End-to-end encryption
All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups are encrypted too, in geographically distributed locations.
SECURITY — ALL SYSTEMS SECURE
Your data is protected by industry-leading practices and infrastructure — encrypted, audited, and monitored around the clock. The most uneventful page on this site, on purpose.
THE PRACTICES
All data encrypted with AES-256 at rest and TLS 1.3 in transit. Backups are encrypted too, in geographically distributed locations.
OAuth 2.0 and SAML SSO, two-factor authentication, and hardware-key support for the truly careful.
Hosted on SOC 2 Type II certified cloud infrastructure with regular security audits and penetration testing.
Role-based permissions with granular workspace controls — people see exactly what their role needs, nothing more.
Complete activity logs for compliance and forensics. Every meaningful action leaves a verifiable trail.
A 24/7 security operations watch with automated threat detection and established response protocols.
COMPLIANCE
VENDORS HANDLING CUSTOMER DATA MUST HOLD SOC 2 OR EQUIVALENT · PEN-TESTED REGULARLY
RESPONSIBLE DISCLOSURE
We respond to verified vulnerability reports within 48 hours and credit researchers who help keep Formilist calm — and safe.