What should an employee survey vendor security checklist cover?
The short answer is six areas: certifications and audit evidence, data handling and encryption, access control and SSO, hosting and data residency, privacy and anonymity plus AI, and incident response and support. Cover all six before you sign, not just the one your last vendor happened to volunteer. Start from CultureMonkey's security and compliance page to see how one vendor presents this, then hold every finalist to the same bar.
- Certifications and audit evidence
- Ask for a current SOC 2 report and an ISO 27001 certificate, plus a recent penetration-test summary (an independent hacker-style test of the system's defences), so the vendor's security is independently verified rather than self-asserted.
- Data handling and encryption
- Confirm encryption in transit and at rest (so data is protected both while it travels and while it is stored), a written retention and deletion policy, a full sub-processor list (third-party tools or services the vendor uses to process your data), and a committed breach-notification timeframe in writing (how quickly they are required to tell you if something goes wrong).
- Access control and SSO
- Require SAML/IDP-based single sign-on (the technical handshake that connects your company's existing login system to the survey tool), role-based least-privilege access, and page-level security over who sees which results.
- Hosting and data residency
- Ask where the data is hosted and with which cloud provider, and whether you can choose or confirm the specific region your survey data lives in.
- Privacy and anonymity plus AI
- Look for configurable anonymity thresholds, the ability to hide free-text and names below them, and clear, per-feature control over any AI analysis of survey comments.
- Incident response and support
- Expect a documented incident-response process, a named security contact or escalation path, and responsive support if you detect a suspected security issue.




