The foundation of our approach to security: we don't keep form submission data. Submissions are held temporarily during validation, workflow and delivery, then permanently deleted subject to your configured Data Retention Period — the default is 10 days.
Our security programme is aligned with the NIST Cybersecurity Framework and informed by selected NIST SP 800-53 controls. Development follows OWASP guidance, and our independent penetration testing uses OWASP Top 10 methodology.
Documented architecture and data flows. Data minimisation limits what's at risk to in-flight submissions.
Encryption in transit and at rest, WAF, MFA and least-privilege access, and a secure development lifecycle.
24/7 external monitoring, telemetry and alerting, monthly vulnerability scanning, and malware scanning of uploads.
Documented incident response plan with severity classification and client notification within 12 hours of a confirmed incident.
Geo-redundant infrastructure, documented recovery runbooks and objectives, and post-incident reviews that feed back into controls.
All connections to our website, API and forms use HTTPS with TLS 1.2. Form data is encrypted with AES-256 while temporarily held, and delivered to all services over HTTPS.
User passwords and access tokens for third-party services are encrypted with AES-256.
Portal access requires a FormsByAir login, with 2FA and IP whitelisting supported. API access uses revocable bearer tokens that expire automatically after 3 years.
Our staff see metadata only by default — access to form data must be requested per issue and is logged. Production infrastructure is administered under least-privilege access with multi-factor authentication, and access is audited.
All traffic enters through Azure Front Door — a global edge network with a Web Application Firewall running OWASP-based managed rule sets.
DDoS attacks are absorbed at the edge, before they reach the application, with selective blocking of attacking traffic.
FormsByAir is hosted on Microsoft Azure. You can nominate your preferred Azure region for storing encrypted form data while it's temporarily held.
Supporting services include GoDaddy (domains/SSL), SendGrid and SMTP2GO (email), Pingdom and Atlassian (monitoring), and ClamAV (malware detection).
Infrastructure follows Azure best practice for high availability including global CDN endpoints. Production is monitored 24/7, every minute, from multiple geographic locations.
We target at least 99.95% availability every month. A public status page is available at status.formsbyair.com.
Independent web application penetration testing using OWASP Top 10 methodology, including authenticated testing and remediation retesting. Monthly external vulnerability scanning with Intruder. Reports available on request.
Our HTTPS configuration is independently rated A+, and our source code has passed an audit for CASA Tier 2 Certification.
Every production change is code reviewed. We build on modern frameworks with protections built in — server-side validation, anti-forgery controls and secure session handling — following OWASP guidance, with dependencies updated regularly.
Post-deployment integrity checks verify behaviour after every release, and a public changelog is available at docs.formsbyair.com/changelog.
A documented cyber incident response plan covers identification, containment, eradication, recovery and post-incident review, with defined severity classifications.
Affected clients are notified within 12 hours of a confirmed incident via status.formsbyair.com and direct email, followed by a detailed post-mortem.
All components are configured with regional and geo redundancy, including database geo-replication with point-in-time restore. Recovery procedures are documented in step-by-step runbooks with defined recovery objectives, and regularly tested.
Our business continuity plan has no dependency on any physical office, and external service outages degrade gracefully — submissions continue and integrations resume without data loss.
FormsByAir is compliant with data-processor obligations under GDPR and UK GDPR. For UK accounts, form data is temporarily held and processed in the UK and EU. Subprocessors include Cliniko and SMTP2GO.
FormsByAir is not PCI-compliant and does not store or transfer credit card information — payments are handled by PCI-compliant gateways.
We monitor for unusual patterns of activity against your forms and block access if thresholds are exceeded.
All form attachments are scanned for malware immediately after submission. Infected files are quarantined and account administrators are automatically notified.
Smart digital forms, expert implementation and seamless integrations — for regulated businesses that need more than a basic form builder.