Regulated data is collected on a tier that was never scoped for it
Protected health information arriving through a form on a plan whose HIPAA controls were never enabled, often because the plan was bought before the use case existed.
FormAssembly publishes SOC 2 Type II results, PCI DSS compliance and a FedRAMP High-Impact environment. None of that is evidence about your instance. Twopir Consulting configures the part an auditor actually examines: plan tier against obligation, respondent authentication, masking, retention, permissions, and where connectors send regulated fields. Their certification. Your configuration. Different responsibilities.
Trusted by 500+ organizations — including healthcare, higher education, nonprofit and financial services teams collecting data a regulator takes an interest in.










Built for Regulated Data Collection
Every one of these can exist in an instance running on a SOC 2 audited, PCI compliant platform with every certificate in order. The certificate describes the vendor's controls. The finding is about yours.
Protected health information arriving through a form on a plan whose HIPAA controls were never enabled, often because the plan was bought before the use case existed.
A form holding sensitive data is technically public — anyone with the link can open it. The link is in an email, a browser history and a support ticket somewhere.
The mapping was built to send everything because that was quickest. Health or financial data is now in a marketing platform whose controls were never assessed for it.
Responses from six years ago sitting in an instance whose retention policy exists only as a paragraph in a document. Data you no longer need is data you are still liable for.
People who changed roles two years ago can still open every response. Nobody has reviewed the permission model since it was set up, and no record shows it was ever checked.
A well-configured instance usually holds what an auditor wants. Producing it for the first time under audit pressure is where the weeks go, and where gaps get discovered.
Both columns have to hold for a process to be defensible. Buyers tend to check the left one thoroughly during procurement and never revisit the right one after go-live.
| Control area | FormAssembly provides | You configure, and an auditor checks |
|---|---|---|
| Platform assurance | SOC 2 Type II audit results and PCI DSS compliance, published for review. | That you obtained, read and retained the current reports for your file. |
| Protected health information | HIPAA-supporting controls on the relevant tier, and a business associate agreement. | That the agreement is executed, the tier is right, and forms are scoped accordingly. |
| Government workloads | A FedRAMP-authorized High-Impact environment on the Government plan. | That you are actually in that environment, not merely on the vendor's price list. |
| Encryption | Encryption in transit and at rest as a platform property. | Field-level masking for the values that need it beyond storage encryption. |
| Access control | SAML, CAS and LDAP respondent authentication, plus platform single sign-on. | Which forms require it, who holds which role, and when access was last reviewed. |
| Data lifecycle | Configurable retention and deletion capability. | The periods you set, and evidence deletion actually occurs. |
| Onward transfer | Connectors and logging of every run. | What each destination receives — and that regulated fields are withheld by mapping. |
| File handling | Secure file scanning on the relevant tier. | Accepted file types, size limits, and where uploads ultimately come to rest. |
This work covers the controls you are accountable for: selecting the plan tier your actual obligations require rather than the one bought before the use case existed, authenticating respondents where the data warrants it, masking sensitive values, setting retention so data is deleted when its purpose ends, modelling permissions so access is least-privilege and reviewable, restricting what each connector destination receives, and assembling the evidence an auditor will ask for before they ask for it. All of it is configuration, and all of it is examined during an audit.
Where this page stops. We configure the platform; we do not issue legal opinions on whether your process satisfies a specific regulation, and you should not accept that from any implementation partner. Your counsel or compliance function owns that judgement and we work to it. Standing the platform up initially is FormAssembly implementation services; the connector mapping that decides what each destination receives is FormAssembly integration services; approval chains that need a documented decision trail are FormAssembly workflow automation.
What Twopir does, and what the product does. The certifications, the encryption, the authentication mechanisms, the scanning and the retention capability are FormAssembly's — the vendor built and maintains them, and its trust centre is where your security reviewer should verify current status and scope. What we contribute is the configuration, the scoping decisions and the evidence pack. As a Salesforce Partner and HubSpot Partner we can also close the gap on the CRM side, which is where regulated fields most often end up somewhere unintended. Product documentation is the FormAssembly Resource Center.
Each of these maps to something a reviewer will ask you to demonstrate. Configuring them is the work; being able to evidence them is the deliverable.
Which regulations actually apply to what you collect, and whether your current tier carries the controls they require.
Forms that only the right people can open, using your existing identity provider rather than an unguessable link.
Collecting less, and protecting what remains. The cheapest compliance control is the field you decided not to collect.
A policy that operates rather than one that exists in a document. Data kept past its purpose is liability without benefit.
Least privilege, and a review cadence that produces a record. Access nobody has checked is access nobody can defend.
Assembled before it is requested. This is the deliverable that turns a well-configured instance into a defensible one.
Durations describe typical engagements and depend on the size of the form estate. Remediation is prioritised by exposure, so the highest-risk findings are closed first.
What is collected, about whom, on which forms, under which obligations — agreed with your compliance function rather than assumed by us. One to two weeks.
Plan tier, authentication posture, permissions, retention, masking and connector destinations assessed against the inventory. Findings ranked by exposure. One to two weeks.
Highest-exposure findings closed first — usually authentication on forms that should never have been public, and connector mappings sending more than they should. One to four weeks.
The data-flow map, access register, retention schedule and authentication posture written up as a pack a non-technical reviewer can follow. One week.
Access review, retention check and a re-inventory when new forms are added — set up as a recurring obligation with an owner, because compliance posture decays without one.
In each of these the collection itself is the regulated act. The obligation named against each is the one that most often drives the engagement, not the only one that applies.
Patient intake and information forms handling protected health information. The engagement usually turns on three things: the tier carrying HIPAA controls, an executed business associate agreement, and which downstream systems the connector is feeding.
Account opening, loan applications and KYC collection. Retention and access review dominate here, because the evidence question is usually who could see an application and when that was last checked.
Applications, student records and support requests. Respondent authentication matters most: student-facing forms are frequently public when the data behind them is not, and the identity provider already exists.
Donor, beneficiary and programme data crossing jurisdictions. Minimisation, evidenced consent and answerable erasure requests are the work — and erasure is where the connector destinations become everyone's problem.
We have not published a case study scoped to a FormAssembly compliance engagement, and we will not present one that does not exist. Compliance work is also the category where client confidentiality is least negotiable — an organization's audit findings are not marketing material. We are happy to talk through anonymised patterns on a call, and our published integration work is linked here for the delivery approach.
See a Published Integration EngagementCertifications and their scope change, so your security reviewer should verify current status at the source rather than relying on any third party's restatement — including ours. FormAssembly publishes its compliance documentation and audit results for review, and that is the right input to a vendor assessment.
FormAssembly Resource CenterWe help growing and mid-market companies solve complex CRM, integration and business system challenges, and we work with enterprise organizations on the same problems at larger scale.
Most of what fails an audit is in the second column. Treating a certificate as evidence about your instance is the single most common mistake we are called in to correct.
Regulated fields usually leave through a connector nobody assessed. As a Salesforce Partner and HubSpot Partner we can trace and fix the destination, not just report it.
We are not a FormAssembly reseller, so the tier recommendation follows the obligation. Sometimes that means telling you the tier you already have is sufficient.
We configure controls and assemble evidence. Whether a process satisfies a specific regulation is your counsel's judgement, and any partner claiming otherwise is overreaching.
Compliance posture decays. Access review, retention checks and re-inventory when forms are added need an owner and a schedule, or the findings simply return.
The question is slightly the wrong shape, and the distinction matters. A platform is not compliant on your behalf — it provides controls that let you build a compliant process. FormAssembly supports HIPAA obligations for organizations handling protected health information and will enter into a business associate agreement, but those controls sit on specific plan tiers, the agreement has to actually be executed, and how you configure access, masking and retention is your responsibility rather than the vendor's. Most compliance failures we see are configuration failures on a properly certified platform, not platform failures.
It depends on which obligation applies, and FormAssembly renamed its tiers — Essentials, Team, Enterprise and Government — so older comparison articles cite names that no longer match. Broadly: identity-provider management for respondent single sign-on sits at Team and above, HIPAA and GLBA controls together with secure file scanning sit at Enterprise, and the FedRAMP-authorized High-Impact environment is the Government plan. FedRAMP in particular is scoped to that environment rather than being a property of the product generally, which is a common and expensive misunderstanding. We confirm current tier definitions with FormAssembly during scoping rather than quoting from memory.
FormAssembly publishes SOC 2 Type II audit results and PCI DSS compliance, and supports organizations working to HIPAA, GDPR, FERPA, GLBA, 21 CFR Part 11, ISO 27001, CCPA, TX-RAMP and Section 508 obligations, with a FedRAMP High-Impact authorized environment available on the Government plan. The vendor maintains a trust centre where the current documentation can be requested, and that is where your security reviewer should go — certifications and their scope change, so we point to the source rather than restating a list that will age.
By authenticating respondents rather than relying on an unguessable URL. Forms can require authentication through SAML, CAS or LDAP, so only people your identity provider recognises can open them — and identity-provider management lets that be configured once and reused across forms rather than set up per form. This is separate from the single sign-on your own staff use to reach the platform. Conflating the two is common, and it means public forms sometimes carry data that should have required a login.
Four things that are configuration rather than paperwork. Collect only what you need, so the form itself enforces minimisation. Capture consent in a way you can later evidence, with the wording and the timestamp retained. Set retention so data is deleted when its purpose ends instead of accumulating indefinitely. And make subject-access and erasure requests answerable, which means knowing every place a submission's data reached — including the systems your connectors send it to. That last one is where most organizations discover their retention policy only covers the CRM.
In our experience: who can access which forms and responses, and when that was last reviewed; how respondents are authenticated where the data warrants it; what the retention period is and evidence that deletion actually happens; where submission data travels, including every connector destination; and the record of who saw or changed a response. Most of that exists in a well-configured instance but has never been assembled. Producing it under audit pressure is considerably harder than setting it up beforehand, which is the main argument for doing this work before you need it.
Yes, and that is how most of these engagements start. We audit the plan tier against your actual obligations, review permissions and access history, check which forms collect regulated data and whether they are authenticated, look at retention and masking configuration, and trace where connectors send data — which is the step that most often finds regulated fields arriving somewhere nobody intended. You get the findings and a prioritised remediation list whether or not you continue with us.
Which of your forms collect regulated data while being reachable by anyone with the link, and where does every connector send those fields afterwards? If either answer takes more than a few minutes to produce, that is the conversation to have.
Or contact the team — we configure the controls and assemble the evidence