Formality · Trust Center
Formality Trust Center
Trust center
Formality maintains a public trust center documenting SOC 2 Type II, ISO 27001, and GDPR compliance.
CompanyAi MlLegalContract ManagementDocument-ManagementAsset IntelligenceComplianceSoftware-as-a-Service
Trust center: https://www.formality.com/en/index.html#security
Certifications & Compliance
SOC 2 Type IIISO 27001GDPR
Source
Trust Center
generated: '2026-08-17'
method: searched
probe: true
source: https://www.formality.com/en/index.html#security
url: https://www.formality.com/en/index.html#security
certifications:
- SOC 2 Type II
- ISO 27001
- GDPR
security_controls_published:
- {control: access control, detail: 'Granular access control, complete audit trail.'}
- {control: hosting sovereignty, detail: 'Data stored in Europe or in France (Scaleway).'}
- {control: AI training exclusion, detail: 'Never trained on your data. Agents operate within a secured perimeter, fully auditable.'}
- {control: encryption, detail: 'AES-256 at rest, TLS 1.3 in transit.'}
- {control: reversibility, detail: 'Full export at any time, no lock-in, no opacity.'}
- {control: SSO enforcement, detail: 'Workspace toggle forcing Google/Microsoft SSO and terminating non-SSO sessions.',
source: https://help.formality.com/setup-permissions/user-management}
- {control: document-access webhook, detail: 'HMAC-SHA256-signed notifications on document view, download, bulk download and signature.',
source: https://help.formality.com/setup-permissions/user-management}
- {control: allowed email domains, detail: 'Admins restrict which email domains may be invited.',
source: https://help.formality.com/setup-permissions/user-management}
- {control: audit trail, detail: 'Audit trail plus per-object change history; deactivated users retain history.',
source: https://help.formality.com/setup-permissions/changes-audit-trail}
commitments:
- {name: One Clause, detail: 'Signatory of One Clause.'}
trust_portal:
exists: false
subdomain_probed: [trust.formality.com, security.formality.com]
note: >-
No dedicated trust portal and no automated evidence-sharing centre. Certification
claims are prose on the marketing site; no certificate numbers, auditor names,
audit scope, report dates or NDA-gated report request flow are published, and the
SOC 2 report is not obtainable from any public surface.
url_correction:
previous_url: https://www.formality.com/en/security
previous_status: 403
checked: '2026-08-17'
note: >-
DEFECT FIXED THIS ROUND. The 2026-07-19 pass recorded
https://www.formality.com/en/security as the source, and both the Compliance and
TrustCenter pointers in apis.yml targeted it. That URL now returns HTTP 403 from the
S3/CloudFront origin — the standalone security page no longer exists after the site
was rebuilt on Framer, and the same is true of the old PrivacyPolicy pointer
(/policies/personal-data-protection-policy/, also 403). The certification and
security content now lives in the "Security & sovereignty" section anchored at
/en/index.html#security. apis.yml pointers were repointed accordingly.
notes: >-
Formality publishes a substantive security posture for a company of its size —
ISO 27001 and SOC 2 Type II claimed and renewed annually, EU/France data residency
with a named infrastructure partner (Scaleway), AES-256 at rest, TLS 1.3 in transit,
contractual prohibition on AI vendors training on customer data, full export
reversibility, and real tenant-level controls (enforced SSO, email-domain
allowlisting, HMAC-signed document-access webhooks, audit trail).
The weakness is verifiability rather than substance: everything is self-declared prose
with no trust portal, no certificate identifiers and no path to the underlying
reports. Live probing also surfaced a regression the marketing copy does not mention —
the www origin now serves NO HSTS header, and the registrable domain still has no
DNSSEC, no CAA records and DMARC at p=none. Those are recorded in
security/formality-domain-security.yml.
evidence:
- source: https://www.formality.com/en/index.html
http_status: 200
fetched: '2026-08-17'
keywords: [iso 27001, soc 2 type ii, aes-256, tls 1.3, scaleway, one clause, audit trail]
- source: https://www.formality.com/en/security
http_status: 403
fetched: '2026-08-17'
note: previous round's source URL, now dead
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/formality-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.