All data is processed without individual answers ever becoming visible, not to the organiser, not to S3ntiment, not to third parties. That isn't a policy choice but a property of the architecture.

When you think about survey risk, you think about the outside: someone breaks in, someone ends up with data that wasn't meant for them. But anyone who knows the people doesn't need any of that. An organiser knows who was invited, knows the department, recognises a writing style. Anonymity that exists only because there's no name above an answer isn't anonymity in that situation.

The questions are fixed in advance

When the survey is created, it's established which breakdowns and calculations are possible. Nothing can be added later. An organiser can't gradually carve the data into smaller and smaller groups until something recognisable falls out, because the questions that can be asked of the data are the same questions that were allowed to be asked of it from the start.

The puzzle exists nowhere as a whole

Answers don't end up in one place. They're distributed across three nodes in a decentralised network, each with its own trusted execution environment: a sealed part of the processor that can't be looked into from outside, not even by whoever runs the machine. Tracing anything back would mean getting into three nodes at once and then fitting the pieces together again.

A single answer can't be read on its own

For numbers, ratings and multiple choice it goes a step further, because the individual answer is itself divided across the three nodes. An answer of 2 is stored as -6, 3 and 5. Each fragment means nothing by itself, and only all three together produce the original answer. Break into one node and you find noise.

Answers never leave the secure environment

To produce a total, each node is asked separately for a partial total. The individual answers stay inside the TEE; only the partial totals come out, and those are added together. The result is correct to the digit, without any one system ever having seen all the answers together.

Crack one machine and you find noise

Where the protection is a single layer

For multiple choice, scales and rankings both levels apply: distribution across nodes and computation on divided values. For open text answers only the isolation of the TEE applies. That's stronger than a platform's promise, but it is one layer, and the moment a survey includes text answers that layer determines the whole.

Rights nobody has to grant

The GDPR asks for privacy in the system itself, not for policy that describes after the fact what happens. A privacy statement and a data processing agreement document the risk; they don't reduce it. At S3ntiment, not being able to look is not an agreement but a property of the setup, and that spares the organiser the position of having to explain why they don't do something they could.

The same goes for respondents' rights. Access and deletion don't have to be requested, assessed and granted, because nobody stands between a respondent and their own answers. What is a procedure elsewhere is a button here.

On the matter of privacy

  • Answers split across three nodes, complete nowhere
  • Individual answers never leave the secure environment
  • Breakdowns are fixed in advance, not widened afterwards
  • Access and deletion without an intermediary
  • Not promised, mathematically enforced