Security and trust at Polst
Organizations use Polst to turn audience input into decisions they can stand behind. That only works if the data is well protected and the results are honest, so security and integrity are built into how the product works.
Last updated: September 2026
How we think about security
Polst exists to turn real audience input into decisions our customers can defend. A decision is only as trustworthy as the data behind it, so we treat security and response integrity as core parts of the product rather than features bolted on afterward.
We keep our practices deliberately simple, which means we can actually maintain them and explain them plainly. The sections below describe how we protect your data and how we keep the results honest.
Encryption
We encrypt data in transit and at rest. Traffic between your browser and Polst is protected with modern transport encryption, and the data we store is encrypted on disk. Encryption keys are managed securely and are never exposed in our application code.
Authentication and access
You can sign in to Polst with a work email and password or through a supported OAuth provider, whichever your team prefers. Accounts that sign in through an OAuth provider inherit that provider's protections, including multi-factor authentication where your organization has enabled it.
Inside Polst, access to production systems and customer data is limited to the people who need it to run the service, and administrative actions are logged so there is a record of who did what.
Response integrity and trust scoring
Most of what makes Polst trustworthy happens the moment a vote is cast. Every response runs through a set of checks designed to keep results honest. We verify device and session identity, rate-limit by network to slow abuse, prevent duplicate voting on the same question, and require a minimum time on screen so a vote reflects genuine attention rather than a reflexive tap.
On top of those checks, we use behavioral signals to flag likely bot activity and coordinated manipulation. The outcome is a trust signal that travels with the data, so the people acting on a result can see how much weight it deserves before they make a call.
Privacy by default for respondents
People answer Polst questions without creating an account and without handing over personal information. We record the choice, a timestamp, and general context such as approximate region and device type. We do not build individual respondent profiles, and we never sell personal information.
Respondents see aggregated results in exchange for their input. That trade keeps participation voluntary, anonymous, and fair.
Public and private data stay separate
Polst runs a public network of questions alongside private, customer-owned programs. Private questions and internal sentiment programs are isolated from the public network. Your private data does not surface in public pages, shared feeds, or search, and it is never mixed into anyone else's results.
Your data, your control
You can export your data at any time, and you control how long it is kept through configurable retention settings. If you close your account, we remove your personal information on a defined schedule, though aggregated and anonymized results may remain as part of the public network where they apply.
Polst is designed to support GDPR, UK GDPR, and CCPA requirements, and enterprise customers can request a Data Processing Addendum. For a data request or a region-specific question, contact privacy@polst.io.
Content moderation and safety
Because anyone can create a question, we moderate the network. We use keyword filters and blocklists, a report button on public content, rate limits, and an internal review queue so our team can act on flagged questions quickly. Clear policies govern sensitive categories, and creators can always see the status of content they publish.
Reporting a vulnerability
If you believe you have found a security issue, we want to hear about it. Email security@polst.io with the details and we will investigate promptly and keep you posted. We value the researchers who help keep Polst safe, and we will not pursue good-faith research that respects our users' privacy and data.
Talk to us
For security questions, documentation requests, or a conversation about the controls your organization needs, contact security@polst.io.
Built to be trusted with your audience.
Real protection for your data, honest results you can act on, and privacy by default, so you can collect feedback with confidence.