1. Overview
This Security Overview describes the general security measures Kommon Poll uses to protect the Service and customer information. It is intended to help customers understand our approach to security without disclosing sensitive implementation details.
2. Security governance
We use administrative, technical, and organisational safeguards appropriate to the nature of Kommon Poll as a SaaS social listening and intelligence platform.
- Security responsibilities are assigned internally based on role and access need.
- Access to production systems and customer information is limited to authorised personnel and contractors with a legitimate business need.
- Internal access may be reviewed, changed, or revoked as roles change.
- Personnel and contractors with access to confidential information are expected to follow confidentiality obligations.
3. Account and access controls
Kommon Poll supports account-based access for customers and authorised users. Customers are responsible for managing their own users, passwords, permissions, and account hygiene.
Where technically available, we use access controls, role limitations, secure authentication workflows, password protection, session controls, and administrative safeguards to reduce unauthorised access risk.
4. Data protection measures
- We use encrypted connections, such as HTTPS/TLS, for access to the website and application where available.
- Customer information is stored in controlled systems and infrastructure used to provide the Service.
- Backups, logs, and operational copies may be maintained for reliability, security, troubleshooting, and recovery.
- Access to Customer Data is limited based on operational, support, security, legal, or contractual need.
- Payment information is handled through payment providers where configured, rather than being stored directly by Kommon Poll unless expressly stated.
5. Application and infrastructure security
We aim to maintain secure development and operational practices proportionate to the Service, including:
- reasonable controls for deployment, configuration, and infrastructure access;
- monitoring of relevant systems, logs, errors, and security events;
- reviewing and addressing material vulnerabilities based on severity and operational risk;
- using reputable infrastructure, cloud, email, payment, support, and AI providers; and
- separating customer access so that one customer should not be able to access another customer's account through normal product use.
6. Vendors and subprocessors
We use selected vendors and subprocessors to provide hosting, cloud infrastructure, AI processing, data collection, email, support, payments, analytics, and related operations.
We aim to choose vendors with security practices appropriate to their role and to impose contractual obligations where they process Customer Data. See the Subprocessors page for more detail.
7. Security incidents
If we become aware of a confirmed security incident affecting Customer Data, we will investigate and take reasonable steps to contain, mitigate, and remediate the incident.
Where required by applicable law or contract, we will notify affected customers without undue delay and provide information reasonably available to us, subject to security, legal, and investigative limitations.
8. Customer responsibilities
Security is shared between Kommon Poll and each customer. You are responsible for:
- using strong, unique passwords and protecting account credentials;
- limiting access to appropriate authorised users;
- removing users who no longer need access;
- protecting exported reports, downloaded files, API tokens, and integrations;
- maintaining appropriate internal controls over searches, reports, alerts, and data exports; and
- promptly notifying us of suspected unauthorised access or misuse.
9. Vulnerability reporting
If you believe you have found a vulnerability in Kommon Poll, email help@kommonpoll.com with a description, affected URL or feature, reproduction steps, screenshots if safe to share, and your contact details.
Do not exploit, access, modify, delete, download, disclose, or disrupt data that does not belong to you. Testing must be limited, safe, and non-destructive.
10. Updates
We may update this Security Overview as our practices, vendors, infrastructure, product features, or legal requirements change.