New
Introducing Smart Templates — pre-built forms for every use case.Learn more →

Security

Your data, protected.

Enterprise-grade security built into every plan. CAPTCHA protection, TLS encryption, hashed IPs, and private file storage — all by default.

Security you can measure.

TLS 1.2+

Encryption standard

0

Raw IPs stored

SOC 2

Compliance target

100%

Server-side enforcement

Built-in, not bolted on.

Security isn’t an add-on. It’s the foundation of everything we build.

TLS encryption

All data encrypted in transit using TLS 1.2 or greater. Your respondents’ data is protected from the moment they start typing.

CAPTCHA protection

Every form is protected against bots and spam automatically. No configuration needed.

Privacy by design

IP addresses are hashed before storage. Raw IPs are never persisted. We collect only what’s needed.

Private file storage

All uploaded files are stored in private buckets with no public URLs. Files are only accessible through authenticated API calls.

Server-side enforcement

Every plan limit, permission, and access control is enforced server-side on every API call. Client-side gating is cosmetic only.

No data training

Your form data is never used to train AI models or shared with third parties for any purpose.

Private file storage

All uploaded files are stored in private buckets with no public URLs. Files are only accessible through authenticated API calls, ensuring no accidental data exposure.

report.pdf
avatar.png
data.csv
backup.zip

Server-side enforcement

Every plan limit, permission, and access control is enforced server-side on every API call. Client-side gating is cosmetic only — the real security happens on our servers.

API Request Pipeline
Auth verified
Plan limits checked
Rate limited
Input sanitized

[Placeholder] A testimonial about security and data protection will go here.

[Name], [Role]

Enterprise-grade compliance.

Trusted by teams worldwide with enterprise-grade protections built in.

No training on your data

Your form data is never used to train AI models or shared with third parties.

Data retention controls

Delete responses anytime. Enterprise plans get configurable retention windows.

Built-in safeguards

Server-side enforcement of all plan limits and permissions keeps your data secure.

Consent disclosures

Clear in-product reminders to obtain consent before collecting data.

Secure encryption

All data encrypted in transit using TLS 1.2 or greater.

SOC 2 (Type 2)

We are working towards SOC 2 Type 2 certification. Our security practices follow SOC 2 standards.

Security teams love NodumForms.

Hear from organisations that trust us with their data.

[Placeholder] A testimonial about security and data protection will go here.

[Name], [Role]

[Placeholder] A testimonial about security and data protection will go here.

[Name], [Role]

[Placeholder] A testimonial about security and data protection will go here.

[Name], [Role]

Questions & Answers

Yes. All data is encrypted in transit using TLS 1.2 or greater. File uploads are stored in private, encrypted buckets.

IP addresses are hashed before storage. Raw IP addresses are never persisted in our systems.

No. Your form data is never used to train AI models or shared with third parties for any purpose.

We are working towards SOC 2 Type 2 certification. Our security practices already follow SOC 2 standards.

Every form includes CAPTCHA protection automatically. No configuration needed. Spam submissions are filtered before they reach your dashboard.