Information Security
This statement describes how FactorFactory protects the information you give us and what we do with it. It is written to be checked, not admired. If a security questionnaire needs more than is here, write to [email protected] and we will answer it directly.
Where your data lives
Our applications and databases run on Heroku, a Salesforce company, in the United States. Heroku's infrastructure holds SOC 2 Type II, ISO 27001, and PCI DSS attestations, which cover the platform we build on. FactorFactory itself has not been separately audited, and we do not claim otherwise. Card payments are handled by Stripe, so card numbers never reach our servers.
Encryption and access
- All traffic between your browser and our sites is encrypted in transit with TLS.
- Databases and backups are encrypted at rest by the hosting provider.
- Access to respondent data is limited to named accounts with a business need. Partner accounts see only their own respondents.
- Administrative access uses strong, unique credentials, and every change to assessment scoring is versioned and reviewable.
- Errors are monitored with Sentry, which is configured not to receive personal data.
Backups
Databases are backed up daily. Backups are retained for 35 days and then expire, so a deletion request is complete once that window has passed.
Assessment data, deletion, and norms
Assessment answers and scores are stored with the respondent's name and email so that reports can be delivered. On a verified request from the respondent or from the partner who ordered the assessment, we delete the identifying information: name, email, phone, and any free-text answers that could identify a person. De-identified responses and scores are retained for research and for developing the norms that make the assessments meaningful, and they cannot be linked back to the individual once identifying fields are removed. Requests are answered within 30 days.
Free tools
The free assessments on our sites record your answers, your scores, and your IP address, which we use to estimate general location and to prevent abuse. If you ask for a PDF report we also record the name and email you give us. You can ask us to delete any of it.
Companies that process data for us
- Heroku (Salesforce): Application hosting and PostgreSQL databases, United States
- Cloudflare: DNS, TLS termination, and bot protection
- Postmark: Transactional email delivery
- Stripe: Card payments. Card numbers never touch our servers
- Sentry: Error monitoring, configured not to send personal data
- Google Analytics: Aggregate site-usage statistics on the marketing sites
Employment testing
Our hiring assessments are designed to be used in a manner consistent with the EEOC's Uniform Guidelines on Employee Selection Procedures and with professional standards for psychological testing. "EEOC compliant" is not a certification anyone can hold, so we do not claim one. We do provide validity documentation and adverse-impact monitoring on request.
Reporting a security problem
If you find a vulnerability, email [email protected] with the subject line SECURITY ISSUE. We respond within one business day.
Last updated September 8, 2026.
Hiring applicants
Job applications are handled by our partner TeamLMI on hire.teamlmi.com and are covered by TeamLMI's security statement.
