FormBridge holds the kind of data that, if exposed, blows up a company — founder passports, bank account numbers, tax returns, equity records. We architect like that's true from day one.
SOC 2 Type II — on the path. Type I audit planned within six months of commercial launch; Type II audit window begins after. Pre-audit controls and policies already in place.
GDPR — applicable given our UK and EU-origin customers. Privacy Policy + DPA reviewed by counsel before public launch.
ISO 27001 — evaluated post-launch based on enterprise-customer demand.
Think you've found a security issue? Email security@formbridge.co. We respond within one business day. Please don't publicly disclose until we've had a chance to fix it and notify affected customers. We credit responsible reports and handle legitimate findings seriously.