Please follow the attached instructions to implement the tracking code below....

Enterprise-grade security, privacy, and responsible AI for the Inspire platform

Inspire Software protects customer data with enterprise-grade security, privacy, and AI governance practices. The platform runs on Microsoft Azure with regional data residency, SSO and modern identity integration on every plan, encryption in transit and at rest, and a SOC 2 Type II program currently underway. Customers in the EU and EEA are supported under a GDPR-compliant data processing model with a standing Data Processing Addendum.

The Program

Six pillars of the Inspire security program

Data Protection
  • AES-256 encryption at rest, TLS 1.2 or higher in transit
  • SSO on every plan
  • Role-based access control with audit logging
Cloud & Infrastructure Security
  • Hosted on Microsoft Azure with regional data residency (US or Singapore)
  • Multi-availability-zone (Multi-AZ) deployment for high availability and failover
  • Continuous infrastructure monitoring and intrusion detection
  • Ongoing data replication and backups with documented recovery objectives
Application Protection
  • Secure software development lifecycle (SDLC) with mandatory code review
  • Continuous automated vulnerability scanning
  • Independent penetration testing performed annually
Responsible AI
  • Customer data stays inside your Inspire tenant
  • Customer content is not used to train foundation models
  • AI-assisted actions captured in the audit trail
Organizational Security
  • 24/7 monitoring and incident response
  • Annual security awareness training for all Inspire staff
  • Documented risk management program
  • Regular user-permission reviews and least-privilege enforcement
Compliance & Privacy
  • SOC 2 Type II current report available. Documentation available under NDA.
  • GDPR compliant with a standing Data Processing Addendum (DPA)
  • Public Privacy Policy describing data collection, use, and rights
DATA PROTECTION

How Inspire protects customer data, identity, and access

Inspire encrypts customer data at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are managed by Inspire on Microsoft Azure’s key-management infrastructure. Access to production data is restricted to a small set of named engineers, granted on a least-privilege basis, logged for audit, and reviewed regularly.

Single sign-on (SSO) is supported on every Inspire plan through SAML 2.0 and OIDC, so customers can keep identity, password rotation, multi-factor authentication, and de-provisioning inside their own identity provider. Inspire integrates with Microsoft Entra ID (formerly Azure AD), Okta, Google Workspace, and other modern IdPs through standard protocols.

Inside the application, role-based access control governs what each user can see and change. Every administrative action — including award configuration changes, recognition eligibility scoping, OKR edits, performance comments, and integration setup — is captured in an audit log that customers can export.

Customer data is logically segregated per tenant. Recognition content, OKRs, performance conversations, and people-data fields from one customer are never exposed to another, and are never used to inform AI suggestions for another customer.

  • Data at rest in Azure Storage and Azure SQL: AES-256
  • Data in transit between the user’s browser and Inspire: TLS 1.2 or higher
  • Data in transit between Inspire and integrated systems: TLS over modern protocols, with secrets managed in Azure Key Vault
CLOUD & INFRASTRUCTURE SECURITY

Where Inspire runs, how it's monitored, and how it stays up

The Inspire platform runs on Microsoft Azure. Each customer is configured for a single region at onboarding: US Azure or Singapore Azure. The configuration is not currently dynamic; customers select the region that matches their data residency and latency requirements, and Inspire provisions the tenant in that region. APAC customers most commonly choose Singapore.

Within each region, Inspire deploys across multiple Azure availability zones (Multi-AZ). The platform uses Azure’s native failover technology so a zone-level disruption does not interrupt service.

Production infrastructure is continuously monitored for security events, configuration drift, and abnormal access patterns. Logs are centralized and retained for incident review. Inspire follows Azure’s defense-in-depth architecture: network segmentation, perimeter controls, and identity-based access policies are layered so a compromise of any single control does not expose customer data.

Ongoing data replication and backups run on a documented cadence and are stored in the same Azure region as the production tenant. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets are documented and tested. Inspire maintains a written Business Continuity and Disaster Recovery plan that is reviewed and exercised annually.

APPLICATION PROTECTION

How Inspire writes, tests, and defends the code that runs your data

Inspire builds the platform using a secure software development lifecycle (SDLC). Every code change is reviewed by a second engineer before it reaches the main branch, and every production deployment passes through automated tests, static analysis, and security checks. The same SDLC governs AI features, integration code, and customer-facing UI alike.

Inspire runs continuous automated vulnerability scanning across the codebase, the container image supply chain, and the production runtime. Critical findings are remediated on a defined SLA; non-critical findings are tracked and triaged on the same cadence as feature work.

Inspire engages a qualified independent firm to conduct an annual penetration test of the platform. Penetration test summaries (executive summary, scope, finding count by severity, remediation status) are available to customers under NDA. Full reports are restricted to authorized auditors.

Inspire also operates a security disclosure channel for external researchers. Vulnerabilities reported in good faith are triaged on the same SLA as internal findings, with credit acknowledgment where appropriate.

RESPONSIBLE AI

How Inspire AI uses your data, and how it doesn't

Inspire uses AI to make the platform measurably more useful to managers, employees, and program owners. Inspire AI helps managers write recognition that lands, drafts OKR check-ins from real activity, suggests coaching conversation starters, and adapts language for each recipient’s personality type. The principles below govern how that AI uses your data.

Your data stays in your tenant

Inspire AI runs on Microsoft Azure’s enterprise AI infrastructure inside the same tenant boundary as your other Inspire data. Recognition content, OKR text, performance comments, coaching notes, and people-data fields from your tenant are never used to inform AI suggestions for another Inspire customer.

AI actions are auditable

Every AI-assisted action — a draft recognition Inspire AI suggested, an OKR check-in it pre-populated, a coaching prompt it surfaced — is captured in the same audit trail as any other Inspire action. Security, compliance, and HR teams can review what the system suggested, what the human accepted, and what the human edited, with timestamps and attribution.

Your content is not used to train foundation models

Inspire does not use customer content to train the underlying large language models that power Inspire AI. The models themselves are operated by enterprise AI providers under data-protection terms that prohibit such use. Your data informs your tenant’s outputs, not the underlying models that any other customer would see.

AI features are optional and configurable

Customers can enable or disable AI features at the program level. Organizations that prefer to launch without AI suggestions can do so, and turn AI on later when their internal governance is ready.

ORGANIZATIONAL SECURITY

How Inspire's people, process, and access controls keep customer data safe

Inspire treats security as a team-wide responsibility. The platform is monitored 24 hours a day, 7 days a week for security events and abnormal access patterns, with on-call responders ready to triage and contain anything the monitoring stack flags.

Every Inspire employee and contractor completes annual security awareness training, including phishing simulation and incident reporting. Engineers receive additional training on secure coding, threat modeling, and the specific risks of building HR and people-data software.

Inspire maintains a documented incident response process. On detection of a confirmed security incident, the on-call security and engineering leads convene, customer impact is assessed, affected customers are notified consistent with the obligations in their Master Services Agreement and Data Processing Addendum, and a post-incident review is performed. Inspire also operates a formal risk management program that identifies, tracks, and remediates security and operational risks on a documented cadence.

Access to customer data is governed by least-privilege principles. New hires receive access only to the systems required for their role. User-permission reviews are conducted regularly and access is revoked promptly on role change or separation. Privileged actions on production systems are logged and reviewable.

COMPLIANCE & PRIVACY

Inspire's compliance posture, the certifications we hold, and the ones we don't

Inspire is committed to a clear, honest description of its compliance posture and to ongoing investment to expand it.

SOC 2 Type II — program in progress

Inspire is current with its SOC 2 Type II program. The control environment is documented, evidence was collected over the full calendar year 2025 audit window, and the report was issued by a qualified independent firm. Program status, scope, and trust services criteria covered are available to prospective and current customers under NDA.

GDPR compliance

Inspire is compliant with the EU General Data Protection Regulation (GDPR). The platform supports the data-subject rights GDPR requires (access, rectification, erasure, restriction, portability, objection). A signed Data Processing Addendum (DPA) is available for customers in the EU, EEA, UK, and other regions whose contracting standards require one. Standard Contractual Clauses (SCCs) are included for international data transfers where applicable.

ISO/IEC 27001

Inspire does not currently hold ISO/IEC 27001 certification. Customers whose procurement processes require ISO 27001 can reference Inspire’s SOC 2 Type II program in lieu, recognizing the substantial overlap between the two frameworks. Inspire is evaluating ISO 27001 as a future certification step.

Subprocessors

Inspire uses a small set of trusted subprocessors to deliver the platform — primarily Microsoft Azure for infrastructure and the enterprise AI provider that powers Inspire AI. The current subprocessor list is maintained on a public page and is updated when subprocessors are added or changed. Material changes are notified to customers under the DPA.

Privacy Policy and data rights

Inspire’s Privacy Policy is publicly available and describes the categories of data Inspire collects, how each is used, how long it is retained, and how customers and end users can exercise their data rights. Requests can be submitted through the channels in the policy or by email to info@inspiresoftware.com.

Security FAQs

Which data types does Inspire store?
Inspire stores the data your program requires: employee identifying fields (name, work email, manager, department, location, tenure, custom HR attributes), recognition content (the praise, the award, the linked value or goal), OKR and performance data (objectives, key results, check-ins, feedback, coaching notes), and platform usage data (logins, access patterns, audit events). Inspire does not store payment-card data; payments for redemption catalog items are processed by integrated providers.
 
Where is Inspire’s product infrastructure hosted?
Microsoft Azure. Each customer is configured for one region at onboarding — today, US Azure or Singapore Azure. The configuration is not currently dynamic. APAC customers typically choose Singapore for data residency and latency.
 
Is Inspire SOC 2 certified?
Inspire has successfully completed its 2025 full-year SOC 2 audit and report. This is the 5th annual SOC 2 audit that was successfully completed since 2021. The report was issued by a qualified independent firm. Detailed program status and scope are available to prospective customers under NDA.
Is Inspire ISO/IEC 27001 certified?
No. Inspire does not currently hold ISO 27001 certification. Customers whose procurement processes require ISO 27001 can reference Inspire’s in-progress SOC 2 Type II program in lieu, recognizing the substantial overlap between the two frameworks.
 
 
Is Inspire GDPR compliant?
Yes. Inspire is GDPR compliant and supports the data-subject rights GDPR requires (access, rectification, erasure, restriction, portability, objection). A signed Data Processing Addendum (DPA) is available for customers in the EU, EEA, UK, and other regions whose contracting standards require one. Standard Contractual Clauses (SCCs) are included for international data transfers where applicable.
 
 
 
Can I sign a DPA with Inspire?
Yes. Inspire offers a standing DPA that can be incorporated into the Master Services Agreement or signed as a standalone document. Customers can request the current DPA template from their Customer Success partner or by emailing info@inspiresoftware.com.
 
 
 
 
Does Inspire have a disaster recovery plan?
Yes. Inspire maintains a documented Business Continuity and Disaster Recovery plan, reviewed and exercised on a recurring basis. Recovery Time Objective and Recovery Point Objective targets are documented in the Security and Privacy Overview available under NDA.
 
 
 
 
 
Does Inspire use my data to train AI?
No. Customer content (recognition, OKR text, performance comments, coaching notes, and people-data fields) is not used to train the foundation models that power Inspire AI. Customer data informs your tenant’s outputs only, never another customer’s outputs and never the underlying models that any other customer would see.
 
 
 
 
 
 
Where can I view the Privacy Policy?
Inspire’s Privacy Policy is publicly available at /privacy-policy. It describes what data is collected, how it is used, retention, and how data rights can be exercised.
 
 
 
 
 
 
Where can I view your subprocessor list?
Inspire maintains a public subprocessor list at /legal/subprocessors. Material changes are notified to customers under the DPA.
 
 
 
 
 
 
How do I report a security vulnerability?
Email info@inspiresoftware.com with a description of the issue, reproduction steps if applicable, and your preferred contact method. Reports are triaged on the same SLA as internal findings. Researchers acting in good faith are credited where appropriate; please do not disclose publicly before Inspire has had a reasonable opportunity to remediate.
 
 
 
 
 
 
I have other security or privacy questions.
Email info@inspiresoftware.com or contact your Customer Success partner. Most procurement questions can be answered from the Security and Privacy Overview, available under NDA, before a discovery call.