Security at Zigpoll

How we protect your data and your customers' responses.

Security Overview

Last reviewed: 9 August 2026

1. Overview

Zigpoll (operated by Argonautic Labs LLC) is trusted by thousands of businesses to collect customer feedback. Protecting the confidentiality, integrity, and availability of that data is core to how we build and operate our platform. This page summarizes the technical and organizational measures we use to keep your data safe.

2. Compliance

  • SOC 2 (Security): Zigpoll is actively pursuing SOC 2 attestation, with our security program continuously monitored through Vanta, an automated compliance platform.
  • GDPR: We support our customers' obligations under the GDPR. Our Data Processing Agreement and Transfer Impact Assessments are publicly available.
  • PCI DSS: Zigpoll never stores or processes payment card data on its own systems; all payments are handled by PCI-certified processors. See our PCI Compliance page.

3. Infrastructure Security

  • Zigpoll's production services are hosted on Amazon Web Services (AWS), which maintains industry-leading physical and environmental security certifications including SOC 2 and ISO 27001.
  • Deployments are performed through managed, versioned rolling deployments with health monitoring and rollback capability. Every production release is tracked and attributable.
  • Platform availability is published in real time on our status page.

4. Data Protection

  • All data transmitted between your users, your systems, and Zigpoll is encrypted in transit using TLS.
  • Access to production systems and customer data is restricted to authorized personnel with a legitimate business need.
  • Customer data is collected and processed in accordance with our Privacy Policy, and can be exported or permanently deleted upon request.
  • Payment card data is handled exclusively by our PCI-certified payment processors (Stripe and Shopify) and never touches Zigpoll's servers.

5. Application Security

  • All code is maintained in version control, and changes are reviewed before being released to production.
  • Production TLS configurations are continuously monitored for known weaknesses and outdated cipher suites.
  • Authentication to the Zigpoll dashboard and APIs uses industry-standard mechanisms, and API access is scoped with per-account keys.

6. Organizational Security

  • Zigpoll maintains a suite of information security policies — covering access control, incident response, data management, cryptography, secure development, and third-party risk — that are reviewed at least annually.
  • Vendors with access to customer data are inventoried and assessed as part of our third-party risk management program.

7. Reporting a Vulnerability

If you believe you have discovered a security vulnerability in Zigpoll, we want to hear from you. Please email [email protected] with the details, and we will investigate promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to address it.

8. Contact

Start collecting feedback in 5 minutes.

Try our no-code surveys that visitors actually answer.

Questions or Feedback?

We are always ready to hear from you.