Your form data, protected at every layer.
At Cognito Forms, we’re concerned about your privacy and the security of your form data. Here are the measures we take to keep it safe, from the infrastructure up to every field on your forms.
Infrastructure & Encryption
- Cognito Forms uses TLS 1.2+ encryption and is always accessed over HTTPS 100% of the time for all users.
- Cognito Forms is hosted securely on the Microsoft Azure cloud platform, which is PCI (DSS) Level 1 and HIPAA compliant. We also have a HIPAA BAA with Microsoft.
- Cognito Forms uses opportunistic TLS encryption when sending email to always encrypt messages when supported by downstream servers. For HIPAA organizations, we recommend that PHI be marked as protected so it is not sent via email for any reason and remind organizations that explicit patient consent is required for sending PHI via email.
Application Security
- The Cognito Forms architecture is unique and highly specialized for massive scale while maintaining data isolation. It does not use transactional databases and is not vulnerable to SQL injection attacks.
- All text data stored by Cognito Forms is sanitized to prevent JavaScript injection attacks, which someone might attempt to leverage by submitting JavaScript as entry data to maliciously access other entry data by compromising our customers browsers when managing entries.
- Production access credentials for storage and encryption tokens used to encrypt sensitive organization data are stored in an Azure credential store and are not stored within our own development environments.
Account Security & Oversight
- Cognito Forms customers can enable two-factor authentication (2FA) to add a second login step to their account. Additionally, organizations on the Enterprise plan level can require two-factor authentication for all users.
- Cognito Forms has completed a SOC 2 Type II audit, and can provide this documentation after a Security NDA is signed.
Access & Data Isolation
- Access to our production environment is limited to select operations security staff, requiring two-factor authentication to deploy updates or access a secure system for limited troubleshooting.
- We do not look at entry data for our customers unless requested to through an official support request. The details of our concern over data privacy are detailed in our Privacy Policy.
- Customer data is carefully segregated at the lowest architectural level in Cognito Forms to ensure that data for one organization cannot be accessed by another.
Sensitive Data & Payments
- Sensitive data, such as Social Security numbers and other personally identifiable information, is required to be encrypted at rest using 256-bit AES encryption. It must also be protected so that it is never emailed or otherwise transmitted in an insecure way. Any field type can be encrypted and/or protected, including uploaded files and sections.
- We partner with PayPal, Stripe, and Square for credit card processing so that secure payment information is never transmitted or stored by Cognito Forms. We also take measures to prevent malicious scripts on sites we are embedded in from stealing this information.
- Cognito Forms is HIPAA compliant, and offers a business associate agreement for organizations seeking to securely communicate with patients via registration forms, appointment scheduling, refill requests, etc.
Privacy & Compliance
GDPR
Cognito Forms complies with all General Data Protection Regulation (GDPR) regulations to ensure we provide our customers in the EU with access to and control of their personal data. Additionally, we make it possible for our users to create GDPR-compliant forms for doing business with customers in the EU. To ensure your forms can be used by customers in the EU, read this article on how to build GDPR-compliant forms.
Data Privacy Framework
Cognito Forms is a certified member of the EU-U.S., Swiss-U.S. and UK-Extension to the EU-US Data Privacy Frameworks. As such, we comply with all Framework requirements. This helps ensure proper data protection measures are in place for our customers who engage in transatlantic commerce.
CCPA
The California Consumer Privacy Act (CCPA) provides California residents similar rights and protections as those provided in the EU by GDPR. Cognito Forms complies with all CCPA regulations, while making it easy for users to respond to data portability and access requests as well as data deletion requests.
We know that there are evolving threats to data security, and we will continue to refine our processes to ensure the safety of our customers’ data in Cognito Forms.