We take data security very seriously.
Your HR and payroll data is encrypted in transit and at rest, retained for the length of the engagement plus 90 days, then deleted automatically or on request. Healthcare engagements run under a Business Associate Agreement.
Built on Amazon Web Services.
Our platform runs on Amazon Web Services (AWS). Sign-in and password protection use AWS security, and your data is encrypted in transit and at rest.
Encryption
TLS 1.2 or higher in transit and AES-256 at rest.
Secure upload
Send us a spreadsheet or a download from your HR system through our secure portal. We do not need an API or any integration.
Retention and deletion
Data is kept for the length of the engagement plus 90 days, then deleted automatically or on request.
Healthcare
For healthcare engagements, we work under a Business Associate Agreement and limit protected health information to what the diagnostic model requires.
SOC 2 Type I
In progress, targeting Q1 2027.
Common questions about security
Do you need access to our HR system?
No. We do not need an API or any integration, and we never need write access. We built EIP for companies that may not have a full HR system. We tell you exactly which fields we need. Send them as an Excel file or a download from your HR system, through our secure portal. Your data is encrypted in transit and at rest, and deleted 90 days after the engagement ends. For healthcare clients, we work under a Business Associate Agreement.
How secure is the data?
Your data is encrypted in transit and at rest on Amazon Web Services. For a free pilot, we ask for anonymized data, so you can remove names, addresses, and employee ID numbers, and results come back by code and group, without names. In a full engagement, we split your data into two files. In the first, every employee has a unique code and no name. We do our analysis on that file as a blind study, and our Council of advisors sees only coded information. A separate file links each code to a person. Only three members of the EIP team can see it, all under NDAs, and our Council members are also under NDAs. We use names only where the work needs them, such as Honest Read interviews and listening sessions. We do not share client data with third parties. Amazon Web Services stores it under the encryption described above. We never need write access to your systems, and we delete your data 90 days after the engagement ends. For healthcare clients, we work under a Business Associate Agreement. SOC 2 Type I is in progress, targeting Q1 2027.
How long do you keep our data?
We keep data for the length of the engagement plus 90 days, then delete it automatically or on request.
Is EIP SOC 2 certified?
SOC 2 Type I is in progress, with a target of Q1 2027.
How does EIP handle healthcare data?
For healthcare engagements, we work under a Business Associate Agreement and limit protected health information to what the diagnostic model requires.