HTTPS/TLS encryption
HTTPS protects information sent between your browser and Klarstig. Connection encryption is separate from encryption of stored data.
More about this protection
Security headers add browser-level safeguards alongside HTTPS.
KLARSTIG SECURITY
Explore how your forms, information and account are protected. Find the details that matter to you, in one place.
KLARSTIG SECURITY
Start with the essentials, then explore each protection in more detail.
Protect information as it moves through your forms and account.
HTTPS protects information sent between your browser and Klarstig. Connection encryption is separate from encryption of stored data.
Security headers add browser-level safeguards alongside HTTPS.
A form mode using customer-held decryption keys is not currently available. Existing connection and storage protections are described separately.
Rate limits and automated-abuse checks help reduce unwanted submissions. These protections do not guarantee that every spam submission will be blocked.
Rate limits and honeypot checks help reduce automated abuse and unwanted submissions. CAPTCHA is a separate feature with its own availability status.
Access controls protect private submissions and files. Sharing a public form must not expose the responses submitted by other people.
Uploaded files are stored privately, with controlled access to downloads. Stored files are not published as public assets.
Connection encryption and encryption of stored form data protect different parts of the service. Customer-held encryption keys are a separate capability.
Storage encryption helps protect data held by the platform. It is separate from customer-held decryption keys, which are not currently available.
CAPTCHA availability is under review. Existing spam controls should not be interpreted as proof that a CAPTCHA challenge is enabled.
Understand privacy controls, data location and your responsibilities.
Klarstig provides tools for privacy requests and data export. GDPR responsibilities also depend on your use, the applicable agreements, and how information is processed.
The privacy-request process supports requests relating to personal information, including GDPR and CCPA requests. Applicable rights and processing details belong in the current privacy notices and agreements.
Privacy-request tools support handling of California privacy requests. Applicable rights and responsibilities depend on the processing activity and each party’s role.
A FERPA-specific offering has not yet been verified. Education-record use requires a review of the institution’s requirements, permitted processing, and applicable terms.
Security features work alongside the applicable privacy notices, service terms, and data-processing agreements. Requirements vary with your location and use of the service.
Review the privacy controls available for your account and forms. Collection choices, sharing settings, and retention should match your intended use.
An EU data-residency option is not currently available. We do not promise that all storage, processing, support access, or backups remain within the EU.
Location-data features are under review. A visitor’s location does not determine where their data is stored.
Manage who signs in and how your team accesses information.
Two-factor authentication adds a verification step to account sign-in. Protect recovery methods as carefully as your password.
Multi-factor authentication adds another verification step beyond a password. Use the supported account controls to manage enrollment and recovery.
OpenID Connect (OIDC) single sign-on is available to organizations. An organization owner or admin configures the connection and enables it only after verifying an email domain and passing a connection test; each organization keeps password sign-in until it opts in. SAML 2.0 single sign-on is also available, using the same admin-configured, domain-verified, opt-in flow. Only service-provider-initiated sign-in is supported; identity-provider-initiated sign-in and federated single logout are not offered, so signing out ends your Klarstig session locally.
Account protections include authentication, permissions, session controls, and security records. Keep your credentials and recovery methods private.
Organization roles control what team members can access and do. Security-relevant activity is logged to support investigation and accountability.
Organization administrators can manage supported session and IP-access policies within platform safeguards. Available settings do not remove the platform’s baseline protections.
Administrators can configure session-lifetime limits and an IP allowlist over the platform baseline. Policy changes have a recorded history.
Explore the practices behind service protection and availability.
Organization owners can download a scoped backup using a time-limited private link. Downloadable archives are separate from platform disaster-recovery backups.
Spreadsheet exports include safeguards against formula injection. Organization backup archives are stored privately and delivered through a signed link that expires after 24 hours. A SHA-256 checksum lets you verify the downloaded archive’s integrity.
A contractual service-level commitment has not been verified for this page. Availability monitoring alone is not an uptime guarantee.
Availability monitoring helps identify service issues. It is separate from a contractual uptime commitment or service credits.
Hosting and data-center details are under review. Any provider assurance must be distinguished from an assessment of Klarstig’s own service.
Platform backup and recovery details are under review. Retention, recovery targets, and restore capabilities will be described only for verified operations.
Secure development includes input validation, access checks, and controlled changes. These practices reduce risk but do not guarantee vulnerability-free software.
Incoming data is checked to reject malformed or unexpected input. Webhook messages are signed using HMAC; receiving systems must verify the signature before trusting or processing the message.
Security testing, independent penetration testing, and assurance audits are different activities. This page will identify only assessments supported by current evidence.
Network protections complement application access controls. Available protections depend on the hosting configuration and the responsibilities assigned to each provider.
Check the status and scope of assessments and specialized offerings.
Klarstig’s PCI DSS validation status is under review. A payment provider’s validation does not establish Klarstig’s own compliance.
HIPAA-enabled forms and a customer BAA offering are not currently available. Do not use Klarstig to collect protected health information requiring that arrangement.
Klarstig does not currently offer a StateRAMP/GovRAMP-verified service. A hosting provider’s status does not extend automatically to Klarstig.
An independent SOC 2 report for Klarstig is not currently available. We will identify the report type and scope if an examination is completed.
An evidence-backed HECVAT response is being prepared. A completed, reviewed questionnaire is not currently available.
ISO/IEC 27001 certification for Klarstig is not currently available.
COMMON QUESTIONS
Find out how Klarstig’s safeguards, account settings, and data controls work.
Klarstig uses HTTPS for data in transit, storage encryption, private file storage, and access controls. Each protection addresses a different part of how information moves through and is stored by the platform.
Organization admins can configure session-lifetime limits and an IP allowlist. These policies sit above the platform baseline, and changes are recorded. Team roles and multi-factor authentication provide additional account protections.
Yes. Organization owners can generate an organization-scoped backup archive. The archive is stored privately and made available through a signed download link that expires after 24 hours. A SHA-256 checksum is included so you can check the downloaded archive’s integrity.
Use the privacy-request process available in Klarstig. This supports requests relating to your personal information, including GDPR- and CCPA-related requests. The process and your rights are described in the applicable privacy information.
An independent SOC 2 report and ISO 27001 certification are not currently available. The assessments section above lists the current status of these and other advanced capabilities.
No. Klarstig does not currently offer a HIPAA Business Associate Agreement. Do not use this page’s security descriptions as a claim that a HIPAA-covered workflow is supported.
EU data residency and customer-held encryption keys are not currently available. Storage encryption is distinct from customer-held keys. See the advanced capabilities section for the current status.
Klarstig signs webhook messages using HMAC. Your receiving system must verify that signature before trusting or processing the message. A signature is useful only when the receiving system checks it.
Modern HTTPS connections use TLS. The encryption negotiated for a connection and the encryption used for stored data are different; a universal 256-bit claim needs specific supporting evidence.
GDPR does not impose a universal EU-only hosting rule. Transfers outside the EEA need an applicable lawful mechanism and safeguards. EU hosting alone does not establish compliance; Klarstig’s EU residency option is not currently available.
No. A customer archive provides a copy of its documented contents. Platform disaster recovery has separate backup schedules, retention, restore procedures and recovery targets. A download does not necessarily include automatic re-import.
No. Rate limits and automated-abuse checks can operate without a CAPTCHA challenge. CAPTCHA availability and its privacy implications must be described separately.
No. A service-level agreement is a contractual commitment with defined scope, measurement and remedies. Monitoring or an internal reliability target alone does not create that commitment.
No matching questions. Try "backup," "access," or "encryption," or clear your search.