SECURITY

Seriously Secure Data Collection, Built for the AI Era

Security that scales with your data strategy

Security certifications

FormAssembly Atlas features a unique combination of secure features and certified operational standards helps organizations reduce risk, protect privacy, and safeguard their business and customers.

Sensitive data processing

Atlas is built to support the most rigorous compliance and regulatory requirements. Whether you’re handling PHI, meeting data localization rules, or ensuring global compliance, Atlas is ready.

Trusted infrastructure

Powered by enterprise-grade architecture and hosted on AWS, FormAssembly Atlas gives you high-performance scalability and a security-first foundation.

Documentation you can trust

Everything you need to know about FormAssembly’s security, privacy, and compliance practices.

Frequently Asked Questions

Why should I be concerned about secure data collection?

The FBI’s Internet Crime Report shows increases in ransomware attacks and phishing and losses totaling $10.3 billion in 2022*. That represents a 49% increase over the previous year. An incomplete security stance can leave your organization, and your customer’s data at risk of data breach and malware attacks.

Securing your data isn’t only about avoiding financial costs and fines, it’s about gaining and maintaining customer trust. Protecting respondent data from the moment of collection is good practice for your organization and the audiences you serve.

*Source: https://www.ic3.gov/Media/PDF/AnnualReport/2022_IC3Report.pdf

Can I control where my data is stored? 

This is a good question to ask any data collection provider. With select FormAssembly plans, you have your choice of 7 AWS regions around the world, hosting your data and backups securely.

If your organization does business globally, you may be impacted by regional data laws and regulations. We can help you manage your data localization requirements so you can scale.

Download Data Residency Checklist

What compliances does FormAssembly follow?

FormAssembly is PCI DSS Level 1 Certified and is compliant with GDPR, HIPAA, FERPA, the Australian Federal Privacy Act and Australian Privacy Principles. Our E-Signature feature is also compliant with the Australian Electronic Transactions Act. Our Government plan is FedRAMP Ready. 

Our policies, procedures, and standards reference best practices of: ISO, FFIEC, GLBA, HIPAA, PCI DSS, NIST, NYDFS, Privacy Act 1988

View Trust Center

Where can I learn more and request security documentation?

You can request and view FormAssembly’s security and compliance documentation in our dedicated trust center. 

Visit Trust Center

Security resources

secure form solution practices

Digital Data Collection & Security

data collection security checklist

Data Collection Security Checklist

Where in the World Is Your Data?