# formcel Trust Center — Controls

> formcel runs every customer on dedicated, isolated infrastructure in the region they choose, encrypts all data at rest and in transit, and builds toward formal attestation in the open. This page lists exactly what we have in place today, what is self-attested, and what is still on the roadmap.

Source: https://trust.formcel.com/controls · Last updated: 2026-09-02 · formcel, Inc., formcel.com

## Controls

25 controls are live in production today. Nothing on this list is aspirational.

### Infrastructure security (5)

- **Dedicated instances** — Separate compute and processes per customer. No shared runtimes.
- **Isolated databases** — One database per customer and one per form. Physical, not logical, separation.
- **Regional data residency** — Data stays in the region selected at signup unless the customer configures replication.
- **Encrypted backups** — Automated backups encrypted with AES-256, point-in-time recovery available.
- **Rate limiting** — Automatic limits on authentication and API endpoints.

### Encryption and data protection (4)

- **AES-256 at rest** — All stored data, including backups and file uploads.
- **TLS 1.3 in transit** — HSTS enforced, no fallback to older protocols.
- **Security headers** — HSTS, X-Content-Type-Options and X-Frame-Options on every response.
- **CSRF and XSS protection** — SameSite cookies, content-type validation, strict output encoding.

### Access security (7)

- **Passwordless authentication** — One-time magic links; no passwords stored.
- **Passkeys** — FIDO2 / WebAuthn hardware and biometric authentication.
- **Two-factor authentication** — TOTP with any authenticator app and recovery codes.
- **SAML SSO** — Any SAML 2.0 identity provider, available on all paid plans.
- **Role-based permissions** — Admin, member and viewer roles with form- and folder-level grants.
- **Scoped API keys** — Prefix-identified keys and service accounts that can be rotated, expired and revoked.
- **Session management** — Configurable timeouts, idle expiration, device tracking and remote revocation.

### Product security (5)

- **Audit logging** — Every login, data access, permission change and admin action recorded with timestamp, IP and user agent.
- **Configurable retention** — Per-form retention with compliance presets enforcing minimums.
- **Audit log export** — Full history exportable for SIEM or compliance reporting.
- **No tracking** — A single session cookie. No analytics, advertising or third-party pixels.
- **Data deletion** — Personal data erased within 30 days of account deletion; backups purged within 90.

### Organizational security (4)

- **Data processing agreement** — Standard DPA with EU Standard Contractual Clauses available on request.
- **Subprocessor notifications** — Customers notified 30 days before a new subprocessor is added.
- **Breach notification** — Affected customers notified within 72 hours of confirmation.
- **Responsible disclosure** — Vulnerability reports accepted at security@formcel.com.

## Contact

- Security — vulnerability reports and security questionnaires: security@formcel.com
- Privacy — data subject requests, DPAs and privacy inquiries, answered within 30 days: privacy@formcel.com

We accept responsible disclosure. Report in good faith, give us reasonable time to fix, and we will not pursue legal action.

## Other pages

- [Overview](https://trust.formcel.com/index.md): Security and compliance posture at a glance: frameworks, control counts, documents and FAQ.
- [Subprocessors](https://trust.formcel.com/subprocessors.md): Complete list of third parties that may process customer data, with purpose, data category and location.
- [Resources](https://trust.formcel.com/resources.md): Policies, legal agreements and security reports, marked public or available on request.
- [Data residency](https://trust.formcel.com/residency.md): Regions where customer data can be stored and processed.
- [FAQ](https://trust.formcel.com/faq.md): Answers to the questions asked most often in security reviews.
