Controls
Updated- Dedicated instances
- Isolated databases
- Regional data residency
- AES-256 at rest
- TLS 1.3 in transit
- Security headers
- Passwordless authentication
- Passkeys
- Two-factor authentication
- Audit logging
- Configurable retention
- Audit log export
- Data processing agreement
- Subprocessor notifications
- Breach notification
FAQ
View all 6Is formcel HIPAA-compliant, and do you sign a BAA?
The technical safeguards for PHI are in place today: encrypted storage, mandatory access logging and enforced 6+ year audit retention. Formal attestation and business associate agreements are still on our roadmap, so we do not sign BAAs yet.
Are you GDPR-compliant, and how do I get a signed DPA?
We self-attest to GDPR and UK GDPR: EU data residency in 12 European regions, right to erasure, data portability and consent management. Our standard DPA with EU Standard Contractual Clauses is available on request from privacy@formcel.com.
Where is my data stored, and can I choose a region?
You pick a region at signup. Data is stored and processed there on dedicated, isolated infrastructure and does not leave it unless you explicitly configure cross-region replication.
How is data encrypted, in transit and at rest?
All stored data, including backups and file uploads, is encrypted with AES-256. Connections use TLS 1.3 with HSTS enforced and no fallback to older protocols.