Trusted by Fortune 500 companies, startups, and everyone in between
ERI meets leading industry standards for data security
SOC 2 Type 2
SOC 2 validates that ERI’s controls pertaining to security, availability, confidentiality, processing integrity, and privacy adhere to the Trust Services Criteria guidelines.
GDPR
ERI is GDPR compliant, ensuring the highest level of protection for personal data. Our processes are aligned with European data protection regulations, facilitating smoother operations across borders.
CCPA
ERI is CCPA compliant, helping protect the privacy rights of California consumers. Our practices align with CCPA requirements to support transparency, consumer choice, and responsible data handling.
AES-256
ERI uses AES-256 encryption to protect your sensitive data at rest. Industry-standard encryption safeguards your information from unauthorized access, helping ensure confidentiality and long-term data security.
TLS 1.2+
ERI secures data in transit using TLS 1.2+ encryption. Every connection between your browser and our platform is encrypted, helping protect sensitive information as it moves across the Internet.
Security Built for Compensation Teams
Compensation involves business-critical data. ERI’s Assessor Platform works best when employee data are synced directly from your HRIS. We understand that your employee and personal company data are highly sensitive. We have over 35 years of experience handling highly confidential, sensitive data for our customers. Securing the data that you share with us is our number one priority and foundational to everything that we do at ERI.
Protection that’s built in, not bolted on
Enterprise Encryption
Sensitive data are encrypted both in transit and at rest to help protect information wherever it travels.
Secure Platform Access
ERI’s Assessor Platform implements Role-Based Access Control and practices Least Privilege principles to ensure that uploaded data are accessible only to authorized users based on assigned role or organizational memberships/policies.
Continuous Monitoring
We continuously monitor our systems for unusual activity and respond quickly to potential threats.
Protection for Customer Information
ERI regularly conducts audits ensuring that customer information is safe and secure.
Everything that your security team needs
For customers, prospects, procurement teams, legal teams, and IT reviewers, the ERI Trust Center provides access to security, privacy, and compliance information, all in one place.
- Latest SOC 2 Report
- Penetration Test Summary
- Privacy Policy
- Subprocessor List
- Frequently Asked Security Questions
Here you can find the following:
How ERI Safeguards Your Data
ERI is committed to protecting customer information and supporting organizations that rely on our compensation data, survey analytics, and software.
Annual Third-Party Penetration Testing
Independent security professionals regularly evaluate our platform to identify and address potential vulnerabilities.
Customer Data Protection
ERI protects sensitive information that customers provide and use within the Assessor Platform.
Secure Compensation Analysis
Users can safely conduct their compensation planning, market pricing, survey management, and job-level analysis within a protected environment.
Responsible Data Handling
ERI’s data practices are designed to support confidentiality, privacy, and trusted use of compensation information.
Your Data Belongs to You
You always retain ownership of your data. ERI provides support for exporting or purging your data.
We do not use customer data to train AI models
Market data are aggregated and anonymized
Well Trained and Highly Skilled Staff
ERI employees undergo rigorous onboarding training, complete quarterly performance-based security training courses, and take part in annual security awareness training programs.
Frequently Asked Questions
Visit the ERI Trust Center at trust.erieri.com for available security, privacy, and compliance resources.
ERI has completed an SOC 2 examination. Visit the ERI Trust Center for available SOC 2 information.
The ERI Trust Center is useful for customers, prospects, IT teams, legal teams, procurement teams, compliance teams, and vendor management reviewers.
- Internal security documentation, policies, and procedures
- Compliance documentation and audit results
- Privacy resources
ERI makes protecting your data our core responsibility. We employ a defense-in-depth approach with multiple layers of technical, administrative, and physical controls to safeguard customer data. This includes uploaded files, prompts, documents, images, and usage history. All data are encrypted at rest and in transit. Access to data follows strict Role-Based Access Controls (RBAC), ensuring uploaded data are only accessible to authorized users based on role, team, and explicit permissions. Least privilege principles are enforced across the organization. Customer data are logically separated. We leverage secure infrastructure, continuous monitoring, intrusion detection, and advanced threat protection. We validate with annual penetration testing, ongoing vulnerability management, and SOC 2 auditing to address any risks before they can impact customers. We do not use customer data to train AI models. You retain ownership of your data at all times. We provide support for exporting or purging your data.
Transparency: We provide clear, accessible information on how we collect and analyze data, making us the trusted source for compensation data.
Data Ownership and Control: You own your data.
Compliance and Governance: We support major privacy regulators. ERI aligns with industry standards through independent audits, SOC 2 compliance, and internal review.
Security is only the beginning. ERI builds lasting trust through transparency, genuine data ownership, ethical development and data analytics, and meaningful user input, feedback, and control.
At ERI, we maintain a rigorous security posture through regular, independent validation of our systems. We conduct comprehensive annual penetration testing performed by qualified, third-party security firms to proactively identify and remediate potential vulnerabilities. We implement continuous internal vulnerability scanning, code reviews, and targeted assessments throughout the year. Results are always reviewed by leadership and our security team.
ERI’s security program aligns with industry best practices and supports our compliance with SOC 2.
We conduct penetration testing annually.
ERI is committed to respecting intellectual property rights while providing the best compensation management platform globally. We maintain processes to report violations and ensure a clear process for handling claims.
Confidence Starts with Trust
Whether you're evaluating our platform for the first time or completing a vendor security review, we're committed to providing the transparency that your team needs to make an informed decision.










