Privacy by Design
Feedback Solutions is fully GDPR compliant. Our system produces aggregate occupant counts only. No personal information is ever collected, stored, or saved at any point in the process.
This is by design rather than by policy. Our platform produces counts, not identities. There is no personal data in the system to protect, disclose, or breach, which removes an entire category of risk for our clients and their tenants.

SOC 2 Type II
Feedback Solutions has completed a SOC 2 Type II audit, performed by Johanson Group LLP.
The audit covered all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Many SOC 2 examinations cover Security alone.
A Type II audit tests whether controls actually operated as described across the full audit period, rather than assessing how they are designed at a single point in time. Our controls are monitored year-round through our GRC platform.
What Our Audit Covered
The examination tested the controls behind:
- Logical access — authentication, authorization, and access review across production systems
- Change management — how changes to production systems are requested, reviewed, approved, and deployed
- Network and firewall configuration — segmentation, rule management, and configuration standards
- Configuration standards — including version-controlled configuration templates for edge devices deployed at client sites
- Backup and recovery — daily automated backups to geo-redundant storage held in a separate region, with restores tested at least annually
- Business continuity and disaster recovery — documented recovery objectives, priorities, and testing
- Incident response — detection, escalation, classification, and communication
- Vendor management — review and oversight of third-party providers
- Patch and vulnerability management — identification, prioritization, and remediation

