Formboost · Trust Center

Formboost Trust Center

Trust center

Formboost maintains a public trust center covering its security and compliance posture.

formsform-backendhtml-formsserverlessstatic-sitesreactnextjsvuewebhooksno-codedeveloper-toolsspam-filtering
Trust center: https://formboost.app/security

Certifications & Compliance

Source

Trust Center

formboost-trust-center.yml Raw ↑
generated: '2026-09-02'
method: searched
source: https://formboost.app/security
url: https://formboost.app/security
trust_center_published: true
trust_center_note: >-
  Formboost has no separate trust.* subdomain or certification portal. It publishes a single
  security-and-data-protection page that does the job of one: what is stored, who processes it,
  how it is protected, retention, GDPR rights, and how to report a vulnerability.
certifications: []
certifications_note: >-
  ZERO third-party certifications, stated by the provider in its own words:
  "We hold no third-party certifications — no SOC 2 report, no ISO 27001, no independent
  penetration test to share yet. Anyone claiming otherwise about us is wrong."
  It goes further: "If your organisation requires a certified processor today, we are not the
  right fit yet, and we would rather say so than lose your trust later."
correction_note: >-
  CORRECTED 2026-09-02. An earlier automated pass (probe-security-programs.py) keyword-matched
  the strings "SOC 2" and "ISO 27001" on this page and recorded both as certifications HELD.
  The page says the exact opposite — the keywords appear inside an explicit disclaimer. The
  false entries were removed by hand. This is a negation false-positive in the probe script, not
  a provider claim, and no Compliance pointer is emitted for SOC 2 or ISO 27001.
compliance_programs:
  - name: GDPR
    status: self-declared
    detail: >-
      Genuinely documented rather than merely asserted. The page sets out the controller/processor
      split (customer is controller of submissions, Formboost is processor), names the data
      subjects, enumerates every subprocessor with what it can see, describes how to exercise
      access/portability/erasure, and offers a data processing agreement on request.
    dpa_available: true
    dpa_route: email request
    source: https://formboost.app/security
data_handling:
  sells_data: false
  sells_data_statement: >-
    "Submissions are not sold, rented, brokered, or used for advertising or profiling. Formboost
    makes money from subscriptions, not from your data."
  stored:
    - category: Submission content
      detail: Whatever fields the form posts, stored as JSON exactly as submitted.
    - category: Submission metadata
      detail: Timestamp, spam score, read state, and the form it belongs to.
    - category: Account data
      detail: Email address, and a bcrypt-hashed password or a Firebase identity.
    - category: Integration config
      detail: Destination URLs and any custom headers, used to deliver submissions.
    - category: Billing records
      detail: Subscription and payment references. Card details are handled by Razorpay only.
  tracking_on_customer_forms: false
  tracking_note: >-
    "We do not run trackers or fingerprinting on the forms you host."
subprocessors:
  published: true
  commitment: >-
    "We do not add a subprocessor that touches submission content without updating this list."
  list:
    - name: Google (Gemini API)
      purpose: Spam screening
      sees: Submission content, on plans with AI screening active
    - name: Google (Firebase)
      purpose: Sign-in
      sees: Account email and authentication identifiers
    - name: Razorpay
      purpose: Payments and subscriptions
      sees: Billing identifiers and payment details entered with them
    - name: Email delivery provider
      purpose: Notification emails
      sees: Recipient address and submission contents in the notification
      note: Not named on the page.
    - name: Tawk.to
      purpose: Support chat on formboost.app
      sees: Chat contents, only after optional cookies are accepted
    - name: Google Analytics
      purpose: Website analytics
      sees: Usage data on formboost.app only — never submission data, and only after consent
controls:
  transport: TLS on every endpoint, terminated at the edge; Helmet security headers on API responses.
  transport_verified: >-
    TLSv1.3, HSTS max-age=15552000 includeSubDomains preload, restrictive CSP — probed 2026-09-02.
  authentication: Signed JWTs for dashboard access; email verification required before the API accepts requests.
  endpoint_hardening: Per-IP rate limiting, oversized-body rejection, spam screening before storage.
  webhook_ssrf_control: >-
    Destinations must be public HTTPS URLs; private and loopback addresses are rejected,
    "which prevents Formboost being used to reach internal networks."
retention:
  automatic_expiry: false
  detail: >-
    "Submissions are kept until you delete them. There is no automatic expiry today, so data
    minimisation is in your hands." Formboost explicitly declines to imply a retention schedule
    it does not enforce; scheduled retention is on the roadmap.
  customer_controls:
    - Export any form's submissions as CSV
    - Delete individual submissions
    - Delete a form (deletes its submissions)
    - Delete the account (removes everything)
  source: https://formboost.app/security
assessment: >-
  A young product with no audited assurance, but with unusually honest disclosure. There is no
  certification to point a procurement team at; there IS a complete, specific and self-critical
  account of what happens to the data. Buyers requiring a certified processor should read the
  provider's own advice and look elsewhere for now.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/formboost-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.