Security at Formit AI
We take the security of your forms and your respondents' data seriously. Here's how the platform is built to protect it.
Practices
How we protect your data
Technical and organizational measures designed to keep your data safe.
Encryption & password hashing
All data is encrypted in transit with TLS. Data at rest is encrypted through our infrastructure providers. Passwords are hashed with argon2 — never stored in plain text.
Role-based access control
Organizations support four roles — Owner, Admin, Member, and Viewer — each with granular permissions for forms, submissions, settings, and team management.
Organization-level isolation
Multi-tenant architecture ensures each organization's data is logically isolated. Members of one organization cannot access another organization's forms or submissions.
Rate limiting & validation
Sensitive endpoints — including AI generation, authentication, and submission — are rate-limited server-side. All inputs are validated with strict schemas.
Session management
Short-lived access tokens with refresh rotation. Sessions are invalidated on sign-out and on account deletion. Email verification gates sensitive actions.
Responsible AI
AI prompts and form content sent to our LLM provider (OpenAI) are processed over encrypted connections. Respondent data is not used to train models. AI features are optional.
Data handling
Your data, your control
You own your content
You retain full rights to the forms you create and the submissions you collect. Formit processes your data only to provide the service.
Account deletion
You can delete your account from settings at any time (requires password verification and email confirmation). Primary data is permanently deleted after a 7-day recovery window. Backup copies are purged within 30 days.
No data selling
We do not sell personal data. We do not use respondent submission data for advertising. Integrations share data only when you explicitly enable them.
Legal & compliance
For full details on how we handle personal data, review our legal policies.
Questions about security?
Contact us at tahir@neurodek.com. We're happy to discuss our security practices in detail.
Start building — free