Sponsors, partners, and clients with strict data privacy requirements often ask about how Audience protects entrant and participant data. This article answers the most common questions at a high level. For formal documentation — SOC 2 report, penetration test results, or a signed security questionnaire — see the section below.
Are you SOC 2 compliant?
Yes. Audience (Aptivada) maintains SOC 2 compliance, which covers the substance of most security, availability, and data-handling questions — including application security ownership, monitoring, and data protection controls.
You can share our live compliance and trust report directly with a sponsor or partner:
This is the fastest way to satisfy a sponsor's security review — most standard questionnaires are already answered there.
How is the platform and entrant data upload system hosted and secured?
The Audience platform is fully hosted on AWS. All data is encrypted in transit (TLS/HTTPS). Participant PII is stored in a managed database, uploaded images pass through automated moderation, and entry endpoints run continuous, layered abuse and fraud protection.
Who is responsible for application security — Audience or a third-party vendor?
Audience owns application security in-house. Audience is the software vendor and operates the platform on its own AWS infrastructure — there is no separate third-party vendor running the application on Audience's behalf. Infrastructure-level security follows AWS's shared-responsibility model, with Audience responsible for the application layer.
Have vulnerability scans or security assessments been performed?
Audience runs continuous security monitoring in production and follows secure-development practices as part of its CI process. Formal assessment results (e.g., penetration test reports) are covered under our SOC 2 program — see the Trust Center link above, or contact your account manager to request documentation directly.
Is data backup and disaster recovery in place for participant data?
Yes. Audience maintains automated point-in-time backups, high-availability failover, and a cross-region disaster recovery setup. Submitted entry data is persisted to the database on submission — it is not held only in application memory — so a service outage does not result in lost entries.
What happens to participant data if your systems experience an outage?
Because entries are committed to the database at submission, an outage affects availability of the platform, not the integrity of already-submitted data. Recovery procedures are in place as part of the backup and failover setup described above.
Can we request deletion of participant data?
Yes. Audience supports data deletion and inactivity-based purge requests, which is helpful for sponsors with strict PII retention policies. Reach out to your account manager to arrange a deletion or retention request.
Need something more formal?
For SOC 2 reports, signed security questionnaires, or anything requiring an attached document, share the Trust Center link with the requester first — it covers most requests. If they need something beyond what's there, contact your account manager or support, and we'll loop in our security team.
