
Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.
Quick links
Qualtrics' XM platform offers artificial intelligence (AI) powered functionality to analyze massive datasets, uncover hidden patterns and relationships, and drive innovation and improvement for our customers. Whether you’re an end user within Qualtrics’ cloud service, performing a vendor risk assessment, asking security questions, seeking legal or privacy approvals within your organization, etc., and have thought something along the lines of:
“I’m interested in Qualtrics’ AI features, but I need to meet my own company’s compliance requirements. Where do I start, what do I do next?”
We recommend flowing down through our “3 Tier Waterfall” approach, and the resources alluded to in each tier therein;
These support pages detail the AI features we offer, permissions required to utilise them and the models in use, along with any subprocessors involved.
This was the first internationally recognised certification for AI management systems (AIMS) and it is only held by a small number of Organizations globally at present. It sets out a practical framework for organizations to govern AI responsibly, manage risks and promote ethical and trustworthy AI practices. Qualtrics' assessment against the framework's requirements demonstrates that our approach to AI development, deployment and governance aligns with international benchmarks for managing AI risks and opportunities.
This document outlines Qualtrics’ comprehensive framework for AI security, privacy and compliance, detailing our policies on ethical data use, model governance, testing and training and AI risk management. It explains how we prioritize transparency and security by ensuring customer control over AI feature access, leverage anonymized data for training and maintain robust oversight to meet reputable industry standards like ISO 42001 and NIST AI Risk Management frameworks.
It further features an Appendix which answers the top 20 themes/FAQs we’re seeing from customers globally on AI as it pertains to our services.
These artifacts are feature specific guidebooks, which dive deeper on insights for assessing, understanding and utilizing the precise AI features we offer E.g. AI feature category, AI type, feature usage and data (Likely to be) involved, customer's control over inputs, prompts and outputs, an overview of the end user experience, privacy considerations for the feature and a data flow diagram, with a supporting written description.
Qualtrics is authorized at the FedRAMP High impact level, supporting federal, state, and local government agencies that handle mission-critical and sensitive data. Qualtrics is committed to transparent security practices and the responsible stewardship of government data.
Access is limited to eligible government agencies and is subject to verification. Public sector customers may request access to the Qualtrics FedRAMP High security package here:
At Qualtrics, we understand the profound responsibility of safeguarding your data. Your trust in us to secure your sensitive information is the foundation of our commitment to you. This is why security is embedded in our design, philosophy, and daily operations. Our systems are engineered with resilience, designed to withstand and recover from adverse conditions. We operate under the principle of "secure by design," which means creating an architecture that remains secure even if individual components fail.
Security at Qualtrics is a continually evolving discipline. We subject our systems to rigorous internal and external security assessments and penetration tests. These evaluations are not one-time events but part of an ongoing effort to enhance our security posture. We understand the ever-changing threat landscape and commit to staying ahead through constant vigilance and innovation. Access to sensitive data is strictly controlled under the principle of least privilege. Only individuals with a demonstrated need and bound by confidentiality obligations can access this data. We continuously monitor and audit these permissions to ensure the highest standards of accountability and security.
Data protection is paramount. We ensure your data is encrypted in transit and at rest. We employ advanced encryption protocols to maintain the highest levels of data security. Our trusted data center providers also adhere to rigorous industry standards and have earned globally recognized certifications to guarantee further protection. Transparency is critical to building and maintaining trust. We pledge to be open about our security practices, methodologies, and incident response protocols. Our Cloud Security Framework provides a detailed overview of our platform's security features and is backed by numerous globally recognized certifications, ensuring independent oversight and validation of our security controls.
Security is more than just a practice at Qualtrics, it is ingrained in our culture and ethos. We are committed to not just meeting but exceeding industry standards and ensuring you have peace of mind when entrusting us with your data. Maintaining confidentiality, integrity, and availability of your information is not just our responsibility—it is our dedication. We want you to feel reassured and valued when you choose Qualtrics.
Thank you for placing your trust in Qualtrics. We are honored to protect your data and remain steadfast in our mission to provide the highest standards of security. Your trust is not taken for granted, and we appreciate the opportunity to serve you.
Bill Sole
Qualtrics CSO