Security & trust

Your form data, handled properly.

Form submissions are other people's personal data in your care. Here's exactly how FormWire stores, protects, and hands back every byte of it.

In practice

Six commitments you can hold us to.

Encrypted in transit

Every submission travels over HTTPS/TLS. The endpoint doesn't accept plaintext connections.

Encrypted at rest

Stored submissions are encrypted by our infrastructure providers before they touch disk.

Verified recipients only

The public access key in your HTML can only deliver to inboxes you've confirmed, so it can't be abused as an open relay.

Spam quarantined, not delivered

Honeypot and rate-limit catches are stored in a separate tab, never emailed, never counted against you.

Export or delete, any time

CSV export and the read API on every tier; deletion is permanent and honored on request, per GDPR and CCPA.

Never sold, never shared

Submission data isn't sold, rented, or shared. It exists to reach your inbox and your dashboard — nothing else.

Security questions

The ones that come up in vendor reviews and DPA conversations.

Questions?

Talk to the person who built it.

Security reviews, DPA questions, or anything this page didn't answer. Replies come from the engineer.