Hearsay is built for evidence, so protecting the data you collect and share is part of the product. This article summarizes the controls that apply to your data. For what gets collected and who can see it, see What Hearsay can and cannot access.
Compliance
Hearsay is SOC 2 Type II compliant.
Encryption
Customer data is classified as confidential, Hearsay's highest data class. It is encrypted at rest and in transit over public networks, and backups are encrypted.
Access
Access to customer data is restricted to specific roles, and the systems that hold it do not allow unauthenticated or anonymous access. Customer data is not used or stored in non-production environments.
Your phone backup and your bank login
For phone collections, the backup is saved on the computer where the collection ran, not in the cloud, and data leaves that computer only at the sharing step. For bank records, Hearsay connects through Plaid; your bank username and password are never shared with Hearsay. See How do I collect financial records?.
Retention and deletion
The account holder controls access to and use of the data shared into their account, and Hearsay deletes data at the account holder's direction. Personal information is deleted or de-identified as soon as it no longer has a business use, and on a verified request from the person it belongs to where Hearsay has no legal obligation to keep it.
Reporting a security concern
Email [email protected] and describe the incident or observation along with any relevant details.
Related articles
