Security & Trust

Formant Trust Center

At Formant, security isn’t just a feature—it’s foundational to everything we build. Our security-first mindset drives our development processes, infrastructure decisions, and organizational policies. We treat the data entrusted to us—whether from our customers, their end users, or anyone who interacts with our organization—with the utmost care and responsibility. Security is embedded in our DNA, enabling us to deliver innovative solutions without compromising on protection.

Compliance

Certifications & Compliance

We are working toward and maintain the following compliance standards and security practices to protect your data.

GDPR Compliant

We comply with the EU General Data Protection Regulation, ensuring the rights and privacy of all users in the European Union.

Annual Penetration Testing

We conduct regular third-party penetration testing to proactively identify and remediate security vulnerabilities.

CCPA Compliant

We honor California Consumer Privacy Act requirements, giving users control over their personal information.

How We Keep You Safe

Security Practices

Security is embedded in every layer of our platform—from the code we write to the infrastructure we operate.

Application Security

Our development lifecycle includes code reviews, static analysis, and secure coding practices. We conduct regular security assessments and promptly address vulnerabilities.

Infrastructure Security

We host our services on AWS with strict access controls, encryption at rest and in transit, regular audits, and continuous monitoring of all infrastructure components.

Data Security

All customer data is encrypted using AES-256 at rest and TLS 1.2+ in transit. We enforce strict data retention policies and provide customers full control over their data.

Organizational Security

Security awareness training is mandatory for all employees. We enforce least-privilege access, multi-factor authentication, and comprehensive background checks.

Controls

Security Controls

A snapshot of the controls in place across our infrastructure, organization, product, and internal procedures.

Infrastructure Security

Encryption key access restricted

Unique account authentication enforced

Production database access restricted

+ 8 more infrastructure security controls

Organizational Security

Asset disposal procedures utilized

Production inventory maintained

Anti-malware technology utilized

+ 7 more organizational security controls

Product Security

Control self-assessments conducted

Vulnerability and system monitoring procedures established

Data encryption utilized

+ 1 more product security control

Internal Security Procedures

Continuity and Disaster Recovery plans established

Continuity and Disaster Recovery plans tested

Configuration management system established

+ 28 more internal security procedure controls

Security Team

Have a security question?

Our security team is here to answer your questions, review compliance requirements, or help you understand how Formant protects your data.