At ePinionCenter, protecting your data is our highest priority. Our platform is built on enterprise-grade infrastructure that adheres to the most rigorous international security and privacy standards.
We maintain compliance with globally recognized security and privacy frameworks to ensure your data is always protected.
Our platform infrastructure maintains ISO 27001 certification — the internationally recognized standard for information security management systems (ISMS). This means rigorous controls are in place to protect the confidentiality, integrity, and availability of all data we handle.
SOC 2 Type II compliance demonstrates that our infrastructure provider has been independently audited over an extended period to verify that security, availability, and confidentiality controls are operating effectively — not just documented, but proven in practice.
ePinionCenter is committed to full compliance with the European Union's General Data Protection Regulation. We process personal data lawfully, transparently, and only for specified purposes. Panelists have the right to access, correct, or delete their data at any time.
We fully support the rights of California residents under the CCPA. Panelists can request to know what personal information is collected, request deletion, and opt out of any sale of their personal information. We do not sell personal data to third parties.
All panelist data is encrypted both at rest and in transit. We use industry-standard TLS 1.2+ for all data in transit and AES-256 encryption for data at rest, ensuring your personal information is protected at every stage.
We enforce strict role-based access controls (RBAC) across our entire platform. Internal staff access to panelist data is limited to what is necessary for their job function, following the principle of least privilege. All access is logged and regularly reviewed.
Privacy is not an afterthought — it is built into our platform from the ground up. We collect only the data necessary to operate the panel, provide clear consent mechanisms, and give panelists full transparency into how their data is used.
Our infrastructure undergoes regular vulnerability assessments and penetration testing. Security patches are applied promptly, and our development practices follow OWASP guidelines to minimize exposure to common web application vulnerabilities.
If you have questions about how we protect your data or our compliance certifications, please reach out to our support team.
Contact Us