Controls
Updated 25 live in productionInfrastructure security
| Control | Status |
|---|---|
Dedicated instances Separate compute and processes per customer. No shared runtimes. | Live |
Isolated databases One database per customer and one per form. Physical, not logical, separation. | Live |
Regional data residency Data stays in the region selected at signup unless the customer configures replication. | Live |
Encrypted backups Automated backups encrypted with AES-256, point-in-time recovery available. | Live |
Rate limiting Automatic limits on authentication and API endpoints. | Live |
Encryption and data protection
| Control | Status |
|---|---|
AES-256 at rest All stored data, including backups and file uploads. | Live |
TLS 1.3 in transit HSTS enforced, no fallback to older protocols. | Live |
Security headers HSTS, X-Content-Type-Options and X-Frame-Options on every response. | Live |
CSRF and XSS protection SameSite cookies, content-type validation, strict output encoding. | Live |
Access security
| Control | Status |
|---|---|
Passwordless authentication One-time magic links; no passwords stored. | Live |
Passkeys FIDO2 / WebAuthn hardware and biometric authentication. | Live |
Two-factor authentication TOTP with any authenticator app and recovery codes. | Live |
SAML SSO Any SAML 2.0 identity provider, available on all paid plans. | Live |
Role-based permissions Admin, member and viewer roles with form- and folder-level grants. | Live |
Scoped API keys Prefix-identified keys and service accounts that can be rotated, expired and revoked. | Live |
Session management Configurable timeouts, idle expiration, device tracking and remote revocation. | Live |
Product security
| Control | Status |
|---|---|
Audit logging Every login, data access, permission change and admin action recorded with timestamp, IP and user agent. | Live |
Configurable retention Per-form retention with compliance presets enforcing minimums. | Live |
Audit log export Full history exportable for SIEM or compliance reporting. | Live |
No tracking A single session cookie. No analytics, advertising or third-party pixels. | Live |
Data deletion Personal data erased within 30 days of account deletion; backups purged within 90. | Live |
Organizational security
| Control | Status |
|---|---|
Data processing agreement Standard DPA with EU Standard Contractual Clauses available on request. | Live |
Subprocessor notifications Customers notified 30 days before a new subprocessor is added. | Live |
Breach notification Affected customers notified within 72 hours of confirmation. | Live |
Responsible disclosure Vulnerability reports accepted at security@formcel.com. | Live |