About SOC

In September 2022, we received our audit report on SOC 2 compliance from an independent auditor, ensuring that the dedicated environment meets the latest security standards. The report shows our security controls and data protection practices for that dedicated environment have been independently tested. The independent assessment of the dedicated environment gives both enterprise customers and end users more peace of mind.

SOC 2 Trust Principles

Jotform’s dedicated SOC 2 environment aligns with the five SOC 2 Trust Service Principles: security, availability, processing integrity, confidentiality, and privacy. Read on for more information on each principle.

  • Security
    Security
    Jotform’s dedicated environment uses controls designed to help protect form data and responses against unauthorized access. Your data is hosted in local data residency centers that comply with high security standards. You can also add password protection to your forms and ensure that form submissions are encrypted for your safety. Enabling multifactor authentication (MFA) on your Jotform account is another way to stop hackers in their tracks.
  • Availability
    Availability
    Jotform Enterprise systems have an SLA of 99.5 percent uptime and are monitored for anomalies on a 24-7 basis. Server and network health is managed to ensure high performance and consistent system operations. The system is built to detect and mitigate security incidents, and if disaster strikes, Jotform follows a rigorous disaster recovery plan.
  • Processing Integrity
    Processing Integrity
    Jotform maintains policies and controls in the dedicated environment to help restrict access to your data to authorized users. As an Enterprise customer, you own your submission data, which cannot be viewed by Jotform personnel without your permission. Data stored in the dedicated environment is in an encrypted format and our data processing is designed to satisfy both your organization’s objectives and regulatory requirements.
  • Confidentiality
    Confidentiality
    At Jotform, we further protect your business’s data by allowing you to set granular access restrictions on both your forms and form submissions. Forms can easily be password protected and submissions are encrypted and available only to the form owner by default, unless you decide to share them with another authorized user.
  • Privacy
    Privacy
    Jotform’s dedicated SOC 2 environment includes privacy features designed to help safeguard personally identifiable information from unauthorized access. That includes names, social security numbers, and addresses — as well as identifiers such as race, ethnicity, and health information.
SOC 2-compliant Jotform Servers

SOC 2-compliant Jotform Servers

Enterprise customers can request to have their servers provisioned in our SOC 2-compliant dedicated environment, which is available as an upgrade. This allows you to deploy custom forms and apps on our hosted platform on systems secured and managed by Jotform that are compliant with these controls.

Physical Server Security

FERPA is a necessary and crucial piece of legislation that protects students’ information. All educational organizations should make protecting students’ information a top priority because any organization found in violation of FERPA could face investigation by the Department of Education, which could lead to the withdrawal of federal funding.

How do you achieve FERPA compliance?

Jotform’s dedicated environment includes security features designed to help protect the data you collect. Jotform servers are hosted in Google Cloud, meaning Google is responsible for the physical security controls over the data centers hosting Jotform’s infrastructure. We’re proud to partner with such trusted services and committed to operating effectively and helping keep your data safe.

To receive a copy of the SOC 2 report if you are an existing Jotform Enterprise customer, please contact your account representative. If you are currently not a Jotform Enterprise customer, please contact our team and a representative will reach out to you with details. To learn more about SOC 2 Type II compliance and what it means for your organization, click the link below to watch our informational webinar.