Confidential by design. Explicit by policy.
Security and privacy
Confidential by design. Explicit by policy.
Individual feedback is protected. Results release only when configured participation and aggregation rules are satisfied.
Can HR see individual responses?
Individual rater responses are not exposed as identifiable submissions to HR or managers by default. People administrators see program participation and aggregated results according to policy.
When are results released?
Results appear when minimum response thresholds and program rules are met. If a rater group is too small, aggregated views may be withheld to protect anonymity.
What can a manager see?
Managers typically see participation status for their scope and aggregated themes—not individual rater identities—unless your organization configures selective sharing for development coaching.
Who owns the development plan?
The leader receiving feedback owns their development plan. Sharing with a manager or coach is optional and controlled by the leader and organization policy.
Can data be deleted?
Retention and deletion follow organization policy and plan capabilities. Contact us for enterprise retention requirements.
Who can see what
| Information | Leader | Manager / coach | People admin |
|---|---|---|---|
| Individual rater response | No | No | No |
| Aggregated results | Yes | Policy-based | Scope-based |
| Development plan | Owner-controlled | Shared selectively | Not automatic |
| Program participation | Own status | Scoped | Program-level |
Validate exact behavior against your deployment and plan before procurement.
How anonymity thresholds work
Capablio aggregates feedback before themes are shown. If participation in a rater group does not meet the configured minimum, that slice may be hidden rather than risking identification.
Implemented today
| Control | Status |
|---|---|
| TLS for data in transit | Implemented |
| Multi-tenant data isolation | Implemented |
| Google Sign-In (OIDC id tokens) | Implemented |
| Role and scope authorization | Implemented |
| Aggregation thresholds before results release | Implemented |
| Sealed response envelopes | Implemented |
Available by plan
| Control | Typical availability |
|---|---|
| SAML/OIDC SSO | Team add-on / Enterprise |
| SCIM | Enterprise |
| Extended audit export | Team / Enterprise |
| Advanced retention policy | Enterprise |
Technical detail
- Encrypted in transit (TLS) for browser and API traffic.
- Sealed response envelopes store protected submissions on the server.
- Subject-controlled keys for sealing submissions (explained in product documentation).
Capablio does not display compliance badges or uptime guarantees without verified evidence.
Who can see what
Validate exact behavior against your deployment and plan before procurement.
| Individual rater responses | Not exposed to managers or HR by default |
|---|---|
| Aggregated results | Released when minimum thresholds are met |
| Development plans | Owned by the leader; sharing is optional and controlled |
Privacy and security
- Privacy controls for protected individual responses
- Admin review before aggregated results release
- Evidence trail for development actions and check-ins
- Governed security posture — security overview