Information Security

This statement describes how FactorFactory protects the information you give us and what we do with it. It is written to be checked, not admired. If a security questionnaire needs more than is here, write to [email protected] and we will answer it directly.

Where your data lives

Our applications and databases run on Heroku, a Salesforce company, in the United States. Heroku's infrastructure holds SOC 2 Type II, ISO 27001, and PCI DSS attestations, which cover the platform we build on. FactorFactory itself has not been separately audited, and we do not claim otherwise. Card payments are handled by Stripe, so card numbers never reach our servers.

Encryption and access

Backups

Databases are backed up daily. Backups are retained for 35 days and then expire, so a deletion request is complete once that window has passed.

Assessment data, deletion, and norms

Assessment answers and scores are stored with the respondent's name and email so that reports can be delivered. On a verified request from the respondent or from the partner who ordered the assessment, we delete the identifying information: name, email, phone, and any free-text answers that could identify a person. De-identified responses and scores are retained for research and for developing the norms that make the assessments meaningful, and they cannot be linked back to the individual once identifying fields are removed. Requests are answered within 30 days.

Free tools

The free assessments on our sites record your answers, your scores, and your IP address, which we use to estimate general location and to prevent abuse. If you ask for a PDF report we also record the name and email you give us. You can ask us to delete any of it.

Companies that process data for us

Employment testing

Our hiring assessments are designed to be used in a manner consistent with the EEOC's Uniform Guidelines on Employee Selection Procedures and with professional standards for psychological testing. "EEOC compliant" is not a certification anyone can hold, so we do not claim one. We do provide validity documentation and adverse-impact monitoring on request.

Reporting a security problem

If you find a vulnerability, email [email protected] with the subject line SECURITY ISSUE. We respond within one business day.

Last updated September 8, 2026.

Hiring applicants

Job applications are handled by our partner TeamLMI on hire.teamlmi.com and are covered by TeamLMI's security statement.