Private beta Request access

Enterprise security. Standard pricing.

Every security feature enterprises need — included on all paid plans. No $500/mo enterprise tier required.

Authentication that protects

Multiple authentication methods to match your organization's security requirements.

Passwordless magic links

Secure, one-time-use email links. No passwords to steal, phish, or forget.

user@company.com
mlk_a1b2c3d4...
Authenticated

Passkeys

FIDO2/WebAuthn hardware and biometric authentication. Phishing-resistant by design.

FIDO2 / WebAuthn

Two-factor authentication

TOTP-based MFA with any authenticator app. Recovery codes included.

4
8
2
9
1
7

SAML SSO

Enterprise single sign-on with any SAML 2.0 identity provider. Okta, Azure AD, OneLogin, and more.

OktaAzure ADOneLoginGoogle

Session management

Configurable session timeouts, idle expiration, device tracking, and remote session revocation.

Chrome · macOS active
Safari · iPhone idle

Encryption everywhere

Your data is encrypted at every layer — at rest, in transit, and in backups.

AES-256 at rest

All data encrypted with AES-256 encryption. Zero-access architecture.

TLS 1.3 in transit

All connections encrypted with TLS 1.3. HSTS enforced. No fallback to older protocols.

Encrypted backups

Automated backups encrypted with the same AES-256 standard. Point-in-time recovery available.

Isolated by design

Every customer gets their own isolated infrastructure. Your data never touches another customer's.

Dedicated instances

Separate compute, separate processes. No shared runtimes, no noisy neighbors.

Isolated databases

Separate database per customer, separate database per form. Physical data isolation, not just logical.

Data residency

Choose from 42 global regions. Your data stays in your selected region. Full sovereignty.

Granular access control

Control who can access what, down to individual forms and actions.

API keys

Scoped API keys with prefix-based identification. Rotate, expire, and revoke anytime.

xf_a1b2c3d4e5f6...

Service accounts

Machine-to-machine authentication with fine-grained permission scopes.

xfs_7g8h9i0j...

Role-based permissions

Admin, member, and viewer roles with form-level and folder-level grants.

Admin Member Viewer

Compliance-ready by design

The controls regulated teams need — without buying an enterprise plan.

GDPR

Full EU data protection compliance. Data residency in 12 European regions. Right to erasure, data portability, and consent management.

All paid plans

HIPAA-ready

Health data protection with enforced audit retention (6+ years), mandatory access logging, and encrypted PHI storage. The technical safeguards are in place today; formal attestation and business associate agreements are on our roadmap.

All paid plans

SOC 2 aligned

Security and availability controls with comprehensive audit trails, access monitoring, and 1+ year log retention. Our SOC 2 audit is planned — no report has been issued yet.

All paid plans

Complete audit trail

Every action tracked, every access logged. Full visibility into who did what, when.

Comprehensive audit logs

Every login, data access, permission change, and admin action recorded with timestamps, IPs, and user agents.

Configurable retention

Set your own retention policies. Compliance presets automatically enforce minimum retention periods.

Audit log export

Export complete audit history for external SIEM integration or compliance reporting.

Defense in depth

Multiple layers of protection at the network and application level.

Rate limiting

Automatic rate limiting on authentication endpoints. Brute-force attacks blocked before they start.

Security headers

HSTS, X-Content-Type-Options, X-Frame-Options enforced on every response. Industry best practices by default.

CSRF & XSS protection

SameSite cookies, content type validation, and strict output encoding. Defense at every layer.

Security shouldn't cost extra

Every feature on this page is included on all paid plans. No enterprise tier. No add-ons. No surprises.