Trust.

Security at Forma

Last updated: July 13, 2026

People bring their most important arguments to Forma — board decks, budgets, strategy. Protecting that work is foundational. This page describes how we secure the Forma application, your account and your content, and how to reach our security team.

At a glance

1 Infrastructure & hosting

Forma runs on established cloud infrastructure providers ([e.g. AWS / GCP]) whose data centers maintain independent certifications such as ISO 27001 and SOC 2. Production environments are logically separated from development and staging. Infrastructure is provisioned as code and network access is restricted through security groups, private networking and firewalls.

2 Encryption

3 Access control

Internal access to production systems follows the principle of least privilege. Employee access requires single sign-on with multi-factor authentication, is scoped by role, is reviewed periodically, and is revoked promptly on role change or departure. Access to Customer Content is limited to the minimum necessary to operate the Services or provide support you request, and such access is logged.

4 Tenant isolation

Forma is a multi-tenant service. Each workspace's data is logically isolated and access is enforced at the application layer by authorization checks tied to your account and workspace, so one customer cannot access another's content.

5 Application security

6 Secure development

Changes go through version control, peer code review and automated testing before release. We use automated dependency scanning and static analysis in our pipelines, and keep dependencies patched. Production deploys are automated and auditable, with the ability to roll back.

7 Logging & monitoring

We centrally collect application, infrastructure and security logs, monitor for anomalies and errors, and alert on-call engineers to potential issues. Logs are retained for a defined period to support investigation while minimizing the personal data they contain.

8 Backups & resilience

Customer data is backed up automatically on a regular schedule, with backups encrypted and retention managed on a rolling basis. Our architecture uses redundancy across availability zones to reduce the impact of component failures. We maintain business-continuity and disaster-recovery plans with target objectives of [RPO / RTO], which we test periodically.

9 Vulnerability management

We scan our systems and dependencies for vulnerabilities, prioritize remediation by severity, and engage independent testers for periodic penetration tests. Findings are tracked to resolution. Summary reports may be available to enterprise customers under NDA.

10 AI & data handling

When you use AI features, prompts and the relevant content are sent to model providers solely to return a result to you. We contractually require these providers not to train their models on content submitted through our accounts, and we do not use your Customer Content to train foundational models unless you opt in. See our Privacy Policy for how we handle personal information.

11 People & vendors

Employees and contractors agree to confidentiality obligations, complete security-awareness training, and receive access appropriate to their role. We assess the security of vendors and sub-processors before granting them access to data and bind them by data-processing agreements. Company devices are managed with disk encryption, screen locks and endpoint protection.

12 Compliance & certifications

We build to recognized frameworks and support customer compliance obligations. A SOC 2 Type II examination is [in progress / planned], and we offer a Data Processing Addendum incorporating the EU Standard Contractual Clauses for customers who need one. Request our current DPA, sub-processor list or security documentation at security@forma.page.

13 Incident response

We maintain an incident-response plan covering detection, triage, containment, eradication and recovery. If a security incident affects your data, we will investigate, take remediation steps and notify affected customers without undue delay and consistent with applicable law and our contractual commitments.

14 Report a vulnerability

We welcome reports from the security community. If you believe you have found a vulnerability, email security@forma.page with details and steps to reproduce. Please act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure. We will not pursue legal action against researchers who follow this policy.