Every security feature enterprises need — included on all paid plans. No $500/mo enterprise tier required.
Multiple authentication methods to match your organization's security requirements.
Secure, one-time-use email links. No passwords to steal, phish, or forget.
FIDO2/WebAuthn hardware and biometric authentication. Phishing-resistant by design.
TOTP-based MFA with any authenticator app. Recovery codes included.
Enterprise single sign-on with any SAML 2.0 identity provider. Okta, Azure AD, OneLogin, and more.
Configurable session timeouts, idle expiration, device tracking, and remote session revocation.
Your data is encrypted at every layer — at rest, in transit, and in backups.
All data encrypted with AES-256 encryption. Zero-access architecture.
All connections encrypted with TLS 1.3. HSTS enforced. No fallback to older protocols.
Automated backups encrypted with the same AES-256 standard. Point-in-time recovery available.
Every customer gets their own isolated infrastructure. Your data never touches another customer's.
Separate compute, separate processes. No shared runtimes, no noisy neighbors.
Separate database per customer, separate database per form. Physical data isolation, not just logical.
Choose from 42 global regions. Your data stays in your selected region. Full sovereignty.
Control who can access what, down to individual forms and actions.
Scoped API keys with prefix-based identification. Rotate, expire, and revoke anytime.
Machine-to-machine authentication with fine-grained permission scopes.
Admin, member, and viewer roles with form-level and folder-level grants.
The controls regulated teams need — without buying an enterprise plan.
Full EU data protection compliance. Data residency in 12 European regions. Right to erasure, data portability, and consent management.
Health data protection with enforced audit retention (6+ years), mandatory access logging, and encrypted PHI storage. The technical safeguards are in place today; formal attestation and business associate agreements are on our roadmap.
Security and availability controls with comprehensive audit trails, access monitoring, and 1+ year log retention. Our SOC 2 audit is planned — no report has been issued yet.
Every action tracked, every access logged. Full visibility into who did what, when.
Every login, data access, permission change, and admin action recorded with timestamps, IPs, and user agents.
Set your own retention policies. Compliance presets automatically enforce minimum retention periods.
Export complete audit history for external SIEM integration or compliance reporting.
Multiple layers of protection at the network and application level.
Automatic rate limiting on authentication endpoints. Brute-force attacks blocked before they start.
HSTS, X-Content-Type-Options, X-Frame-Options enforced on every response. Industry best practices by default.
SameSite cookies, content type validation, and strict output encoding. Defense at every layer.
Every feature on this page is included on all paid plans. No enterprise tier. No add-ons. No surprises.