How can we help you?

FeraSurvey Security and Data Protection

Product: FeraSurvey Topic: Administration and Security Versions: Applies to all documented versions Current

Apply layered controls to survey content, respondent data, links, exports, and integrations.

Audience: Security administrators and product owners
Editorial status: Public
Product: FeraSurvey

Overview

Apply layered controls to survey content, respondent data, links, exports, and integrations.

Key points

  • Dashboard access uses FeraAuth tokens and instance scoping.
  • Public links are one-time-revealed bearer secrets backed by stored hashes.
  • Identity modes range from anonymous to invitation only.
  • Resume tokens, versions, and idempotency support safe response continuity.
  • Exports can include respondent identity.
  • Webhook endpoints and secrets require SSRF controls and secure storage.

Recommended procedure

  1. Classify the survey data and identity requirements.
  2. Choose the least permissive distribution and access model that meets the need.
  3. Protect links, tokens, exports, and integration secrets.
  4. Audit administrative actions and test isolation, retention, and recovery.

Troubleshooting

Sensitive data is exposed

Disable or rotate affected access, preserve evidence, and follow the incident procedure.

The policy is unclear

Keep the article in draft until product, engineering, security, and legal approve the contract.

Related documentation