SurveyCX for Amazon Connect

Help center › Security and data

Security and data

This page is written for the person who has to approve SurveyCX for a contact centre.

Where it runs

SurveyCX is a CloudFormation stack in your AWS account: Lambda functions, one DynamoDB table, a Kinesis stream, an HTTP API, a private S3 bucket behind CloudFront, a Cognito user pool, EventBridge rules and CloudWatch alarms. EKPK LLC has no access to the account, the table or the answers. The template is public on GitHub and every release ships with checksums.

What leaves the account

No telemetry, no phone-home, no third-party services.

What is stored

Per response: the contact id, survey id, agent id and name, queue, channel, status, timestamps, the answers (including free text) and the scores. Phone numbers and email addresses are stored only as SHA-256 hashes, used for the frequency cap and the opt-out list; the queued invitation holds the address until it is sent, for at most a day. The web survey link is a random token with a 14-day life.

Free-text answers may contain whatever the customer typed. SurveyCX does not send them to any AI service. Redaction before any future AI processing is a design rule for this product.

Retention and deletion

Access

Encryption

DynamoDB, Kinesis and S3 are encrypted at rest with AWS-managed keys. All traffic is HTTPS; the site sends HSTS and a content security policy.

Compliance notes

Current as of version 0.1.0. See the release notes for what changed since.