Infrastructure security
- Data encrypted in transit and at rest
- SOC 2 Type II audited security program
Login:
Cloud Service Provider
United States
Cloud-based Analytics Provider
United States
Cloud-based Email Notifications
United States
Polly uses your organization's data to deliver the service, including creating, processing, and displaying polls, surveys, and results for your team. Data is used to operate the product, support core functionality, and help admins and authorized users review insights generated in Polly. Polly does not read or store messages in your Slack workspace, in public, private, or group channels, with four exceptions: messages where Polly is mentioned directly, messages sent with a Polly slash command, private messages sent to the Polly app channel, and messages Polly itself publishes.
Polly reads and stores only the information required to deliver the service. This includes a user's name, used to display results and attribute votes and comments; their UPN and Azure AD object ID, used to send chat messages and attribute voting and authoring activity to the correct person; team names, used to identify where Polly is installed within a tenant; and channel names, so users can choose where to send surveys. Polly also stores survey content, meaning titles and questions, along with survey responses, meaning votes and comments, both of which are necessary to provide the service.
You can request access directly through the Trust Center’s Request Access section. Submit the form with your business details and the documents you need, and Polly’s team will review the request before sharing restricted materials.
No resources matched your search.
Need access to sensitive security or compliance materials? Submit a request and our team will review it before sharing the appropriate documents.
No controls matched your search.
Polly uses several third-party subprocessors to provide infrastructure services, customer support and relationship management, performance analytics, email communications and AI-assisted content generation (via Amazon Bedrock). Prior to use of any of these third-party services, Polly conducts a thorough evaluation of their privacy, security, and confidentiality practices before implementing them.
Cloud Service Provider
United States
Cloud-based Analytics Provider
United States
Cloud-based Email Notifications
United States
Cloud Database
United States
Cloud-based Customer Relationship Management
United States
Cloud-based Payment Infrastructure Provider (PCI DSS Level 1 certified)
United States
No subprocessors matched your search.
Polly uses your organization's data to deliver the service, including creating, processing, and displaying polls, surveys, and results for your team. Data is used to operate the product, support core functionality, and help admins and authorized users review insights generated in Polly. Polly does not read or store messages in your Slack workspace, in public, private, or group channels, with four exceptions: messages where Polly is mentioned directly, messages sent with a Polly slash command, private messages sent to the Polly app channel, and messages Polly itself publishes.
Polly reads and stores only the information required to deliver the service. This includes a user's name, used to display results and attribute votes and comments; their UPN and Azure AD object ID, used to send chat messages and attribute voting and authoring activity to the correct person; team names, used to identify where Polly is installed within a tenant; and channel names, so users can choose where to send surveys. Polly also stores survey content, meaning titles and questions, along with survey responses, meaning votes and comments, both of which are necessary to provide the service.
You can request access directly through the Trust Center’s Request Access section. Submit the form with your business details and the documents you need, and Polly’s team will review the request before sharing restricted materials.
Polly supports sign-in through the collaboration platforms your organization already uses, such as Slack, Microsoft Teams, and other supported integrations. Authentication is handled through those connected platforms, which helps streamline access and support existing identity and admin controls.
Polly is SOC 2 Type II compliant.
Authentication is handled by the platform your organization uses, so successful and failed login attempts are logged there rather than by Polly: Slack, Microsoft Entra ID (Azure AD), Zoom, or Google Workspace admin consoles. Polly does not receive identifiable information from an unsuccessful login attempt.
IP addresses are logged at the network layer via AWS Load Balancer access logs and retained for a minimum of one year. We do not record customer IP addresses for usage of the Slack app or the Microsoft Teams bot. For the Polly web app accessed within Slack, inside the Microsoft Teams client, or in Zoom or Google Workspace, the client IP address is logged.
We allow exports from within the application for activity logs. This is available to administrators on our Enterprise tier.
Yes, we do perform automated code scans as well as manual code inspections for security strengthening.
Yes, we use Amazon GuardDuty to monitor our production environments in AWS for any untoward activity.
Production servers and containers are continuously scanned with AWS Inspector, and code dependencies with Dependabot. Findings are remediated under our Vulnerability Management Policy on severity-based timelines, and the SOC 2 audit confirmed no overdue vulnerabilities
All company workstations are required to run anti-malware software, enforced through MDM. Production infrastructure is continuously scanned for vulnerabilities and malicious activity using AWS Inspector and Amazon GuardDuty, and container and dependency scanning runs as part of our deployment pipeline.
Polly maintains a documented Security Incident Response Plan that is reviewed annually and tested in any year without a live incident. It defines roles, severity levels, containment, and customer notification requirements
Data at rest is encrypted using AES-256 with keys managed in AWS KMS. Data in transit is encrypted using TLS 1.2 or higher.
Polly operates on a shared-tenancy model. Customer data is stored indefinitely unless a deletion request is made. Enterprise customers can set custom data retention policies for their organization and can remove specific pollys at any time. All customers may request deletion of their data; requests are verified for scope and authorization (an administrator or the installing user must authorize team-level deletion), and verified data is hard-deleted from production systems within one month of the request.
We take data privacy very seriously and are EU-U.S. Data Privacy Framework certified, including the UK Extension and Swiss-U.S. DPF, with Standard Contractual Clauses in our standard DPA. Verifiable at dataprivacyframework.gov/list.
Polly does not maintain its own passwords. Users authenticate through the collaboration platform where Polly is installed — Slack (Slack OAuth, including Slack-enforced SSO providers such as Okta), Microsoft Teams (Microsoft Entra ID / Azure AD), Zoom, or Google Workspace — and Polly inherits the SSO and MFA policies your organization has configured on that platform. Polly cannot bypass or weaken those controls.
Polly offers IP whitelisting for the Polly web app on Slack, available as an additional feature on Enterprise plans. It currently gates access to results export. IP whitelisting is not available for the Polly app in Microsoft Teams.
We allow users only access to their own data or to users' data that has been explicitly shared to them. Additionally, we offer an additional administrator role with our enterprise plan that can access and set policies for data across the organization.
Under Polly's Data Classification Policy, all information received from customers — including poll and survey content, responses, customer PII, and customers' customers' PII — is classified as Customer Confidential, our most restrictive tier. Polly upholds the highest levels of integrity, confidentiality, and restricted availability for this data, enforced through encryption in transit and at rest, least-privilege access, activity logging, and a prohibition on storage on removable media or unmanaged devices.
We rely on Amazon AWS: https://aws.amazon.com/compliance/iso-27001-faqs/
We rely on Stripe for payment processing which is a PCI Level 1 service provider https://stripe.com/docs/security/stripe
Polly carries commercial general liability insurance together with cyber liability and technology errors & omissions coverage. A current certificate of insurance is available on request through the Request Access section of this Trust Center.
Polly maintains a documented Incident Response Plan that requires customer notification when a confirmed security incident affects customer data. For personal data breaches, Polly notifies affected customers without undue delay and in any event within 72 hours of confirming the breach, consistent with GDPR Article 33 and our standard DPA. Notification includes the nature of the incident, data affected, actions taken to contain it, and recommended customer steps.
Polly maintains a documented Business Continuity Plan and Disaster Recovery Plan with a 24-hour Recovery Time Objective for critical services. Production data is backed up automatically and continuously by our database provider, with snapshots every six hours plus daily, weekly, and monthly snapshots on a tiered retention schedule, so data can be restored to shortly before any failure. Both plans are reviewed and tested at least annually, including a full restore from backup, and the most recent tests were completed without exception under our SOC 2 Type II audit.
Polly has a dedicated information security function reporting to executive leadership. The security team owns our SOC 2 program, vulnerability management, incident response, vendor risk, and security awareness training, and is supported by external auditors and penetration testers annually.
All employees complete security awareness training within 30 days of hire and annually thereafter, sign a confidentiality and invention assignment agreement, and acknowledge all security policies at onboarding. Developers additionally complete secure-coding (SSDLC) training annually
We conduct background checks on employees and maintain a system of least privilege access. Audits are conducted regularly of access to systems for employees.
Available on Enterprise level plans
United States
Direct customer audit of data is not possible under our shared tenancy model. Polly is SOC 2 Type II audited, and the report is available on request through the Request Access section of this trust center.
All company workstations are enrolled in MDM. Workstations require full disk encryption (FileVault on macOS, BitLocker on Windows), automatic screen lock after no more than 10 minutes of inactivity, mandatory anti-malware, and password-manager use. Configuration compliance is verified continuously and tested annually under our SOC 2 audit.
AWS environment including servers, load balancers etc. are continuously monitored using GuardDuty
Yes
No: Mitigated through MDM software and malware scanning
Polly does not operate a standalone DLP product. Data exfiltration risk is mitigated through MDM-enforced controls on all company workstations (USB write blocking, full disk encryption, mandatory anti-malware), host-based intrusion detection on endpoints, and least-privilege, IP-restricted access to production systems with activity logging retained for at least one year.
No: Information is scrubbed from logs
Yes
Yes. Access to production systems is reviewed at least annually, and access is revoked promptly on role change or termination.
Yes. An independent third-party application penetration test is performed annually, with a remediation verification letter issued after fixes. Both are available through the Request Access section
Polly's optional AI features (for example, generating question suggestions from keywords) run on Amazon Bedrock within Polly's AWS environment. Customer inputs are used only to generate the requested output, are not stored beyond the session, and are never used by Polly or AWS to train or fine-tune models. AI features are clearly labeled, are not required to use Polly, and can be disabled for your organization on request. Our full AI Use Policy is available on request.
Polly operates a responsible disclosure program. Security researchers and customers can report vulnerabilities to security@polly.ai; reports are acknowledged, triaged, and remediated under our Vulnerability Management Policy
Every subprocessor undergoes a security, privacy, and confidentiality review before onboarding, and Polly performs an annual review of each critical subprocessor's SOC 2 report, including complementary user entity controls. Changes are published on the subprocessor list, and customers may object under the terms of our DPA.
All production changes go through peer code review, automated testing, and approval before deployment, under a documented Change Management Policy audited as part of SOC 2
Polly supports access, correction, deletion, and portability requests under GDPR and CCPA. Requests can be submitted via privacy@polly.ai or through your workspace administrator and are handled under our Subject Access Request procedure
No FAQs matched your search.