We take data security very seriously.
Your workforce data is encrypted in transit and at rest, retained for the length of the engagement plus 90 days, then deleted automatically or on request. No names or public identifiers required. Healthcare engagements run under a Business Associate Agreement.
You stay in control.
You share what you choose. We tell you what is useful, you send what you are comfortable with. No system access, no integration. What you share is encrypted, kept only for the length of the engagement, and deleted when the work is done.
Encryption
TLS 1.2 or higher in transit and AES-256 at rest.
Secure upload
Send us a spreadsheet or a download from your HR system through our secure portal. We do not need an API or any integration.
Retention and deletion
Data is kept for the length of the engagement plus 90 days, then deleted automatically or on request.
No PII required
We do not need names, Social Security numbers, addresses, or any public identifiers. The score runs on coded employee records. You control what we see.
Healthcare
For healthcare engagements, we work under a Business Associate Agreement and limit protected health information to what the diagnostic model requires.
SOC 2 Type I
In progress, targeting Q1 2027.
Common questions about security
Do you need access to our HR system?
No. You share what you are comfortable sharing, usually a spreadsheet of what you already track. We tell you what is useful, you decide what to send. No system access, no integration, no IT project. Your data is encrypted in transit and at rest, and deleted 90 days after the engagement ends. For healthcare clients, we work under a Business Associate Agreement.
How secure is the data?
You stay in control of what you share. For a pilot, you can send anonymized information with no names or IDs, and results come back by group. In a full engagement, your information is split so our analysis runs without names attached. Only three members of the EIP team can see the link between a code and a person, all under NDA. We do not share client information with third parties, and we delete everything 90 days after the engagement ends. For healthcare clients, we work under a Business Associate Agreement. SOC 2 Type I is in progress, targeting Q1 2027.
How long do you keep our data?
We keep data for the length of the engagement plus 90 days, then delete it automatically or on request.
Is EIP SOC 2 certified?
SOC 2 Type I is in progress, with a target of Q1 2027.
How does EIP handle healthcare data?
For healthcare engagements, we work under a Business Associate Agreement and limit protected health information to what the diagnostic model requires.