# formcel Trust Center

> formcel runs every customer on dedicated, isolated infrastructure in the region they choose, encrypts all data at rest and in transit, and builds toward formal attestation in the open. This page lists exactly what we have in place today, what is self-attested, and what is still on the roadmap.

Source: https://trust.formcel.com/ · Last updated: 2026-09-02 · formcel, Inc., formcel.com

## At a glance

- 25 controls live in production across 5 categories
- 11 frameworks tracked; 0 third-party certified
- 11 subprocessors disclosed, last changed 2026-09-02
- 40 data residency regions
- 7 documents, 2 public and 5 available on request

## Compliance frameworks

| Framework | Scope | Status | Details |
| --- | --- | --- | --- |
| GDPR | EU data protection | Compliant | Full EU data protection compliance. Data residency in 12 European regions. Right to erasure, data portability, and consent management. |
| UK GDPR | United Kingdom | Compliant | Same controls as GDPR. ICO registration pending. |
| CCPA / CPRA | California | Compliant | Privacy notice, opt-out, Global Privacy Control honored. |
| PIPEDA | Canada | Compliant | Named privacy officer, OPC breach reporting process. |
| LGPD | Brazil | Compliant | GDPR-equivalent controls with a designated encarregado. |
| HIPAA-ready | Health data protection | In progress | Health data protection with enforced audit retention (6+ years), mandatory access logging, and encrypted PHI storage. The technical safeguards are in place today; formal attestation and business associate agreements are on our roadmap. |
| PCI DSS SAQ A | Card payments | In progress | Card data never touches our servers; handled entirely by Stripe. |
| CSA STAR Level 1 | Cloud security self-assessment | Planned | CAIQ submission to the CSA registry. |
| SOC 2 aligned | Security & availability | Planned | Security and availability controls with comprehensive audit trails, access monitoring, and 1+ year log retention. Our SOC 2 audit is planned — no report has been issued yet. |
| ISO 27001 | Information security management | Planned | Follows SOC 2 on the roadmap. |
| WCAG 2.2 AA | Accessibility | In progress | Self-authored VPAT for the form renderer. |

Status values are `certified`, `self-attested` (labelled Compliant), `in-progress` and `planned`. "Compliant" is our own assessment against the framework, not a third-party certification. No audited report exists for SOC 2, ISO 27001 or HIPAA; none is claimed.

## Controls

25 controls are live in production today. Nothing on this list is aspirational.

### Infrastructure security (5)

- Dedicated instances
- Isolated databases
- Regional data residency
- Encrypted backups
- Rate limiting

### Encryption and data protection (4)

- AES-256 at rest
- TLS 1.3 in transit
- Security headers
- CSRF and XSS protection

### Access security (7)

- Passwordless authentication
- Passkeys
- Two-factor authentication
- SAML SSO
- Role-based permissions
- Scoped API keys
- Session management

### Product security (5)

- Audit logging
- Configurable retention
- Audit log export
- No tracking
- Data deletion

### Organizational security (4)

- Data processing agreement
- Subprocessor notifications
- Breach notification
- Responsible disclosure

## Resources

### Legal

- **Privacy Policy** — https://formcel.com/privacy (updated 2026-08-21)
- **Terms of Service** — https://formcel.com/terms (updated 2026-08-21)
- **Data Processing Agreement** — available on request from security@formcel.com (updated 2026-09-02)

### Policies

- **Information Security Policy** — available on request from security@formcel.com (updated 2026-09-02)
- **Incident Response Plan** — available on request from security@formcel.com (updated 2026-09-02)
- **Business Continuity Plan** — available on request from security@formcel.com (updated 2026-09-02)

### Security reports

- **Penetration Test Summary** — available on request from security@formcel.com (updated 2026-09-02)

## FAQ

### Is formcel HIPAA-compliant, and do you sign a BAA?

The technical safeguards for PHI are in place today: encrypted storage, mandatory access logging and enforced 6+ year audit retention. Formal attestation and business associate agreements are still on our roadmap, so we do not sign BAAs yet.

### Are you GDPR-compliant, and how do I get a signed DPA?

We self-attest to GDPR and UK GDPR: EU data residency in 12 European regions, right to erasure, data portability and consent management. Our standard DPA with EU Standard Contractual Clauses is available on request from privacy@formcel.com.

### Where is my data stored, and can I choose a region?

You pick a region at signup. Data is stored and processed there on dedicated, isolated infrastructure and does not leave it unless you explicitly configure cross-region replication.

### How is data encrypted, in transit and at rest?

All stored data, including backups and file uploads, is encrypted with AES-256. Connections use TLS 1.3 with HSTS enforced and no fallback to older protocols.

### Do you have a SOC 2 report?

Not yet. Our controls are SOC 2 aligned and the audit is planned, but no report has been issued. We will publish the report here as soon as one exists.

### How will I know when you add a subprocessor?

Customers are notified 30 days before a new subprocessor is added. The full list, with purpose, data category and location, is published on this page with its last-change date.

## Contact

- Security — vulnerability reports and security questionnaires: security@formcel.com
- Privacy — data subject requests, DPAs and privacy inquiries, answered within 30 days: privacy@formcel.com

We accept responsible disclosure. Report in good faith, give us reasonable time to fix, and we will not pursue legal action.

## Other pages

- [Controls](https://trust.formcel.com/controls.md): Every security control live in production today, grouped by category, with a plain-English description.
- [Subprocessors](https://trust.formcel.com/subprocessors.md): Complete list of third parties that may process customer data, with purpose, data category and location.
- [Resources](https://trust.formcel.com/resources.md): Policies, legal agreements and security reports, marked public or available on request.
- [Data residency](https://trust.formcel.com/residency.md): Regions where customer data can be stored and processed.
- [FAQ](https://trust.formcel.com/faq.md): Answers to the questions asked most often in security reviews.
