Oh, they're also requiring that we encrypt the answers in the database. With encryption keys stored on the same server. But that's a separate (and arguably sillier) issue.
Oh, they're also requiring that we encrypt the answers in the database. With encryption keys stored on the same server. But that's a separate (and arguably sillier) issue.
Well, that's fine. Just keep the decryption key somewhere else, or don't use an algorithm that can be decrypted.
The only thing required is a well-designed text normalization algorithm, which will neglect all variations in case, spacing, punctuation, spelling (i.e. "color" vs "colour") and other similar sort of issues.
(In edge cases, where this may fail, the plaintext answers could be recovered by authorized person from off-site write-only-API "secret storage" server, where the data should lay encrypted with asymmetric crypto. Less convenient, but more secure.)