Trust

Security and compliance at HelloForms

What we actually do to keep your forms and your respondents' data safe — with the numbers our own systems report, not badges we cannot back.

Uptime, last 30 days

Not available right now

View the status page

Latest automated security scan

4 September 2026

57 open findings · 0 resolved in that run

Finding details stay private; only the date and the counts are published.

We do not hold SOC 2, ISO 27001, HIPAA or PCI-DSS certification and we do not claim it. If your procurement process requires one of those, tell us before you buy.

Data protection

You are the controller of the responses your forms collect; we process them only to run the service on your instructions.

  • · Our standard Data Processing Agreement applies to every account automatically — no signature needed.
  • · Data residency: European Union — AWS eu-north-1 (Stockholm). The database, authentication and uploaded files all live in that region.
  • · Transfers outside the EEA/UK rely on the EU Standard Contractual Clauses or the UK International Data Transfer Addendum.
  • · We never use your submission data to train models or to target advertising.

Security practices

These are the controls implemented in the product today, not a roadmap.

  • · Row-level security on every table that holds account data, so no workspace can read another's records.
  • · Roles live in a separate privileged table and are checked server side — never in the browser.
  • · Server-only credentials: the privileged database key exists only in server functions and never ships to the client.
  • · An automated security scan runs nightly against the database configuration; new and resolved findings are emailed to the operator.
  • · Administrative actions are audit-logged, and dependency scans run against the installed packages.

Uptime

The same trailing-30-day figure the homepage prints, measured by our own probes.

  • · Live status, incident history and the 30-day uptime timeline are on the status page.
  • · Uptime is truncated, never rounded up. When the probe log cannot be read we show no figure rather than an invented one.

Payments

Card data is handled entirely by the payment provider.

  • · Subscription billing runs through Stripe Checkout; card numbers never touch our servers or our database.
  • · Form payments run through the gateway you connect. We store the payment reference and status, not the instrument.

Backups and exports

Your data is portable at any time.

  • · The managed database is backed up automatically by the platform on its own rotation.
  • · Submissions export to CSV or JSON from the inbox, and forms export as JSON — no support ticket required.
  • · Deleted submissions sit in Trash for 30 days before purge, so an accidental delete is recoverable.

Sub-processors

The providers we rely on to run the service.

Supabase
Managed Postgres database, authentication and file storage (EU region).
Cloudflare
Application hosting, CDN and DDoS protection.
Resend
Transactional, notification and reminder email delivery.
Stripe
Subscription billing and card processing. Card details never reach our servers.
Google
Optional Google sign-in and, when you enable them, reCAPTCHA and Google Drive/Sheets delivery.

Reporting a vulnerability

Security reports are read by a human and answered.

  • · Email hello@helloforms.net with the affected URL, the steps to reproduce and what you were able to access.
  • · We aim to acknowledge within one business day, and we will tell you when the issue is fixed.
  • · Please do not run load tests, attempt to access other accounts' data, or publish details before we have responded.