Trust and securityat Diaform

Diaform is built for teams collecting customer interviews, churn reasons, testimonials, and product context through AI-led conversations. Here is how we protect the data behind those workflows.

Secure AI interviews

The core controls buyers look for before putting an AI interviewer in front of customers, users, or employees.

Security controls

Diaform gives teams the controls buyers expect before launching AI-led customer interviews: role-based access, SAML SSO on Enterprise, signed webhooks, service-provider review, and data export or deletion paths.

Data encryption

Customer data is encrypted at rest and in transit, including interview sessions, dashboard access, transcripts, and authenticated product traffic.

User roles

Invite teammates into a workspace and assign roles so only the right people can configure projects, manage collaborators, or review respondent data.

Rate limiting

Public interview and AI endpoints use rate limits to reduce abuse, protect respondent sessions, and keep abnormal request volume from overwhelming a study.

Domain allowlist

Control where embedded interviews can load. Teams can restrict embeds to approved website origins

Practical operations for customer research data

Security is not just the model layer. It is also deletion, export, service-provider review, and a direct path for security questions.

Service-provider review

Diaform relies on trusted service providers for hosting, database, analytics, email, billing, and model functionality, with regular review of provider practices.

Deletion and retention

Deleted interviews, transcripts, and workspaces are removed from active systems and backups according to retention schedules.

Security contact

Have questions about security, privacy, procurement, or an enterprise rollout? You can always reach out to the Diaform team for help.

Security questions buyers ask before launch

Does Diaform use our interview data to train AI models?

No. Diaform does not use respondent transcripts to train foundation models. AI providers are used to generate prompts, follow-up questions, and summaries, with the data shared limited to what is necessary for each request.

What data is sent to AI model providers?

Diaform sends the conversational context required for the AI-assisted task, such as drafting follow-up questions or generating summaries. The goal is to minimize what is shared while still making the interview useful.

Is Diaform encrypted?

Diaform uses encryption in transit for product and interview traffic, together with role-based access controls, monitoring, and service-provider review practices described in the privacy policy.

Can we delete interviews and transcripts?

Yes. Workspace owners can delete interviews, transcripts, or whole workspaces. Deleted items are removed from active systems and backups according to retention schedules.

Can we restrict where interviews are shared or embedded?

Yes. Diaform supports branded subdomains, custom domains on Business and Enterprise plans, targeted respondent access modes, and embed domain restrictions for teams that need tighter distribution controls.

Does Diaform support SSO?

Enterprise workspaces can use SAML SSO with supported identity providers. Contact Diaform to review setup requirements for your organization.

Ready to upgrade your feedback loop?

Stop guessing why users leave. Start an automated interviewer in seconds and get the deep insights of a Zoom call at the scale of a survey.

14-day free trial · No demo required