Security & Compliance
Security controls
Formabi handles sensitive form data. This page lists the encryption, authentication, audit, and hosting controls we run.
Encryption in transit
All traffic to Formabi is served over HTTPS (TLS 1.2/1.3) with HSTS. Internal database connections between application and database are TLS-encrypted as well.
Encryption at rest
Database storage sits on LUKS-encrypted volumes, and every backup is encrypted before it leaves the server. Your form data is never written to disk in the clear.
Two-factor authentication
Accounts can enable TOTP 2FA (Google Authenticator, 1Password, Authy, and others), with single-use recovery codes. 2FA secrets are encrypted at rest.
Single sign-on (SSO)
Connect your identity provider over OpenID Connect — Google Workspace, Microsoft Entra ID, Okta, or any OIDC-compliant IdP. Access follows your directory.
Immutable audit log
Sign-ins, administrative changes, permission updates, and data-subject actions are recorded to an append-only audit trail that cannot be altered or deleted.
Session management
Review the devices signed in to your account and revoke any session at any time. Sessions are stored hashed and expire automatically.
Strong authentication
Passwords are hashed with bcrypt; session and share-link tokens are never stored in the clear. Login attempts are rate-limited to slow brute-force attacks.
Vulnerability management
Our build pipeline scans dependencies for known vulnerabilities on every change, and infrastructure is patched through a reviewed, version-controlled process.
GDPR & data-subject rights
Formabi is hosted in the European Union, with the tools to answer requests from the people whose data lives in your forms — access, erasure, retention and consent — built into the product.
Data-subject access
Answer an access request in minutes: search your forms for a person and export everything you hold about them — every field, across every submission — as a single file.
Right to erasure
Erase a person's data on request — a whole submission or individual fields — permanently removed from files, database, search and exports. Every request is logged.
Retention controls
Configure how long form submissions are kept; older records are purged automatically per your policy.
Consent records
Consent is captured with a snapshot of the exact text shown, and can be withdrawn — every consent event is logged.
Infrastructure & tenancy
EU hosting
Servers run in the EU (Hetzner, Germany). Data does not leave the region.
Tenant isolation
Each tenant runs in its own container with a dedicated, access-scoped database — no shared application state.
Encrypted backups
Automated nightly backups, encrypted at rest, with a tested restore process and defined retention.
Security questions or a due-diligence review?
We can walk your team through these controls or complete a security questionnaire on request.
Or email us directly at help@formabi.com