FormAssembly · Security & Compliance

The platform is certified. Your configuration of it is not.

FormAssembly publishes SOC 2 Type II results, PCI DSS compliance and a FedRAMP High-Impact environment. None of that is evidence about your instance. Twopir Consulting configures the part an auditor actually examines: plan tier against obligation, respondent authentication, masking, retention, permissions, and where connectors send regulated fields. Their certification. Your configuration. Different responsibilities.

Certification vs Configuration
WHAT THE VENDOR PROVIDES Certified Controls SOC 2 · PCI · ISO 27001 Environment Tier Enterprise or Government Encryption in Transit Encryption at Rest Secure File Scan YOUR CONFIGURATION · TWOPIR Plan & Tier Fit Obligation-led Not volume-led Access Control Respondent auth Permissions · SSO Data Lifecycle Masking · Retention Deletion · export A CERTIFIED PLATFORM CONFIGURED CARELESSLY STILL FAILS THE AUDIT 2πr WHAT AN AUDITOR SEES Controls Applied Not just available on the plan Evidence Ready Produced on request, not reconstructed Scope Defensible You can say where the data lives SCOPE · RESTRICT · MINIMISE · RETAIN · EVIDENCE
12+
Years CRM delivery
500+
Clients served
40+
Consultants
250+
Deployments

Trusted by 500+ organizations — including healthcare, higher education, nonprofit and financial services teams collecting data a regulator takes an interest in.

Magnus Health
Ideal Health Consulting
Aventria
Social Justice Collaborative
LegalZoom

Built for Regulated Data Collection

  • Salesforce Partner
  • HubSpot Partner
  • HIPAA Configuration
  • GDPR & Consent
  • SAML & CAS Authentication
  • Field-Level Masking
  • Retention Policies
  • Audit Evidence
Where It Fails

Six findings that appear on a properly certified platform

Every one of these can exist in an instance running on a SOC 2 audited, PCI compliant platform with every certificate in order. The certificate describes the vendor's controls. The finding is about yours.

Regulated data is collected on a tier that was never scoped for it

Protected health information arriving through a form on a plan whose HIPAA controls were never enabled, often because the plan was bought before the use case existed.

An unguessable URL is doing the job of authentication

A form holding sensitive data is technically public — anyone with the link can open it. The link is in an email, a browser history and a support ticket somewhere.

A connector sends regulated fields somewhere unscoped

The mapping was built to send everything because that was quickest. Health or financial data is now in a marketing platform whose controls were never assessed for it.

Nothing is ever deleted

Responses from six years ago sitting in an instance whose retention policy exists only as a paragraph in a document. Data you no longer need is data you are still liable for.

Access was granted and never reviewed

People who changed roles two years ago can still open every response. Nobody has reviewed the permission model since it was set up, and no record shows it was ever checked.

The evidence exists but has never been assembled

A well-configured instance usually holds what an auditor wants. Producing it for the first time under audit pressure is where the weeks go, and where gaps get discovered.

Who Owns What

The vendor's certification is not evidence about your instance

Both columns have to hold for a process to be defensible. Buyers tend to check the left one thoroughly during procurement and never revisit the right one after go-live.

Control areas split by who is accountable. Certifications and their scope change over time — verify current status through the vendor's trust centre rather than relying on any restatement, including this one.
Control areaFormAssembly providesYou configure, and an auditor checks
Platform assuranceSOC 2 Type II audit results and PCI DSS compliance, published for review.That you obtained, read and retained the current reports for your file.
Protected health informationHIPAA-supporting controls on the relevant tier, and a business associate agreement.That the agreement is executed, the tier is right, and forms are scoped accordingly.
Government workloadsA FedRAMP-authorized High-Impact environment on the Government plan.That you are actually in that environment, not merely on the vendor's price list.
EncryptionEncryption in transit and at rest as a platform property.Field-level masking for the values that need it beyond storage encryption.
Access controlSAML, CAS and LDAP respondent authentication, plus platform single sign-on.Which forms require it, who holds which role, and when access was last reviewed.
Data lifecycleConfigurable retention and deletion capability.The periods you set, and evidence deletion actually occurs.
Onward transferConnectors and logging of every run.What each destination receives — and that regulated fields are withheld by mapping.
File handlingSecure file scanning on the relevant tier.Accepted file types, size limits, and where uploads ultimately come to rest.
What This Covers

Compliance is configuration, not paperwork

This work covers the controls you are accountable for: selecting the plan tier your actual obligations require rather than the one bought before the use case existed, authenticating respondents where the data warrants it, masking sensitive values, setting retention so data is deleted when its purpose ends, modelling permissions so access is least-privilege and reviewable, restricting what each connector destination receives, and assembling the evidence an auditor will ask for before they ask for it. All of it is configuration, and all of it is examined during an audit.

Where this page stops. We configure the platform; we do not issue legal opinions on whether your process satisfies a specific regulation, and you should not accept that from any implementation partner. Your counsel or compliance function owns that judgement and we work to it. Standing the platform up initially is FormAssembly implementation services; the connector mapping that decides what each destination receives is FormAssembly integration services; approval chains that need a documented decision trail are FormAssembly workflow automation.

What Twopir does, and what the product does. The certifications, the encryption, the authentication mechanisms, the scanning and the retention capability are FormAssembly's — the vendor built and maintains them, and its trust centre is where your security reviewer should verify current status and scope. What we contribute is the configuration, the scoping decisions and the evidence pack. As a Salesforce Partner and HubSpot Partner we can also close the gap on the CRM side, which is where regulated fields most often end up somewhere unintended. Product documentation is the FormAssembly Resource Center.

What We Configure

Six control areas, each one an audit question

Each of these maps to something a reviewer will ask you to demonstrate. Configuring them is the work; being able to evidence them is the deliverable.

Obligation Mapping & Plan Fit

Which regulations actually apply to what you collect, and whether your current tier carries the controls they require.

  • Data inventory: what is collected, about whom, by whom
  • Obligations identified with your compliance function
  • Tier assessed against obligation, not against volume
  • Business associate agreement status confirmed
  • A written recommendation for procurement

Respondent Authentication

Forms that only the right people can open, using your existing identity provider rather than an unguessable link.

  • SAML, CAS or LDAP authentication on forms that need it
  • Identity-provider management configured once and reused
  • A decision, per form, on whether public access is appropriate
  • Secure prefill links that do not leak record identifiers
  • Platform single sign-on for internal users, kept distinct

Masking & Data Minimisation

Collecting less, and protecting what remains. The cheapest compliance control is the field you decided not to collect.

  • Field-level masking for sensitive values
  • Form review to remove fields with no live purpose
  • Conditional collection so data is gathered only when relevant
  • Upload rules covering accepted types and size
  • Payment handling that keeps instrument details off your systems

Retention & Deletion

A policy that operates rather than one that exists in a document. Data kept past its purpose is liability without benefit.

  • Retention periods set per form and per data category
  • Deletion that demonstrably happens, with evidence
  • Draft and save-and-resume retention decided deliberately
  • Subject access and erasure requests made answerable
  • Downstream systems included in the retention picture

Permissions & Access Review

Least privilege, and a review cadence that produces a record. Access nobody has checked is access nobody can defend.

  • Role model matched to who genuinely needs response data
  • Administrative separation between building and viewing
  • Joiner, mover and leaver handling agreed with IT
  • A recurring access review with an evidence trail
  • Integration-user privileges scoped to what connectors need

Evidence Pack

Assembled before it is requested. This is the deliverable that turns a well-configured instance into a defensible one.

  • Data-flow map covering every connector destination
  • Access register and review history
  • Retention schedule with deletion evidence
  • Authentication posture documented per form
  • A pack a non-technical reviewer can actually read
How We Deliver

Find the gap, close it, then make it provable

Durations describe typical engagements and depend on the size of the form estate. Remediation is prioritised by exposure, so the highest-risk findings are closed first.

Stage 01

Data & Obligation Inventory

What is collected, about whom, on which forms, under which obligations — agreed with your compliance function rather than assumed by us. One to two weeks.

Stage 02

Configuration Audit

Plan tier, authentication posture, permissions, retention, masking and connector destinations assessed against the inventory. Findings ranked by exposure. One to two weeks.

Stage 03

Remediation

Highest-exposure findings closed first — usually authentication on forms that should never have been public, and connector mappings sending more than they should. One to four weeks.

Stage 04

Evidence Assembly

The data-flow map, access register, retention schedule and authentication posture written up as a pack a non-technical reviewer can follow. One week.

Stage 05

Review Cadence

Access review, retention check and a re-inventory when new forms are added — set up as a recurring obligation with an owner, because compliance posture decays without one.

Where This Lands

The four sectors where this work is not optional

In each of these the collection itself is the regulated act. The obligation named against each is the one that most often drives the engagement, not the only one that applies.

Healthcare — HIPAA

Patient intake and information forms handling protected health information. The engagement usually turns on three things: the tier carrying HIPAA controls, an executed business associate agreement, and which downstream systems the connector is feeding.

Financial Services — GLBA

Account opening, loan applications and KYC collection. Retention and access review dominate here, because the evidence question is usually who could see an application and when that was last checked.

Higher Education — FERPA

Applications, student records and support requests. Respondent authentication matters most: student-facing forms are frequently public when the data behind them is not, and the identity provider already exists.

Nonprofit & International — GDPR

Donor, beneficiary and programme data crossing jurisdictions. Minimisation, evidenced consent and answerable erasure requests are the work — and erasure is where the connector destinations become everyone's problem.

On Evidence

Why There Is No Case Study Here

We have not published a case study scoped to a FormAssembly compliance engagement, and we will not present one that does not exist. Compliance work is also the category where client confidentiality is least negotiable — an organization's audit findings are not marketing material. We are happy to talk through anonymised patterns on a call, and our published integration work is linked here for the delivery approach.

See a Published Integration Engagement
Verify For Yourself

Check the Vendor's Current Posture

Certifications and their scope change, so your security reviewer should verify current status at the source rather than relying on any third party's restatement — including ours. FormAssembly publishes its compliance documentation and audit results for review, and that is the right input to a vendor assessment.

FormAssembly Resource Center
Why Twopir

We configure controls; we do not sell certificates

We help growing and mid-market companies solve complex CRM, integration and business system challenges, and we work with enterprise organizations on the same problems at larger scale.

We separate the vendor's controls from yours

Most of what fails an audit is in the second column. Treating a certificate as evidence about your instance is the single most common mistake we are called in to correct.

We follow the data past the form

Regulated fields usually leave through a connector nobody assessed. As a Salesforce Partner and HubSpot Partner we can trace and fix the destination, not just report it.

We do not sell you a bigger plan

We are not a FormAssembly reseller, so the tier recommendation follows the obligation. Sometimes that means telling you the tier you already have is sufficient.

We stay inside our competence

We configure controls and assemble evidence. Whether a process satisfies a specific regulation is your counsel's judgement, and any partner claiming otherwise is overreaching.

We leave a cadence, not just a fix

Compliance posture decays. Access review, retention checks and re-inventory when forms are added need an owner and a schedule, or the findings simply return.

Common Questions

What compliance teams ask before an audit, not after

The question is slightly the wrong shape, and the distinction matters. A platform is not compliant on your behalf — it provides controls that let you build a compliant process. FormAssembly supports HIPAA obligations for organizations handling protected health information and will enter into a business associate agreement, but those controls sit on specific plan tiers, the agreement has to actually be executed, and how you configure access, masking and retention is your responsibility rather than the vendor's. Most compliance failures we see are configuration failures on a properly certified platform, not platform failures.

It depends on which obligation applies, and FormAssembly renamed its tiers — Essentials, Team, Enterprise and Government — so older comparison articles cite names that no longer match. Broadly: identity-provider management for respondent single sign-on sits at Team and above, HIPAA and GLBA controls together with secure file scanning sit at Enterprise, and the FedRAMP-authorized High-Impact environment is the Government plan. FedRAMP in particular is scoped to that environment rather than being a property of the product generally, which is a common and expensive misunderstanding. We confirm current tier definitions with FormAssembly during scoping rather than quoting from memory.

FormAssembly publishes SOC 2 Type II audit results and PCI DSS compliance, and supports organizations working to HIPAA, GDPR, FERPA, GLBA, 21 CFR Part 11, ISO 27001, CCPA, TX-RAMP and Section 508 obligations, with a FedRAMP High-Impact authorized environment available on the Government plan. The vendor maintains a trust centre where the current documentation can be requested, and that is where your security reviewer should go — certifications and their scope change, so we point to the source rather than restating a list that will age.

By authenticating respondents rather than relying on an unguessable URL. Forms can require authentication through SAML, CAS or LDAP, so only people your identity provider recognises can open them — and identity-provider management lets that be configured once and reused across forms rather than set up per form. This is separate from the single sign-on your own staff use to reach the platform. Conflating the two is common, and it means public forms sometimes carry data that should have required a login.

Four things that are configuration rather than paperwork. Collect only what you need, so the form itself enforces minimisation. Capture consent in a way you can later evidence, with the wording and the timestamp retained. Set retention so data is deleted when its purpose ends instead of accumulating indefinitely. And make subject-access and erasure requests answerable, which means knowing every place a submission's data reached — including the systems your connectors send it to. That last one is where most organizations discover their retention policy only covers the CRM.

In our experience: who can access which forms and responses, and when that was last reviewed; how respondents are authenticated where the data warrants it; what the retention period is and evidence that deletion actually happens; where submission data travels, including every connector destination; and the record of who saw or changed a response. Most of that exists in a well-configured instance but has never been assembled. Producing it under audit pressure is considerably harder than setting it up beforehand, which is the main argument for doing this work before you need it.

Yes, and that is how most of these engagements start. We audit the plan tier against your actual obligations, review permissions and access history, check which forms collect regulated data and whether they are authenticated, look at retention and masking configuration, and trace where connectors send data — which is the step that most often finds regulated fields arriving somewhere nobody intended. You get the findings and a prioritised remediation list whether or not you continue with us.

Next Step

Two questions worth answering before anyone audits you

Which of your forms collect regulated data while being reachable by anyone with the link, and where does every connector send those fields afterwards? If either answer takes more than a few minutes to produce, that is the conversation to have.

Or contact the team — we configure the controls and assemble the evidence