Trust center
Data security and responsibility boundaries
This page describes security measures that can be verified in the current implementation, without claiming certifications we do not hold or using vague promises.
Identity and access control
Research, report, media, and administrative functions that require sign-in are protected by server-side authentication and authorization policies.
- Passwords are verified as salted digests rather than authenticated from plaintext passwords.
- Administrative, workspace, and business functions enforce server-side authorization checks.
- Recordings, reports, and export resources are checked by their respective business controllers.
Transport protection
The TrendFirst official site is served over HTTPS. Customers remain responsible for securing their devices, email, credentials, and sharing links.
Research content handling
Questions, responses, transcripts, recordings, video, and reports should be processed only as needed for the customer-directed research workflow.
- Media access URLs are resolved server-side according to storage type and access identity.
- AI processing and content retention are jointly constrained by system settings, business authorization, and the selected provider's rules.
- Customers must not upload personal data, trade secrets, or unlawful content they are not authorized to process.
Monitoring and log redaction
The system records operational, performance, and business-state events for troubleshooting and security audit, while redacting sensitive fields, email addresses, phone numbers, and credential-like text.
- Browser monitoring does not collect passwords, access tokens, question bodies, response bodies, or report bodies.
- Session replay, heatmaps, and general click tracking are currently disabled.
Customer responsibilities
The research organization determines the research purpose, participant population, content, retention needs, and member permissions, and is responsible for obtaining required authorization.
- Use least-necessary permissions for team members and sharing.
- Complete appropriate reviews before processing sensitive data, children's data, or cross-border data.
Report a security issue
If you suspect unauthorized access, a data incident, or a security defect, contact support@trendfirst.top immediately with the time, affected page, and necessary reproduction details. Do not send passwords or access tokens.
Need more help?
Tell us about your real research needs
Book a product demo, or contact support about accounts, interviews, and data handling.