Your employer cannot see what you personally answered — by construction, not by promise.
In the employee-survey category the central failure is that nobody believes the survey is anonymous — and usually they are right to doubt it. So this page does not ask you to trust us. It shows you the mechanism, and states its limits honestly.
For the legal statement of what we hold, why, and for how long, read the privacy notice.
- 01Individual answers are non-traceable at the aggregation boundary
- 02A slice with fewer than five respondents is suppressed, and shown as suppressed
- 03You can start anonymously, with no login
- 04An unfinished draft is purged within a bounded window
- 05Results are issued to the person who answered — only you can read yours
The non-traceability wall
Your response crosses into aggregation without an identity attached to carry. There is no join back. A continuous-integration check fails the build if that wall is breached, which means the wall cannot quietly erode between releases.
BOUNDARY
CI-ENFORCED
n ≥ 5 suppression — and why a gap in the data is the rule working
Organizations see distributions only. When a slice — a team, a location, a tenure band — has fewer than five respondents, it is suppressed, so no individual or small group is singled out. The dashboard says so plainly rather than showing an empty chart.
Anonymous start, bounded draft
You can begin with no account at all. Progress is held against a resume code you keep. If you never come back, the unfinished draft is purged within a bounded window after its time-to-live lapses, by a scheduled job. Not “the moment you close the tab”: a job runs, and it runs on a schedule. The TTL lives in one module so it can't drift into copy, and an automated test proves the job does its work.
Self-scoped results, and consent on the record
Your result is issued to you. Your answers do not silently become organizational data: an org assessment is a separate, sponsored, consented engagement, and the report it produces is built from distributions. Before such a run opens, the sponsor records that employee representation has been consulted where required, with a version and a timestamp, and the API refuses to open a run on provisional text. Two further declarations, on benchmarking and on being named publicly, are optional and a sponsor may decline either.
The honest limits, stated here rather than in fine print
We say no individual or small group is singled out in any slice. That is the claim the mechanism actually supports.
We say purged within a bounded window after the draft’s time-to-live lapses. The TTL lives in one module so it can’t drift into copy, and a test in the pipeline proves the job runs.
Scoring is deterministic and the pattern registry is written down in advance. There is no model interpreting your answers.
The instrument is young and the validation evidence doesn't exist yet. The registry and scoring are written down in advance so you can check the logic; the psychometrics come only with the data.
One path does reach an organization's report, and only one: a Leadership respondent who acknowledged the disclosure can have their own words quoted in it. Employee, partner and customer narrative is not eligible for that in any run.
Now that you know how it works, answer honestly.
That is the whole point of the mechanism: the instrument is only as good as the candour it can safely collect.