Security & compliance

Responses that stay yours

Access to your data is enforced in the database itself, not only in the interface. Here is what that means in practice — and what we deliberately do not claim.

What it looks like

What you get

  • Row-level access rules

    Every table that holds your data carries policies that scope rows to your account, so a request for someone else's responses returns nothing rather than relying on UI checks.

  • Credentials never reach the browser

    Integration keys and payment credentials are stored server-side and are not rendered into your published form.

  • Abuse limits on public forms

    Public submission endpoints are rate limited, so a scripted flood is throttled instead of filling your inbox.

  • Deletion, export and a DPA

    Delete a response to Trash and purge it permanently with an audited trail, export everything as CSV or Excel, and sign our Data Processing Agreement.

How it works

  1. 1

    Read the trust page

    Data protection, sub-processors and the latest security scan date in one place.

  2. 2

    Set your form's visibility

    New forms are not indexable by default; opt in per form when you want to be found.

  3. 3

    Sign the DPA if you need one

    The agreement is published and available before you subscribe.

Questions

See the detail on the trust page

Data protection, sub-processors, scans and security contact.