Compliance & assurance
Compliance & assurance
See the protections Klarstig provides, how privacy responsibilities are shared, and which assessments and advanced capabilities are available.
Start readingSecurity controls support responsible information handling.
Data protection, international transfers and EU hosting are separate questions.
Assessment status and feature availability are stated explicitly.
01Security controls in the service
Klarstig’s documented controls include HTTPS, storage encryption, private file storage, multi-factor authentication, organization roles, security logging, input validation, rate limits, honeypot checks and HMAC-signed webhooks. Organization administrators can configure supported session and IP-access policies.
Privacy-request tools, data exports and customer-downloadable backups support information access and portability. Availability monitoring supports service operations. These controls have different purposes; their presence does not establish an independent audit opinion or make every customer workflow compliant.
02GDPR, California privacy and customer responsibilities
Klarstig provides privacy-request and export tools. Organizations using forms still need an appropriate purpose and legal basis for collection, suitable notices, permissions and retention decisions. Klarstig’s own obligations depend on its role and the processing activity.
The Privacy Policy explains information handling and applicable rights. The relevant data-processing terms define customer and provider responsibilities. GDPR and CCPA/CPRA support should not be read as a blanket certification of every use of the service.
03EU privacy and data location
EU-only data residency is not currently available. We do not promise that storage, processing, support access, backups or connected services remain within the EU.
GDPR does not impose a universal EU-only hosting requirement. Relevant transfers outside the EEA require an applicable mechanism and safeguards, in addition to the other applicable data-protection obligations. EU hosting alone does not establish compliance.
Use the Privacy Policy’s current location and transfer information and the applicable processing documents when assessing a European workflow. Interface language and visitor geolocation do not determine data residency.
04Independent assessments and advanced capabilities
The following capabilities are not currently available. A supplier’s report or certification does not automatically cover Klarstig. Availability changes require an actual released offering or completed assessment with an identified scope.
SOC 2
Not availableAn independent SOC 2 report for Klarstig is not currently available.
ISO/IEC 27001
Not availableCertification for Klarstig is not currently available.
HIPAA-enabled forms / BAA
Not availableHIPAA-enabled forms and a customer BAA offering are not available.
StateRAMP / GovRAMP
Not availableNo verified or authorized Klarstig offering is currently available.
HECVAT
Not availableAn evidence-backed draft is in progress; a completed, reviewed questionnaire is not available.
Single sign-on (SSO/SAML)
Not availableCustomer sign-in through SSO is not currently available.
EU data residency
Not availableAn EU-only residency option is not available.
Customer-held encryption keys
Not availableA released form mode using customer-held decryption keys is not available.
05Payment, education and regulated information
Klarstig’s PCI DSS validation status has not been verified for this page. A payment provider’s validation does not establish Klarstig’s validation. Do not use ordinary form fields to collect card security codes or other payment authentication secrets.
A FERPA-specific offering has not been verified. Institutions need to assess their intended use, applicable requirements, terms and controls. HIPAA-enabled forms and a customer BAA are unavailable; do not submit protected health information where that arrangement is required.
No StateRAMP/GovRAMP authorization is claimed. Customer eligibility requirements must be assessed against the service actually offered, not another provider’s credentials.
06Encryption, backups, service levels and testing
Modern HTTPS uses TLS. We describe connection encryption separately from storage encryption and do not make a universal “256 Bit SSL” claim. Customer-held decryption keys are a separate unavailable capability.
Customer-downloadable archives are separate from platform disaster recovery. The 24-hour signed-link expiry is an access limit, not a retention or recovery guarantee. Monitoring is separate from an agreed SLA.
Spam protections do not by themselves establish CAPTCHA availability. Internal security checks, independent penetration tests, SOC 2 examinations and ISO certification are distinct activities. We identify an assessment only when its scope and evidence support the statement.
07Policies and supporting documents
Read the Privacy Policy for information handling and rights, the Terms of Service for contractual responsibilities, and the Security page for control descriptions.
Applicable processing terms and current subprocessor information are available on request through [email protected]. An unfinished questionnaire is not a completed assessment, and a draft agreement is not an executed contract. Any assurance material provided applies only to its stated service scope and period.
08Questions about your requirements
Tell us which information you intend to collect, the countries involved and any required contractual or assurance conditions. Contact [email protected] to request the applicable documents and confirm whether the service supports your intended use.
