Trusted by Fortune 500 companies, startups, and everyone in between

ERI meets leading industry standards for data security

SOC 2 Type 2

SOC 2 Type 2

SOC 2 validates that ERI’s controls pertaining to security, availability, confidentiality, processing integrity, and privacy adhere to the Trust Services Criteria guidelines.

GDPR

GDPR

ERI is GDPR compliant, ensuring the highest level of protection for personal data. Our processes are aligned with European data protection regulations, facilitating smoother operations across borders.

CCPA

CCPA

ERI is CCPA compliant, helping protect the privacy rights of California consumers. Our practices align with CCPA requirements to support transparency, consumer choice, and responsible data handling.

AES-256

AES-256

ERI uses AES-256 encryption to protect your sensitive data at rest. Industry-standard encryption safeguards your information from unauthorized access, helping ensure confidentiality and long-term data security.

TLS 1.2+

TLS 1.2+

ERI secures data in transit using TLS 1.2+ encryption. Every connection between your browser and our platform is encrypted, helping protect sensitive information as it moves across the Internet.

Security Built for Compensation Teams

Compensation involves business-critical data. ERI’s Assessor Platform works best when employee data are synced directly from your HRIS. We understand that your employee and personal company data are highly sensitive. We have over 35 years of experience handling highly confidential, sensitive data for our customers. Securing the data that you share with us is our number one priority and foundational to everything that we do at ERI. 

Protection that’s built in, not bolted on

Enterprise Encryption

Sensitive data are encrypted both in transit and at rest to help protect information wherever it travels.

Secure Platform Access 

ERI’s Assessor Platform implements Role-Based Access Control and practices Least Privilege principles to ensure that uploaded data are accessible only to authorized users based on assigned role or organizational memberships/policies. 

Continuous Monitoring

We continuously monitor our systems for unusual activity and respond quickly to potential threats.

Protection for Customer Information 

ERI regularly conducts audits ensuring that customer information is safe and secure.

Everything that your security team needs

For customers, prospects, procurement teams, legal teams, and IT reviewers, the ERI Trust Center provides access to security, privacy, and compliance information, all in one place.

  • Latest SOC 2 Report
  • Penetration Test Summary
  • Privacy Policy
  • Subprocessor List
  • Frequently Asked Security Questions
Visit the ERI Trust Center

Here you can find the following:

Security Documentation
Compliance Information
Privacy Resources
Vendor Review Support

How ERI Safeguards Your Data

ERI is committed to protecting customer information and supporting organizations that rely on our compensation data, survey analytics, and software.

Annual Third-Party Penetration Testing

Independent security professionals regularly evaluate our platform to identify and address potential vulnerabilities.

Customer Data Protection 

ERI protects sensitive information that customers provide and use within the Assessor Platform. 

Secure Compensation Analysis 

Users can safely conduct their compensation planning, market pricing, survey management, and job-level analysis within a protected environment. 

Responsible Data Handling 

ERI’s data practices are designed to support confidentiality, privacy, and trusted use of compensation information. 

Your Data Belongs to You

You always retain ownership of your data. ERI provides support for exporting or purging your data. 

We do not use customer data to train AI models

Market data are aggregated and anonymized

Well Trained and Highly Skilled Staff

ERI employees undergo rigorous onboarding training, complete quarterly performance-based security training courses, and take part in annual security awareness training programs.

Frequently Asked Questions

Visit the ERI Trust Center at trust.erieri.com for available security, privacy, and compliance resources.

ERI has completed an SOC 2 examination. Visit the ERI Trust Center for available SOC 2 information.

The ERI Trust Center is useful for customers, prospects, IT teams, legal teams, procurement teams, compliance teams, and vendor management reviewers.

  • Internal security documentation, policies, and procedures
  • Compliance documentation and audit results
  • Privacy resources

ERI makes protecting your data our core responsibility. We employ a defense-in-depth approach with multiple layers of technical, administrative, and physical controls to safeguard customer data. This includes uploaded files, prompts, documents, images, and usage history. All data are encrypted at rest and in transit. Access to data follows strict Role-Based Access Controls (RBAC), ensuring uploaded data are only accessible to authorized users based on role, team, and explicit permissions. Least privilege principles are enforced across the organization. Customer data are logically separated. We leverage secure infrastructure, continuous monitoring, intrusion detection, and advanced threat protection. We validate with annual penetration testing, ongoing vulnerability management, and SOC 2 auditing to address any risks before they can impact customers. We do not use customer data to train AI models. You retain ownership of your data at all times. We provide support for exporting or purging your data.

Transparency: We provide clear, accessible information on how we collect and analyze data, making us the trusted source for compensation data.

Data Ownership and Control: You own your data.

Compliance and Governance: We support major privacy regulators. ERI aligns with industry standards through independent audits, SOC 2 compliance, and internal review.

Security is only the beginning. ERI builds lasting trust through transparency, genuine data ownership, ethical development and data analytics, and meaningful user input, feedback, and control.

At ERI, we maintain a rigorous security posture through regular, independent validation of our systems. We conduct comprehensive annual penetration testing performed by qualified, third-party security firms to proactively identify and remediate potential vulnerabilities. We implement continuous internal vulnerability scanning, code reviews, and targeted assessments throughout the year. Results are always reviewed by leadership and our security team.

ERI’s security program aligns with industry best practices and supports our compliance with SOC 2.

We conduct penetration testing annually.

ERI is committed to respecting intellectual property rights while providing the best compensation management platform globally. We maintain processes to report violations and ensure a clear process for handling claims.

Confidence Starts with Trust

Whether you're evaluating our platform for the first time or completing a vendor security review, we're committed to providing the transparency that your team needs to make an informed decision.