Appendix A. Trust, security, integrations
A.1 Security posture
| Control | Commitment |
|---|---|
| Certification path | SOC 2 Type I at GA; Type II within 12 months; ISO 27001 within 18 months |
| Identity (firm) | OIDC SSO at MVP; SAML 2.0 and SCIM in v1.1; MFA enforced for Partner, EM, Firm Admin |
| Identity (client) | Magic link or client SSO for portal users; respondents via tokenized links, no accounts |
| Encryption | TLS 1.2+ in transit; AES-256 at rest; envelope encryption with per-firm KEK and per-workspace DEK; optional customer-managed keys at Firm tier |
| Tenant isolation | Schema per client workspace; row-level security; no cross-workspace query path; Book pool holds aggregates only |
| Residency | US, EU at MVP; UK v1.1; AU v2. Workspace residency set at creation and immutable; video stored in the same region |
| Access | Least privilege by role and engagement; contractor assignments expire; identifiable-data access requires a purpose and is time-boxed |
| Audit | Append-only, hash-chained per workspace; views of identifiable data, exports, approvals, publishes, permission changes, purges, AI runs |
| Retention | Contact data purged at wave close + 30 days (default); video default 12 months; microdata per contract; one-click workspace purge by crypto-shredding |
| Testing | Annual third-party pen test; anonymity-engine fuzzing in CI; tenant-isolation tests on every release |
A.2 AI policy
- Runtime AI features (theme coding, transcript processing, Insight drafts) run on providers under zero-data-retention terms.
- No training or improvement of foundation models on client content unless the firm opts in at firm level and the client's contract flag allows it. Both default to off. The UI shows the state of both switches on every workspace.
- AI never sees direct identifiers: text and transcripts are redacted before processing.
- AI outputs are drafts. See Insight Object spec §6.7.
A.3 Legal playbooks built into launch
| Regime | What OrgDiagnostic generates or enforces |
|---|---|
| GDPR / UK GDPR | Privacy notice per language; lawful-basis record (typically legitimate interests for the client as controller); DPIA template pre-filled with data flows; sub-processor list; data-subject request workflow (access and erasure at the response level where the respondent can prove their token) |
| CCPA / CPRA | Notice at collection; opt-out of sale/sharing not applicable (no sale) stated plainly |
| Works councils (DE, FR, NL, AT and others) | Works-council mode (§5.10), review packet, frozen instrument, observer role |
| Unions (US, UK, AU) | Higher-k option, no individual-level export, site-level reporting defaults |
Roles: the client is the controller for employee data; the firm is a processor (or joint controller where the engagement contract says so); OrgDiagnostic is the firm's sub-processor. Templates reflect this chain.
A.4 Integrations
| Direction | Systems | MVP | v1.1 | v2 |
|---|---|---|---|---|
| HRIS in | CSV | ✓ | ||
| Workday, BambooHR, Rippling, Personio | ✓ | |||
| SAP SuccessFactors, ADP | ✓ | |||
| Comms out | Email (firm sending domain, SPF/DKIM) | ✓ | ||
| Outlook / Gmail send-as | ✓ | |||
| Slack, Microsoft Teams, SMS, WhatsApp Business | ✓ | |||
| Deliverables out | PowerPoint (firm master), PDF, Excel | ✓ | ||
| Google Slides, SharePoint, Box, Drive | ✓ | |||
| Notion | ✓ | |||
| Legacy in | Generic CSV wave import with item mapping | ✓ | ||
| Qualtrics, Culture Amp exports | ✓ | |||
| Structure in | Orgvue, org-chart tools | ✓ | ||
| CRM | HubSpot, Salesforce (engagement record, stage sync) | ✓ |
Integration rules: HRIS connectors are read-only and snapshot-based (a wave uses a frozen Population); credentials are stored per client workspace; any connector can be revoked by the client admin.