An EVP is assembled from what employees say when they are being candid: engagement data, exit conversations, research they agreed to give you. That is among the most sensitive material a people function holds, so the platform was built on three principles rather than one policy page.
Separated by organization
Protected by role
Governed by you
Isolation is a property of the infrastructure, not a promise about our code.
Every row carries a customer identifier, and the application is trusted to filter on it correctly in every query, forever. One missed filter exposes every customer in the table.
Each customer runs in a dedicated, isolated database, separated at the infrastructure level. There is no shared table to filter, so no query can return another customer's evidence or strategy.
Logical separation is cheaper to run. It was rejected because EVP, engagement and strategy data is confidential enough that a single coding mistake should not be able to disclose it.
Customer data is held in the region of your choice, so residency follows your own regulatory and contractual requirements rather than ours.
Encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Encryption keys are managed by our cloud infrastructure provider.
You should not have to maintain a second list of who works here. Authentication happens against your directory, and what each role can see and do is yours to configure.
Enterprise single sign-on, so authentication happens against your identity provider and your existing controls, including multi-factor policy, apply here unchanged.
Automated provisioning and de-provisioning through SCIM. When somebody leaves your directory, their access here ends with it rather than waiting for anyone to remember.
A configurable role matrix, set per organization. Approval rights, publishing rights and visibility of sensitive evidence are separable, so the person who can read research is not necessarily the person who can publish from it.
Internal support access to a customer environment is consent-gated and read-only. There is no standing administrative access to your data.
Why Here keeps an append-only, tamper-evident audit trail of security and governance events across your tenant: sign-ins and support-access sessions, member invitations, removals and role changes, data exports and erasures, settings and configuration changes (including changes to this retention setting), plan changes, and the creation, approval and publishing of EVP and content.
Each entry records who acted, what changed, and when, and records cannot be edited or deleted. Retention is set by your administrators: keep for the life of the account (the default), 24 months, or 12 months. Your administrators can review the full trail in the platform, filter it, and export it as CSV for your own compliance evidence.
APPEND-ONLY · REVIEWABLE AND EXPORTABLE IN-PLATFORM
The clearest way to describe an AI product's governance is to state what it is allowed to do and what it is structurally prevented from doing. Both lists are enforced in the system rather than described in a policy.
A human remains accountable for every consequential action.
The AI proposes and drafts. A person approves before anything reaches a candidate, an employee or a public channel. Reputation replies are always gated behind human approval, because an automated response to a review is where an AI product would do the most damage.
Research and evidence surface by role, never by a person's name. This is a rule of the product, enforced in the system, not a setting an administrator can switch off. It is also the reason employees tell you the truth in the first place.
Employee research is captured in research mode: never briefed, never in brand mode, never published. Produced brand content is a separate path by design, so somebody speaking candidly is not accidentally quoted in a campaign.
In line with EU AI Act transparency expectations, the assistant is clearly disclosed as AI to the people using it. It is not presented as a colleague.
Every piece of advice shows what it was grounded in, so the reasoning can be checked. The mechanism is described on Intelligence.
Customer content and evidence are not used to train public foundation models. Each organization can run on its own approved model provider, so processing stays within an arrangement your security team has signed off.
Employees are the source of everything valuable here, which makes their consent and their anonymity the foundation the product rests on rather than a compliance afterthought.
An employee gives evidence
A survey response, an interview, or their own photo or video.
A consent record is captured
Before contributed media can be used, in line with GDPR. Likeness is not treated as content the organization simply owns.
Their identity is separated
The contribution is held so that no output can attribute it to them by name.
Surfaced by role and audience
The insight reaches the people who need it, attributed to a role rather than a person.
Evidence is surfaced by role and audience, never attributed to a named individual. Read as a privacy guarantee rather than a feature: an employee can tell you something uncomfortable without it becoming attributable to them.
We process your data as your processor under a Data Processing Agreement (available on request), with Standard Contractual Clauses covering any sub-processing outside the EEA.
Data-subject requests are supported in the platform: an administrator can export or permanently erase an individual's data, and every such action is itself written to the audit trail.
DPA ON REQUEST · SCCS FOR SUB-PROCESSING OUTSIDE THE EEA
Your data is retained for the life of your account and stored in the EU (Paris region). At any time you can export or delete it.
On termination we return your data as a portable export, then delete it from production and backups within 35 days.
PORTABLE EXPORT · DELETED WITHIN 35 DAYS OF TERMINATION
Four assurance areas, with the detail a reviewer needs behind each rather than in front of everybody else.
Authentication runs through your identity provider, and provisioning follows your directory. Within the platform, a configurable role matrix governs which modules and actions each role can reach.
Internal support access to a customer environment is consent-gated and read-only. There is no standing administrative access.
Why Here automatically checks the health of its third-party integrations every six hours. The Integration Health Monitor checks connected services and APIs, including data providers, email services and AI model providers, and alerts platform administrators when a connection is failing.
Background-job failures are also mapped to the affected service area, so operational issues can be surfaced against the right component rather than disappearing silently.
Automated health check · every 6 hours
Why Here is connected to Instatus for public service-status reporting. Background-job failures are routed to the relevant platform component, so a service issue can be reflected against the part of the platform it affects.
API · Ingestion · Video · AI · Notifications
This creates a clear path from internal monitoring to external service visibility, rather than relying on issues to be discovered and communicated manually.
We publish live service status and incident history on our public status page, and notify affected customers of material incidents.
Changes are version-controlled and peer-reviewed, ship through an automated pipeline with staging separated from production, and can be rolled back.
An independent penetration test is run at least annually, with ongoing dependency and vulnerability monitoring between tests.
We name our sub-processors: hosting and database (Supabase, on AWS in the EU), application and web hosting (Railway and Vercel), identity and single sign-on (WorkOS), email (SendGrid), video (Cloudflare Stream), transcription (Deepgram and Azure Speech), meeting capture (Recall.ai), public-data collection (Bright Data and Apify), your chosen AI model provider, and status reporting (Instatus). The current list is maintained in your data processing agreement.
No vague promises. Here is what is live today, and what is available on request.
Our information security management system is certified to ISO 27001.
A dedicated, isolated database per customer, separated at the infrastructure level.
Customer data held in the region of your choice.
Enterprise SSO with automated provisioning and de-provisioning.
Per-organization control of who can see and do what.
Nothing outward-facing goes live without a person approving it.
Enforced in the system, not offered as a setting.
Research insight cannot cross into published content.
Captured before an employee's photo or video can be used.
The assistant is disclosed as AI to the people using it.
Shared with your security team on request.
DPA available on request, with Standard Contractual Clauses covering sub-processing outside the EEA.
Bring your security, IT or procurement team. We will walk through the architecture, controls, data model and AI governance with them directly, rather than sending a questionnaire back and forth.