Back to the official site

Trust center

Data security and responsibility boundaries

This page describes security measures that can be verified in the current implementation, without claiming certifications we do not hold or using vague promises.

Updated: August 2, 2026

Identity and access control

Research, report, media, and administrative functions that require sign-in are protected by server-side authentication and authorization policies.

  • Passwords are verified as salted digests rather than authenticated from plaintext passwords.
  • Administrative, workspace, and business functions enforce server-side authorization checks.
  • Recordings, reports, and export resources are checked by their respective business controllers.

Transport protection

The TrendFirst official site is served over HTTPS. Customers remain responsible for securing their devices, email, credentials, and sharing links.

Research content handling

Questions, responses, transcripts, recordings, video, and reports should be processed only as needed for the customer-directed research workflow.

  • Media access URLs are resolved server-side according to storage type and access identity.
  • AI processing and content retention are jointly constrained by system settings, business authorization, and the selected provider's rules.
  • Customers must not upload personal data, trade secrets, or unlawful content they are not authorized to process.

Monitoring and log redaction

The system records operational, performance, and business-state events for troubleshooting and security audit, while redacting sensitive fields, email addresses, phone numbers, and credential-like text.

  • Browser monitoring does not collect passwords, access tokens, question bodies, response bodies, or report bodies.
  • Session replay, heatmaps, and general click tracking are currently disabled.

Customer responsibilities

The research organization determines the research purpose, participant population, content, retention needs, and member permissions, and is responsible for obtaining required authorization.

  • Use least-necessary permissions for team members and sharing.
  • Complete appropriate reviews before processing sensitive data, children's data, or cross-border data.

Report a security issue

If you suspect unauthorized access, a data incident, or a security defect, contact support@trendfirst.top immediately with the time, affected page, and necessary reproduction details. Do not send passwords or access tokens.

Need more help?

Tell us about your real research needs

Book a product demo, or contact support about accounts, interviews, and data handling.

Support