Alchemer Raises Commitment to Security and Privacy, Completes SOC 2® Type 2 Examination

Jan 13, 2022 | Security

Global leader in survey, customer experience, and VoC technology completes rigorous audit demonstrating commitment to security, privacy, and regulatory compliance

LOUISVILLE, COLORADO, January 12, 2021 – Alchemer (formerly SurveyGizmo) – a global leader in Customer Experience (CX) and Voice-of-the-Customer (VoC) technology – announced today the successful completion of its Service Organization Control (SOC) 2 Type 2 examination, which demonstrates compliance with the leading industry standards for managing enterprise data. Alchemer requested this voluntary audit to further affirm its long-standing commitment to information and data security and privacy practices, ensuring policies, procedures and operations not only meet, but exceed the industry standards for security, availability, and confidentiality.

“Collecting and managing customer data is our core business. Completing the SOC 2 Type 2 examination demonstrates that we are taking the required steps to protect our customers’ data,” said David Roberts, CEO of Alchemer. “Alchemer has long been at the forefront of ensuring data security and privacy, and we will continue to invest heavily in fiercely safeguarding customer data.”

In 2019, Alchemer completed a SOC 2 Type 1 examination. The SOC 2 standard validates that systems are established to manage the security, availability, processing integrity, confidentiality, and privacy of customer data. Alchemer’s data centers are now all SOC 1 (financial systems), SOC 2 (information systems), and SOC 3 (business systems) certified.

About SOC 2 Certification

The American Institute of CPAs (AICPA)’s Service Organization Control established the Security Operations Center (SOC) standard as a means to assure customer data security in different systems. The SOC 2 standard focuses on information systems, assuring customers that they have been audited for customer data security, availability, processing integrity, confidentiality, and privacy. In addition to the technical audit, there is a requirement for the company to document and follow comprehensive information security policies and procedures.

SOC 2 applies to organizations that store customer data in the cloud, which includes virtually every SaaS (Software as a Service) company, such as Alchemer. SOC 2 Type 1 assesses the design of security processes at a specific point in time, while a SOC 2 Type 2 report assesses the effectiveness of those controls over time by observing operations for six months.

About Alchemer 

Alchemer (formerly SurveyGizmo) offers the world’s most flexible feedback and data collection solution, with twice as many question types and a low-code design that allows innovative thinkers across organizations to solve real business problems cost-effectively. Alchemer serves more than 15,000 global customers and 30% of the Fortune 500. For more information about Alchemer visit Alchemer.com.

 

 

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more