Enterprise-grade security, privacy, and responsible AI for the Inspire platform
Inspire Software protects customer data with enterprise-grade security, privacy, and AI governance practices. The platform runs on Microsoft Azure with regional data residency, SSO and modern identity integration on every plan, encryption in transit and at rest, and a SOC 2 Type II program currently underway. Customers in the EU and EEA are supported under a GDPR-compliant data processing model with a standing Data Processing Addendum.
The Program
Six pillars of the Inspire security program
Data Protection
- AES-256 encryption at rest, TLS 1.2 or higher in transit
- SSO on every plan
- Role-based access control with audit logging
Cloud & Infrastructure Security
- Hosted on Microsoft Azure with regional data residency (US or Singapore)
- Multi-availability-zone (Multi-AZ) deployment for high availability and failover
- Continuous infrastructure monitoring and intrusion detection
- Ongoing data replication and backups with documented recovery objectives
Application Protection
- Secure software development lifecycle (SDLC) with mandatory code review
- Continuous automated vulnerability scanning
- Independent penetration testing performed annually
Responsible AI
- Customer data stays inside your Inspire tenant
- Customer content is not used to train foundation models
- AI-assisted actions captured in the audit trail
Organizational Security
- 24/7 monitoring and incident response
- Annual security awareness training for all Inspire staff
- Documented risk management program
- Regular user-permission reviews and least-privilege enforcement
Compliance & Privacy
- SOC 2 Type II current report available. Documentation available under NDA.
- GDPR compliant with a standing Data Processing Addendum (DPA)
- Public Privacy Policy describing data collection, use, and rights
DATA PROTECTION
How Inspire protects customer data, identity, and access
Inspire encrypts customer data at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are managed by Inspire on Microsoft Azure’s key-management infrastructure. Access to production data is restricted to a small set of named engineers, granted on a least-privilege basis, logged for audit, and reviewed regularly.
Single sign-on (SSO) is supported on every Inspire plan through SAML 2.0 and OIDC, so customers can keep identity, password rotation, multi-factor authentication, and de-provisioning inside their own identity provider. Inspire integrates with Microsoft Entra ID (formerly Azure AD), Okta, Google Workspace, and other modern IdPs through standard protocols.
Inside the application, role-based access control governs what each user can see and change. Every administrative action — including award configuration changes, recognition eligibility scoping, OKR edits, performance comments, and integration setup — is captured in an audit log that customers can export.
Customer data is logically segregated per tenant. Recognition content, OKRs, performance conversations, and people-data fields from one customer are never exposed to another, and are never used to inform AI suggestions for another customer.
- Data at rest in Azure Storage and Azure SQL: AES-256
- Data in transit between the user’s browser and Inspire: TLS 1.2 or higher
- Data in transit between Inspire and integrated systems: TLS over modern protocols, with secrets managed in Azure Key Vault
CLOUD & INFRASTRUCTURE SECURITY
Where Inspire runs, how it's monitored, and how it stays up
The Inspire platform runs on Microsoft Azure. Each customer is configured for a single region at onboarding: US Azure or Singapore Azure. The configuration is not currently dynamic; customers select the region that matches their data residency and latency requirements, and Inspire provisions the tenant in that region. APAC customers most commonly choose Singapore.
Within each region, Inspire deploys across multiple Azure availability zones (Multi-AZ). The platform uses Azure’s native failover technology so a zone-level disruption does not interrupt service.
Production infrastructure is continuously monitored for security events, configuration drift, and abnormal access patterns. Logs are centralized and retained for incident review. Inspire follows Azure’s defense-in-depth architecture: network segmentation, perimeter controls, and identity-based access policies are layered so a compromise of any single control does not expose customer data.
Ongoing data replication and backups run on a documented cadence and are stored in the same Azure region as the production tenant. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets are documented and tested. Inspire maintains a written Business Continuity and Disaster Recovery plan that is reviewed and exercised annually.
APPLICATION PROTECTION
How Inspire writes, tests, and defends the code that runs your data
Inspire builds the platform using a secure software development lifecycle (SDLC). Every code change is reviewed by a second engineer before it reaches the main branch, and every production deployment passes through automated tests, static analysis, and security checks. The same SDLC governs AI features, integration code, and customer-facing UI alike.
Inspire runs continuous automated vulnerability scanning across the codebase, the container image supply chain, and the production runtime. Critical findings are remediated on a defined SLA; non-critical findings are tracked and triaged on the same cadence as feature work.
Inspire engages a qualified independent firm to conduct an annual penetration test of the platform. Penetration test summaries (executive summary, scope, finding count by severity, remediation status) are available to customers under NDA. Full reports are restricted to authorized auditors.
Inspire also operates a security disclosure channel for external researchers. Vulnerabilities reported in good faith are triaged on the same SLA as internal findings, with credit acknowledgment where appropriate.
RESPONSIBLE AI
How Inspire AI uses your data, and how it doesn't
Inspire uses AI to make the platform measurably more useful to managers, employees, and program owners. Inspire AI helps managers write recognition that lands, drafts OKR check-ins from real activity, suggests coaching conversation starters, and adapts language for each recipient’s personality type. The principles below govern how that AI uses your data.
Your data stays in your tenant
Inspire AI runs on Microsoft Azure’s enterprise AI infrastructure inside the same tenant boundary as your other Inspire data. Recognition content, OKR text, performance comments, coaching notes, and people-data fields from your tenant are never used to inform AI suggestions for another Inspire customer.
AI actions are auditable
Every AI-assisted action — a draft recognition Inspire AI suggested, an OKR check-in it pre-populated, a coaching prompt it surfaced — is captured in the same audit trail as any other Inspire action. Security, compliance, and HR teams can review what the system suggested, what the human accepted, and what the human edited, with timestamps and attribution.
Your content is not used to train foundation models
Inspire does not use customer content to train the underlying large language models that power Inspire AI. The models themselves are operated by enterprise AI providers under data-protection terms that prohibit such use. Your data informs your tenant’s outputs, not the underlying models that any other customer would see.
AI features are optional and configurable
Customers can enable or disable AI features at the program level. Organizations that prefer to launch without AI suggestions can do so, and turn AI on later when their internal governance is ready.
ORGANIZATIONAL SECURITY
How Inspire's people, process, and access controls keep customer data safe
Inspire treats security as a team-wide responsibility. The platform is monitored 24 hours a day, 7 days a week for security events and abnormal access patterns, with on-call responders ready to triage and contain anything the monitoring stack flags.
Every Inspire employee and contractor completes annual security awareness training, including phishing simulation and incident reporting. Engineers receive additional training on secure coding, threat modeling, and the specific risks of building HR and people-data software.
Inspire maintains a documented incident response process. On detection of a confirmed security incident, the on-call security and engineering leads convene, customer impact is assessed, affected customers are notified consistent with the obligations in their Master Services Agreement and Data Processing Addendum, and a post-incident review is performed. Inspire also operates a formal risk management program that identifies, tracks, and remediates security and operational risks on a documented cadence.
Access to customer data is governed by least-privilege principles. New hires receive access only to the systems required for their role. User-permission reviews are conducted regularly and access is revoked promptly on role change or separation. Privileged actions on production systems are logged and reviewable.
COMPLIANCE & PRIVACY
Inspire's compliance posture, the certifications we hold, and the ones we don't
Inspire is committed to a clear, honest description of its compliance posture and to ongoing investment to expand it.
SOC 2 Type II — program in progress
Inspire is current with its SOC 2 Type II program. The control environment is documented, evidence was collected over the full calendar year 2025 audit window, and the report was issued by a qualified independent firm. Program status, scope, and trust services criteria covered are available to prospective and current customers under NDA.
GDPR compliance
Inspire is compliant with the EU General Data Protection Regulation (GDPR). The platform supports the data-subject rights GDPR requires (access, rectification, erasure, restriction, portability, objection). A signed Data Processing Addendum (DPA) is available for customers in the EU, EEA, UK, and other regions whose contracting standards require one. Standard Contractual Clauses (SCCs) are included for international data transfers where applicable.
ISO/IEC 27001
Inspire does not currently hold ISO/IEC 27001 certification. Customers whose procurement processes require ISO 27001 can reference Inspire’s SOC 2 Type II program in lieu, recognizing the substantial overlap between the two frameworks. Inspire is evaluating ISO 27001 as a future certification step.
Subprocessors
Inspire uses a small set of trusted subprocessors to deliver the platform — primarily Microsoft Azure for infrastructure and the enterprise AI provider that powers Inspire AI. The current subprocessor list is maintained on a public page and is updated when subprocessors are added or changed. Material changes are notified to customers under the DPA.
Privacy Policy and data rights
Inspire’s Privacy Policy is publicly available and describes the categories of data Inspire collects, how each is used, how long it is retained, and how customers and end users can exercise their data rights. Requests can be submitted through the channels in the policy or by email to info@inspiresoftware.com.