Menu

Language

Security & Compliance

Security controls

Formabi handles sensitive form data. This page lists the encryption, authentication, audit, and hosting controls we run.

Encryption in transit

All traffic to Formabi is served over HTTPS (TLS 1.2/1.3) with HSTS. Internal database connections between application and database are TLS-encrypted as well.

Encryption at rest

Database storage sits on LUKS-encrypted volumes, and every backup is encrypted before it leaves the server. Your form data is never written to disk in the clear.

Two-factor authentication

Accounts can enable TOTP 2FA (Google Authenticator, 1Password, Authy, and others), with single-use recovery codes. 2FA secrets are encrypted at rest.

Single sign-on (SSO)

Connect your identity provider over OpenID Connect — Google Workspace, Microsoft Entra ID, Okta, or any OIDC-compliant IdP. Access follows your directory.

Immutable audit log

Sign-ins, administrative changes, permission updates, and data-subject actions are recorded to an append-only audit trail that cannot be altered or deleted.

Session management

Review the devices signed in to your account and revoke any session at any time. Sessions are stored hashed and expire automatically.

Strong authentication

Passwords are hashed with bcrypt; session and share-link tokens are never stored in the clear. Login attempts are rate-limited to slow brute-force attacks.

Vulnerability management

Our build pipeline scans dependencies for known vulnerabilities on every change, and infrastructure is patched through a reviewed, version-controlled process.

GDPR & data-subject rights

Formabi is hosted in the European Union, with the tools to answer requests from the people whose data lives in your forms — access, erasure, retention and consent — built into the product.

Data-subject access

Answer an access request in minutes: search your forms for a person and export everything you hold about them — every field, across every submission — as a single file.

Right to erasure

Erase a person's data on request — a whole submission or individual fields — permanently removed from files, database, search and exports. Every request is logged.

Retention controls

Configure how long form submissions are kept; older records are purged automatically per your policy.

Consent records

Consent is captured with a snapshot of the exact text shown, and can be withdrawn — every consent event is logged.

Infrastructure & tenancy

EU hosting

Servers run in the EU (Hetzner, Germany). Data does not leave the region.

Tenant isolation

Each tenant runs in its own container with a dedicated, access-scoped database — no shared application state.

Encrypted backups

Automated nightly backups, encrypted at rest, with a tested restore process and defined retention.

Security questions or a due-diligence review?

We can walk your team through these controls or complete a security questionnaire on request.

Or email us directly at help@formabi.com