penetration Test Certification
Need more information?
If you need any more information on our security and privacy policies, please get in touch and we’ll be happy to help.
Get in touch