Every survey tool promises anonymity. None can prove it. The same system holds the names and the answers. CandidSignal splits them apart with mathematics, so a response cannot be traced to a person. Not by the vendor. Not by the employer. Not by us. Not under subpoena.
Ask HR leaders why survey scores look fine right up until the exit interviews don't, and you'll hear the same thing: people answer carefully. "Anonymous" means we promise we won't look. That's a policy. It can be revoked, it can't be checked, and every employee knows it. So the candid signal you bought the survey to collect is exactly the signal people hold back.
The problem isn't your survey tool. It's that a promise is doing a job only proof can do.
CandidSignal is an anonymity layer that plugs into the survey platform you already use. Your vendor keeps the surveys, the questions, the dashboards, the branding. We sit underneath, the way a payment processor sits under a checkout, and change exactly one thing: whether anonymity is a promise or a property of the system. We are not a survey platform, and we never will be. A trust layer only works if it's run by a party with nothing to gain from looking.
You open the survey in your vendor's normal page. Their system (the one that already knows you) hands your browser a one-time ticket request. Your name never leaves their side of the fence.
Our system signs it without being able to read it (picture stamping a sealed envelope right through the paper). Your browser then unseals it. The result: a valid, one-time credential that no server anywhere has ever seen.
The vendor sees an answer with no name. We see a used ticket with no answer. Nobody holds both halves, and the two can't be joined by cooperation, hacking, or court order. The information needed to join them was never created.
| Knows who you are | Sees your answer | |
|---|---|---|
| Your survey vendor | Yes, they invited you | Yes, with no name attached |
| CandidSignal | No | Never |
| Your employer | Yes, they employ you | Only cohort reports |
Every count is published to a public, tamper-evident log (the same mechanism that secures the web's certificate system), so an auditor, a works council, or a skeptical employee can check the totals without asking our permission.
Take a real survey, watch each cryptographic step narrated in plain language, try to submit twice, then verify your own receipt.
app.candidsignal.com →Signed tree heads published continuously. Verifiable by anyone with the included command-line tool, from public files, trusting no one.
View the log →The code in the respondent's browser builds bit-for-bit identically and ships with integrity hashes. The cryptographic core is open source.
View the repo →Anonymity is unconditional. Response integrity is conditional, but independently auditable.
The math makes it impossible to link a response to a person: the information doesn't exist. It makes tampering with results detectable rather than impossible, via the published issuance counters and the public log. We never market it the other way around.
We'll even tell you how we could cheat, and how you'd catch us: we could over-issue credentials. That is exactly what the published per-survey counters exist to expose. Honest systems tell you where to point the flashlight.
Offer what no competitor can: provable anonymity, under your brand, integrated in weeks. Three touchpoints: a signed voucher from your backend, a ~95 KB browser SDK, and one receipt check on submit. Your surveys, dashboards, and customer relationships stay entirely yours: we're structurally incapable of competing with you.
Talk integration →Get the candid signal you're already paying for, on the platform you already use. Post-incident, regulated, unionized, or just tired of survey scores you don't quite believe: ask your vendor for CandidSignal, or talk to us about a design-partner pilot.
Ask about a pilot →Really. The credential accompanying your response was signed sealed (blind signatures, RFC 9474, an internet standard): no server has ever seen it unsealed until you submit. There's no database row, log line, or backup tape connecting it to you, because that connection was never created. The data isn't deleted or locked away. It never exists.
Still no. That's the bar the cryptography clears: full collusion of every server-side party cannot link a response to a person. The only computer that ever held both halves is your own browser.
It can compel us to hand over everything we have. Everything we have is sealed-signature records, used-credential fingerprints, answer fingerprints, and coarse counters. None of it identifies anyone, and no legal process changes the math.
One credential per eligible person (a second request is refused; try it in the demo), one redemption per credential. And the honest part: stopping us from over-issuing is what the published counters are for. Anyone can check redeemed ≤ issued ≤ headcount. We convert "trust the issuer" into "check the counter."
No. Nothing to install, no account, nothing crypto-flavored. It runs inside the survey page they already open, in any modern browser.
No. The public log is a signed Merkle tree: the boring, proven mechanism behind Certificate Transparency, which your browser relies on every day. No tokens, no coins.
Three honest ones. Small-cohort inference: math can't stop a manager guessing from writing style in a five-person team, so cohort-size discipline stays in the vendor's reporting. The guarantee assumes your browser ran our published code, which is why it's reproducibly built, integrity-hashed, and auditable instead of "trust us." And we prevent tracing, not telepathy: type your own name into a comment box and you've signed your answer.