Security Features
Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Authentication
Secure password hashing with bcrypt. Support for OAuth providers.
Infrastructure
Hosted on enterprise-grade infrastructure with regular security audits.
Access Control
Role-based permissions and workspace isolation.
Compliance
- GDPR compliant
- CCPA compliant
- SOC 2 Type II (in progress)
- Regular penetration testing
- Vulnerability disclosure program
Report a Security Issue
If you've discovered a security vulnerability, please report it responsibly through our contact form. We appreciate your help in keeping Forma secure.
Report Vulnerability