Ask Insights

Information Security and Data Governance

At Ask Insights, we recognise that psychological safety and data confidentiality are the foundational prerequisites for effective leadership development. This document outlines our data governance architecture, security protocols, and compliance mechanisms designed to protect client and participant information.

Last updated 28 August 2026

01Data classification and the confidentiality imperative

Our programmatic assessments require participants to evaluate personal fulfillment metrics, identify internal barriers, and provide candid written reflections. We classify this as highly sensitive personal data.

The efficacy of our DEI and leadership interventions relies entirely on an environment of uncompromising trust, allowing participants to share insights they may not disclose to their employers. For Ask Insights, strict confidentiality is not merely a compliance obligation; it is the core mechanism of our methodology.

02Infrastructure and encryption architecture

Our platform operates on enterprise-grade infrastructure with security embedded at every layer.

Application hosting
Hosted via Vercel, utilising global edge delivery. All traffic is strictly enforced over HTTPS with platform-managed TLS certificates.
Database infrastructure
PostgreSQL on Supabase, deployed on Amazon Web Services (AWS) in the Singapore region (ap-southeast-1).
Encryption in transit
End-to-end TLS encryption is mandated for all connections.
Encryption at rest
Handled natively by the underlying AWS storage layer.
Business continuity
Automated daily backups are maintained by our database provider.
Data sovereignty
For clients with strict regional data residency mandates, we can provision a dedicated, region-specific database architecture. This must be scoped and deployed prior to participant onboarding.

03Access management and segregation

We enforce the principle of least privilege across all systems.

Participant access
Strict Row-Level Security (RLS) within the database ensures that participants can only query and manipulate their own authenticated submissions.
Internal access
Access is restricted to designated personnel utilising managed @askinsights.com identities. There are no shared credentials, and no anonymous path to participant data.
Client visibility
Individual responses are never presented to an employer with identifiable markers attached. Clients are provided with aggregated, anonymised insights and are never granted direct database access.
Tenant isolation
Strict logical separation ensures zero cross-mingling of client data. One organisation’s data is never pooled or shared with another.

04Strict data minimisation protocol

We operate on a strict data minimisation framework. We collect only the participant’s name, professional email address, and their specific assessment responses. The complete question set is provided to clients prior to engagement.

We strictly prohibit the collection of:

  • ×Government-issued identity numbers, passports, or national registry identifiers
  • ×Financial, banking, or compensation data
  • ×Medical records, diagnoses, or biometric identifiers
  • ×Performance ratings or internal HR/appraisal data
  • ×Login credentials for any external system
  • ×Telemetry, device identifiers, or location-tracking data

05Data lifecycle and retention

Active engagement
Data is maintained throughout the program duration and the subsequent reporting cycle.
Post-engagement
Data is retained securely to facilitate longitudinal progress tracking should a participant return for future programs. Clients may stipulate shorter retention periods during the contracting phase.
Right to erasure
Executed upon formal written request from the client or individual participant. We provide formal written confirmation upon verifiable destruction of the data.

06Third-party vendor management (sub-processors)

To deliver our services, Ask Insights partners with vetted, enterprise-tier sub-processors.

ProviderPurposeRegion
VercelApplication hosting and deliveryUnited States / global edge
SupabaseManaged database infrastructureAWS Singapore
Amazon Web ServicesUnderlying infrastructureSingapore (ap-southeast-1)
AnthropicAutomated report synthesis via APIUnited States

Assessment responses are processed securely by Anthropic to generate written reports, but are explicitly restricted from being used to train any AI models. We do not monetise, license, or sell client data to any third party under any circumstances.

07Compliance, auditing, and transparency

We maintain total transparency regarding our security posture. While Ask Insights does not currently carry ISO 27001 or SOC 2 certifications, we provide robust bilateral assurance mechanisms for our enterprise clients, including:

  • ·Execution of comprehensive Data Processing Agreements (DPAs) prior to data collection.
  • ·Timely completion of client-specific vendor risk and security questionnaires.
  • ·Assignment of a designated information security liaison.
  • ·A strict 72-hour breach notification SLA in the event of an incident affecting your data.

08Client-hosted deployments

For organisations with internal governance mandates that require on-premises or internal-ecosystem data collection, we offer a modular deployment approach. Assessments can be executed via the client’s internal Microsoft Forms tenant, with Ask Insights conducting analysis via sanitised data exports. We provide the full build specification and question set to facilitate this.

09Information security inquiries

Direct all vendor security questionnaires, compliance agreements, deletion requests, and technical inquiries to security@askinsights.com. We maintain a standard response SLA of two business days.

Ask Insights · askinsights.com · This page describes the assessment platform used for Ask Insights programmes.