Security at Forminit
Forminit is hosted on Amazon Web Services in Ireland, within the European Union. Submission data is encrypted in transit and at rest, and we provide controls for authentication, access, spam prevention and data management.
Security at a glance
EU data residency
Form submission data, including uploaded files and backups, is hosted on AWS infrastructure in Ireland, European Union.
Encryption at rest
Submission data is encrypted at rest using AES-256 encryption.
Encryption in transit
Connections to Forminit are protected using HTTPS with TLS 1.2 or higher.
Protected API access
Server-side integrations can use Protected Mode, which requires a secret API key for submissions.
Spam and abuse protection
Built-in protection can be combined with rate limiting, authorised domains, honeypots, Cloudflare Turnstile and hCaptcha.
Signed webhooks
Webhook requests can be cryptographically verified using HMAC-SHA256 signatures.
Restricted internal access
Internal access to production systems by the Forminit team requires an encrypted VPN and follows the principle of least privilege.
GDPR & UK GDPR
Forminit provides a Data Processing Agreement and documents its subprocessors and data-processing practices.
Infrastructure & data residency
Forminit runs on Amazon Web Services (AWS). Form submission data, including uploaded files and backups, is stored on AWS infrastructure located in Ireland, European Union.
AWS maintains independently audited security and compliance programmes, including ISO 27001 and SOC certifications. These certifications apply to AWS's infrastructure and should not be interpreted as certifications held directly by Forminit.
We choose established infrastructure providers and services that provide appropriate security, availability and operational controls for the data they process.
You can find more information about how personal data is handled on our GDPR and Privacy Policy pages.
Backups
Submission data is backed up to support reliability and disaster recovery. Backups are encrypted in transit and at rest using AES-256 and are retained redundantly across multiple availability zones within the AWS Ireland region.
When a submission is deleted, it is removed from live systems and expires from backups within 35 days. Data in backups is not restored to live systems except as part of disaster recovery.
Data encryption
Encryption at rest
Submission data stored by Forminit is encrypted at rest using AES-256 encryption.
Encryption in transit
Data transmitted between your application, your users and Forminit is encrypted using HTTPS with TLS 1.2 or higher. This protects submission data while it travels across the network.
Application security
Forminit is designed as a backend for receiving data from websites, applications and server-side systems. Security controls are applied on the server rather than relying on code running in the user's browser.
Server-side validation
Forminit supports structured form blocks and performs validation on incoming submission data. This allows validation rules to be enforced by Forminit even if browser-side validation is modified or bypassed.
Public and Protected Modes
Forms can operate in two authentication modes. Public Mode is designed for forms submitted directly from websites and client-side applications where a secret API key cannot safely be stored. Protected Mode is designed for server-side integrations. Requests require an API key that should remain securely stored on the server and never be exposed in browser code.
Protected Mode provides an additional authentication layer for applications handling sensitive or higher-volume submissions.
API authentication
Secret API tokens can be created for authenticated access to Forminit APIs and Protected Mode forms. API keys should be stored in environment variables or secret-management systems rather than committed to source code.
Authorised domains
Forms can be restricted to approved domains. Requests originating from unauthorised websites can be identified and handled as spam, helping prevent third parties from abusing a public form endpoint.
Spam & abuse protection
Forminit includes built-in protections designed to reduce automated spam and abusive submissions. Additional protection can be enabled depending on the requirements of each form, including:
- Rate limiting
- Authorised domain restrictions
- Honeypot fields
- Cloudflare Turnstile
- hCaptcha
- IP-based abuse detection
- Automated spam filtering
These controls can be combined to provide multiple layers of protection. No spam-prevention system can guarantee that every unwanted submission will be detected, so customers should select the controls appropriate for their use case.
Webhook security
Forminit supports signed webhooks so receiving applications can verify that a webhook genuinely originated from Forminit. Webhook requests can include:
- A unique webhook identifier
- Timestamp
- HMAC-SHA256 signature
The signature is generated using a secret known only to Forminit and the customer. Applications can verify the signature before processing the webhook body and reject requests with invalid signatures or timestamps outside the accepted tolerance.
This helps protect webhook integrations against forged requests and replay attacks.
File uploads
Forminit supports file uploads as part of form submissions. Uploaded files are stored alongside submission data within Forminit's infrastructure and access is controlled through the Forminit application.
File uploads are subject to file-size and file-type validation before they are accepted.
Customers should avoid requesting unnecessary sensitive documents and should only collect information required for their stated purpose.
Access control
Account registration on Forminit is protected by Cloudflare Turnstile, which helps block automated sign-ups to the platform.
Administrative access to Forminit's internal services and databases is only possible over an encrypted VPN connection and is limited to authorised personnel.
Internal access follows the principle of least privilege: it is role-based, uses unique credentials, requires approval before it is granted, and is removed promptly when a team member changes role or leaves.
Access to customer personal data by Forminit personnel or approved service providers is restricted to circumstances where it is necessary to operate, maintain or support the service.
Personnel with access to personal data are subject to confidentiality obligations and receive appropriate data-protection and security training.
Data ownership & control
Customers remain in control of the information collected through their forms. For respondent data collected through a customer's form:
- The Forminit customer acts as the Data Controller.
- Forminit acts as the Data Processor.
Customers can access, manage, export and delete their submission data through Forminit. Forminit processes respondent data on behalf of the customer and according to the customer's instructions, subject to our Terms, Data Processing Agreement and applicable law.
We do not sell respondent submission data.
We do not use submission data to train artificial intelligence models, including large language models.
Data retention & deletion
Forminit provides controls for managing the lifecycle of submission data. Customers can delete submissions when they are no longer required. Deleted submissions, including any associated uploaded files, are removed from live systems and expire from backups within 35 days.
Customers remain responsible for determining an appropriate retention period for the personal data they collect.
When an account or processing relationship ends, Forminit deletes or returns personal data in accordance with our Data Processing Agreement, subject to any legal obligations requiring continued retention.
For more information, see our Privacy Policy and GDPR information.
Subprocessors
Forminit uses a limited number of service providers to operate parts of the platform, such as cloud infrastructure, payment processing, monitoring and spam prevention.
We maintain a list of our subprocessors, their purpose and their processing location on our GDPR page.
Where Forminit acts as a processor, subprocessors are required to provide appropriate data-protection and security safeguards.
Monitoring & reliability
Forminit monitors its application and infrastructure to identify operational problems, errors and service interruptions. Security-relevant logs from applications and infrastructure are collected centrally, reviewed by the team and escalated when necessary.
The infrastructure supporting Forminit spans multiple fault-independent AWS availability zones within the Ireland region to support high availability.
We maintain processes for investigating and responding to incidents affecting the availability or security of the service. Changes to the Forminit application are tested in a staging environment before being deployed to production.
Current and historical service availability can be viewed on our public Status Page.
Security incidents
If Forminit becomes aware of a personal data breach affecting data processed on behalf of a customer, we will notify the affected customer without undue delay in accordance with our Data Processing Agreement and applicable data-protection law.
We will provide reasonable information and assistance required for the customer to assess the incident and meet their own regulatory obligations.
Privacy & data protection
Forminit is operated by UXPLUS LTD, a company registered in the United Kingdom. Our privacy and data-protection documentation includes:
- Privacy Policy
- GDPR Compliance
- Data Processing Agreement (available on request via our contact page)
- Subprocessor information (listed on our GDPR page)
- CCPA information
- Terms & Conditions
These documents explain Forminit's role as a controller and processor, how personal data is handled and the responsibilities of customers using Forminit to collect information.
Responsible vulnerability disclosure
We welcome responsible reports from security researchers and customers who believe they have identified a security issue affecting Forminit.
Please report security concerns to privacy@forminit.com. When reporting an issue, include:
- A description of the vulnerability
- Steps required to reproduce it
- The affected endpoint or feature
- Any supporting evidence that can help us investigate
Please do not publicly disclose a suspected vulnerability before we have had a reasonable opportunity to investigate it. When testing, please avoid accessing data that is not your own and avoid actions that could degrade the service for other users.
We will acknowledge legitimate reports, keep the reporter informed where practical, and work to address confirmed vulnerabilities as appropriate.
Questions about security?
If your organisation is reviewing Forminit for security, privacy or regulatory requirements, please contact us. We can provide additional information about our infrastructure, data processing practices and security controls where appropriate.
You can also review our: Privacy Policy · GDPR Compliance · Status Page · Documentation