Security & Trust
Formant Trust Center
At Formant, security isn’t just a feature—it’s foundational to everything we build. Our security-first mindset drives our development processes, infrastructure decisions, and organizational policies. We treat the data entrusted to us—whether from our customers, their end users, or anyone who interacts with our organization—with the utmost care and responsibility. Security is embedded in our DNA, enabling us to deliver innovative solutions without compromising on protection.
Compliance
Certifications & Compliance
We are working toward and maintain the following compliance standards and security practices to protect your data.
GDPR Compliant
We comply with the EU General Data Protection Regulation, ensuring the rights and privacy of all users in the European Union.
Annual Penetration Testing
We conduct regular third-party penetration testing to proactively identify and remediate security vulnerabilities.
CCPA Compliant
We honor California Consumer Privacy Act requirements, giving users control over their personal information.
How We Keep You Safe
Security Practices
Security is embedded in every layer of our platform—from the code we write to the infrastructure we operate.
Application Security
Our development lifecycle includes code reviews, static analysis, and secure coding practices. We conduct regular security assessments and promptly address vulnerabilities.
Infrastructure Security
We host our services on AWS with strict access controls, encryption at rest and in transit, regular audits, and continuous monitoring of all infrastructure components.
Data Security
All customer data is encrypted using AES-256 at rest and TLS 1.2+ in transit. We enforce strict data retention policies and provide customers full control over their data.
Organizational Security
Security awareness training is mandatory for all employees. We enforce least-privilege access, multi-factor authentication, and comprehensive background checks.
Controls
Security Controls
A snapshot of the controls in place across our infrastructure, organization, product, and internal procedures.
Infrastructure Security
Encryption key access restricted
Unique account authentication enforced
Production database access restricted
+ 8 more infrastructure security controls
Organizational Security
Asset disposal procedures utilized
Production inventory maintained
Anti-malware technology utilized
+ 7 more organizational security controls
Product Security
Control self-assessments conducted
Vulnerability and system monitoring procedures established
Data encryption utilized
+ 1 more product security control
Internal Security Procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
+ 28 more internal security procedure controls
Documentation
Security Resources
Privacy Policy
Learn how we collect, use, and protect your personal data.
Security Overview
Access our full trust center documentation and security reports.
Vulnerability Disclosure
Report security vulnerabilities responsibly to our team at security@formant.io.
Engagement Letter
Download our formal engagement letter for compliance and procurement purposes.
Security Team
Have a security question?
Our security team is here to answer your questions, review compliance requirements, or help you understand how Formant protects your data.