Form Builder Security & Compliance Guide
A form is a collection device pointed straight at your customers, which makes it the one tool that gathers personal data before any other system touches it — names, emails, payment details, sometimes health information on a medical intake. That puts security and compliance at the front of the buying decision, not the back. This is the plain-English guide to what the badges mean, what to verify before you embed a form, and which of the builders we rank document each protection.
Why this is the criterion buyers underweight
Most form-builder shopping is about templates, logic and how the form looks. Security feels handled — every vendor says "your data is safe" — so people embed the form and move on. That is the mistake. A form is the first point of collection, so a weak one leaks regulated data at the source, and a public form with no spam or access control is an open inbox for abuse. Security and compliance is one of the five weighted criteria in our methodology, and this guide is where we make it visible.
Hold onto one idea: compliance is shared. The vendor gives you a certified platform with encryption and the right contracts; you are responsible for what you ask for, who can see responses, how long you keep them, and how you honour a deletion request. Your job as a buyer is two-part — verify what the vendor genuinely provides, then configure your side properly. We take each in turn, defining every term as we go.
What to verify before you buy
SOC 2 is a report, common in the United States, where an independent firm checks that the security practices a vendor claims are real and working. Ask for the "Type II" report — it covers a stretch of months, not a single day, so it is far harder to stage. For a tool that receives your customers’ submissions, a vendor that cannot share one under an NDA is a warning.
ISO 27001 is a globally recognised certificate showing the vendor runs a formal, audited information-security system — policies, risk reviews, staff training. Where SOC 2 is the American reference point, ISO 27001 is the international one. The strongest form builders hold both; for one that stores submitted personal data, the absence of either is a real concern.
GDPR is the European data-protection law that applies the moment your form collects data on anyone in the EU or UK — which a public web form often does without you realising. The practical thing to get is a DPA, a Data Processing Agreement, where the vendor commits to process submissions lawfully, host them in the right region, and help with access and deletion requests. Confirm EU-region storage if your respondents are European, and turn off any data collection you do not need.
HIPAA is a US healthcare law covering PHI — Protected Health Information. If your form gathers any (a patient intake, an appointment request with symptoms), you need the vendor to sign a BAA, a Business Associate Agreement sharing legal responsibility for that data. This is the sharpest dividing line in form-builder compliance: most builders will only sign a BAA on a specific higher edition, and several will not sign one at all. Never embed a health-data form without a signed BAA for your exact plan.
Two basics belong on every shortlist. Encryption "in transit and at rest" means submissions are scrambled both while travelling from the form and while stored, so an intercepted response is gibberish. And if your form takes card payments, the vendor (or its payment partner) must be PCI-DSS compliant — never collect raw card numbers in plain form fields. Prefer a builder that tokenises payments through Stripe or PayPal rather than touching card data itself.
A form is exposed in two directions. Inbound: without CAPTCHA, rate limits or validation, a public form invites spam and injection abuse. Outbound: response data needs role-based access so not every team member can export the whole submission database. Look for granular permissions, audit visibility, encrypted file uploads, and spam protection you can configure — the unglamorous controls that prevent the most common incidents.
The compliance matrix
Here is where each of the seven builders in our form-builder ranking stands on the certificates and contracts that matter, as documented in mid-2026. Read the HIPAA column especially carefully: a tick means a BAA is available (usually on a higher edition), a tilde means only on a specific plan, on request, or not clearly published, and a dash means no BAA — so it must not collect patient health data. Forms gather data directly, so confirm the current position in writing for your exact plan.
✓ documented · ∼ on a specific edition, on request, or not clearly published · — not offered. Verified July 2026 from vendor trust documentation where available; because forms collect regulated data at the source, confirm the exact plan in writing before relying on it.
What to look for, and what to walk away from
Both are independent proofs that the vendor takes security seriously. SOC 2 is an audit report, mostly used in the United States, where an outside firm checks that the controls a vendor claims are actually in place — ask for the Type II report, which covers months rather than a single day. ISO 27001 is an international certificate showing the vendor runs a formal information-security management system. For a tool that receives your customers’ submissions, seeing both is reassuring; seeing neither is a red flag.
As of mid-2026, Jotform offers a BAA and HIPAA features on its higher (Gold/Enterprise) editions, and Cognito Forms offers one on its Enterprise plan. Google Forms can be covered only under a Google Workspace BAA for eligible customers, and SurveyMonkey and Typeform offer HIPAA support on specific plans or by request. Tally and Paperform do not position for PHI. Editions and policies change, so confirm the BAA in writing for your exact plan before collecting any patient data.
Yes, if the form tokenises payments through a PCI-DSS compliant processor such as Stripe or PayPal rather than collecting raw card numbers in form fields. The card data then never touches the form builder in plain text, which is both safer and removes most of your PCI burden. Avoid any setup that asks respondents to type a full card number into an ordinary text field — that is the configuration that creates liability.
No, and this is the most expensive misunderstanding. Compliance is shared. The vendor provides the certified platform, encryption, a DPA and region storage; you are responsible for what you collect, who can see responses, how long you keep them, how you capture consent, and how you handle deletion requests. A compliant form builder configured carelessly — collecting more than you need, with everyone able to export responses — is still a breach waiting to happen.
One email when the rankings move. The shortlist, the tradeoffs, the compliance changes. No filler.