Appendix A. Trust, security, integrations

A.1 Security posture

Control Commitment
Certification path SOC 2 Type I at GA; Type II within 12 months; ISO 27001 within 18 months
Identity (firm) OIDC SSO at MVP; SAML 2.0 and SCIM in v1.1; MFA enforced for Partner, EM, Firm Admin
Identity (client) Magic link or client SSO for portal users; respondents via tokenized links, no accounts
Encryption TLS 1.2+ in transit; AES-256 at rest; envelope encryption with per-firm KEK and per-workspace DEK; optional customer-managed keys at Firm tier
Tenant isolation Schema per client workspace; row-level security; no cross-workspace query path; Book pool holds aggregates only
Residency US, EU at MVP; UK v1.1; AU v2. Workspace residency set at creation and immutable; video stored in the same region
Access Least privilege by role and engagement; contractor assignments expire; identifiable-data access requires a purpose and is time-boxed
Audit Append-only, hash-chained per workspace; views of identifiable data, exports, approvals, publishes, permission changes, purges, AI runs
Retention Contact data purged at wave close + 30 days (default); video default 12 months; microdata per contract; one-click workspace purge by crypto-shredding
Testing Annual third-party pen test; anonymity-engine fuzzing in CI; tenant-isolation tests on every release

A.2 AI policy

  • Runtime AI features (theme coding, transcript processing, Insight drafts) run on providers under zero-data-retention terms.
  • No training or improvement of foundation models on client content unless the firm opts in at firm level and the client's contract flag allows it. Both default to off. The UI shows the state of both switches on every workspace.
  • AI never sees direct identifiers: text and transcripts are redacted before processing.
  • AI outputs are drafts. See Insight Object spec §6.7.

A.3 Legal playbooks built into launch

Regime What OrgDiagnostic generates or enforces
GDPR / UK GDPR Privacy notice per language; lawful-basis record (typically legitimate interests for the client as controller); DPIA template pre-filled with data flows; sub-processor list; data-subject request workflow (access and erasure at the response level where the respondent can prove their token)
CCPA / CPRA Notice at collection; opt-out of sale/sharing not applicable (no sale) stated plainly
Works councils (DE, FR, NL, AT and others) Works-council mode (§5.10), review packet, frozen instrument, observer role
Unions (US, UK, AU) Higher-k option, no individual-level export, site-level reporting defaults

Roles: the client is the controller for employee data; the firm is a processor (or joint controller where the engagement contract says so); OrgDiagnostic is the firm's sub-processor. Templates reflect this chain.

A.4 Integrations

Direction Systems MVP v1.1 v2
HRIS in CSV ✓
Workday, BambooHR, Rippling, Personio ✓
SAP SuccessFactors, ADP ✓
Comms out Email (firm sending domain, SPF/DKIM) ✓
Outlook / Gmail send-as ✓
Slack, Microsoft Teams, SMS, WhatsApp Business ✓
Deliverables out PowerPoint (firm master), PDF, Excel ✓
Google Slides, SharePoint, Box, Drive ✓
Notion ✓
Legacy in Generic CSV wave import with item mapping ✓
Qualtrics, Culture Amp exports ✓
Structure in Orgvue, org-chart tools ✓
CRM HubSpot, Salesforce (engagement record, stage sync) ✓

Integration rules: HRIS connectors are read-only and snapshot-based (a wave uses a frozen Population); credentials are stored per client workspace; any connector can be revoked by the client admin.