FormsByAir
Security

The safest place for your data is your systems — not ours.

The foundation of our approach to security: we don't keep form submission data. Submissions are held temporarily during validation, workflow and delivery, then permanently deleted subject to your configured Data Retention Period — the default is 10 days.

TLS 1.2+
HTTPS on every connection
AES-256
Encryption at rest, incl. tokens
99.95%
Monthly availability target
24/7
Independent uptime monitoring
Framework alignment

Structured around the NIST Cybersecurity Framework.

Our security programme is aligned with the NIST Cybersecurity Framework and informed by selected NIST SP 800-53 controls. Development follows OWASP guidance, and our independent penetration testing uses OWASP Top 10 methodology.

Identify

Documented architecture and data flows. Data minimisation limits what's at risk to in-flight submissions.

Protect

Encryption in transit and at rest, WAF, MFA and least-privilege access, and a secure development lifecycle.

Detect

24/7 external monitoring, telemetry and alerting, monthly vulnerability scanning, and malware scanning of uploads.

Respond

Documented incident response plan with severity classification and client notification within 12 hours of a confirmed incident.

Recover

Geo-redundant infrastructure, documented recovery runbooks and objectives, and post-incident reviews that feed back into controls.

Encryption

All connections to our website, API and forms use HTTPS with TLS 1.2. Form data is encrypted with AES-256 while temporarily held, and delivered to all services over HTTPS.

User passwords and access tokens for third-party services are encrypted with AES-256.

Access

Portal access requires a FormsByAir login, with 2FA and IP whitelisting supported. API access uses revocable bearer tokens that expire automatically after 3 years.

Our staff see metadata only by default — access to form data must be requested per issue and is logged. Production infrastructure is administered under least-privilege access with multi-factor authentication, and access is audited.

Web application firewall & DDoS

All traffic enters through Azure Front Door — a global edge network with a Web Application Firewall running OWASP-based managed rule sets.

DDoS attacks are absorbed at the edge, before they reach the application, with selective blocking of attacking traffic.

Hosting & data sovereignty

FormsByAir is hosted on Microsoft Azure. You can nominate your preferred Azure region for storing encrypted form data while it's temporarily held.

Supporting services include GoDaddy (domains/SSL), SendGrid and SMTP2GO (email), Pingdom and Atlassian (monitoring), and ClamAV (malware detection).

Availability

Infrastructure follows Azure best practice for high availability including global CDN endpoints. Production is monitored 24/7, every minute, from multiple geographic locations.

We target at least 99.95% availability every month. A public status page is available at status.formsbyair.com.

Independent testing

Independent web application penetration testing using OWASP Top 10 methodology, including authenticated testing and remediation retesting. Monthly external vulnerability scanning with Intruder. Reports available on request.

Our HTTPS configuration is independently rated A+, and our source code has passed an audit for CASA Tier 2 Certification.

Secure development

Every production change is code reviewed. We build on modern frameworks with protections built in — server-side validation, anti-forgery controls and secure session handling — following OWASP guidance, with dependencies updated regularly.

Post-deployment integrity checks verify behaviour after every release, and a public changelog is available at docs.formsbyair.com/changelog.

Incident response

A documented cyber incident response plan covers identification, containment, eradication, recovery and post-incident review, with defined severity classifications.

Affected clients are notified within 12 hours of a confirmed incident via status.formsbyair.com and direct email, followed by a detailed post-mortem.

Resilience & recovery

All components are configured with regional and geo redundancy, including database geo-replication with point-in-time restore. Recovery procedures are documented in step-by-step runbooks with defined recovery objectives, and regularly tested.

Our business continuity plan has no dependency on any physical office, and external service outages degrade gracefully — submissions continue and integrations resume without data loss.

GDPR & PCI

FormsByAir is compliant with data-processor obligations under GDPR and UK GDPR. For UK accounts, form data is temporarily held and processed in the UK and EU. Subprocessors include Cliniko and SMTP2GO.

FormsByAir is not PCI-compliant and does not store or transfer credit card information — payments are handled by PCI-compliant gateways.

Spam protection

We monitor for unusual patterns of activity against your forms and block access if thresholds are exceeded.

Malware scanning

All form attachments are scanned for malware immediately after submission. Infected files are quarantined and account administrators are automatically notified.

Questions from your compliance team? We speak their language.

Contact Sales →
FormsByAir

Smart digital forms, expert implementation and seamless integrations — for regulated businesses that need more than a basic form builder.

Product
How We Work Features Security Integrations Status
Legal
Terms of Service Privacy Policy
Contact
Contact Us Contact Sales Log In
© 2026 FormsByAir. "FormsByAir" is a trademark of Forms By Air Limited.
Made in New Zealand