Show MeStart free

KLARSTIG SECURITY

Security, made clear.

Explore how your forms, information and account are protected. Find the details that matter to you, in one place.

Every submission matters. Protected Access on your terms Your data stays portableExports & organization backups

KLARSTIG SECURITY

Security at a glance

Start with the essentials, then explore each protection in more detail.

Independent assessments & advanced capabilities8 capabilities are not currently available
01 / Forms & data

Protect your forms and data

Protect information as it moves through your forms and account.

HTTPS/TLS encryption

HTTPS protects information sent between your browser and Klarstig. Connection encryption is separate from encryption of stored data.

More about this protection

Security headers add browser-level safeguards alongside HTTPS.

Encrypted forms with customer-held keys

Not available

A form mode using customer-held decryption keys is not currently available. Existing connection and storage protections are described separately.

Spam protection

Rate limits and automated-abuse checks help reduce unwanted submissions. These protections do not guarantee that every spam submission will be blocked.

More about this protection

Rate limits and honeypot checks help reduce automated abuse and unwanted submissions. CAPTCHA is a separate feature with its own availability status.

Form privacy

Access controls protect private submissions and files. Sharing a public form must not expose the responses submitted by other people.

More about this protection

Uploaded files are stored privately, with controlled access to downloads. Stored files are not published as public assets.

Form data encryption

Connection encryption and encryption of stored form data protect different parts of the service. Customer-held encryption keys are a separate capability.

More about this protection

Storage encryption helps protect data held by the platform. It is separate from customer-held decryption keys, which are not currently available.

CAPTCHA and bot challenges

CAPTCHA availability is under review. Existing spam controls should not be interpreted as proof that a CAPTCHA challenge is enabled.

02 / Privacy & the EU

Privacy and European data protection

Understand privacy controls, data location and your responsibilities.

GDPR and European data protection

Klarstig provides tools for privacy requests and data export. GDPR responsibilities also depend on your use, the applicable agreements, and how information is processed.

More about this protection

The privacy-request process supports requests relating to personal information, including GDPR and CCPA requests. Applicable rights and processing details belong in the current privacy notices and agreements.

California privacy rights — CCPA/CPRA

Privacy-request tools support handling of California privacy requests. Applicable rights and responsibilities depend on the processing activity and each party’s role.

Education records and FERPA

A FERPA-specific offering has not yet been verified. Education-record use requires a review of the institution’s requirements, permitted processing, and applicable terms.

Legal terms and responsibilities

Security features work alongside the applicable privacy notices, service terms, and data-processing agreements. Requirements vary with your location and use of the service.

Privacy settings

Review the privacy controls available for your account and forms. Collection choices, sharing settings, and retention should match your intended use.

EU servers and data residency

Not available

An EU data-residency option is not currently available. We do not promise that all storage, processing, support access, or backups remain within the EU.

Geolocation and location data

Location-data features are under review. A visitor’s location does not determine where their data is stored.

03 / Account & access

Control account access

Manage who signs in and how your team accesses information.

Two-factor authentication (2FA)

Two-factor authentication adds a verification step to account sign-in. Protect recovery methods as carefully as your password.

More about this protection

Multi-factor authentication adds another verification step beyond a password. Use the supported account controls to manage enrollment and recovery.

Single sign-on (SSO)

OpenID Connect (OIDC) single sign-on is available to organizations. An organization owner or admin configures the connection and enables it only after verifying an email domain and passing a connection test; each organization keeps password sign-in until it opts in. SAML 2.0 single sign-on is also available, using the same admin-configured, domain-verified, opt-in flow. Only service-provider-initiated sign-in is supported; identity-provider-initiated sign-in and federated single logout are not offered, so signing out ends your Klarstig session locally.

Account security

Account protections include authentication, permissions, session controls, and security records. Keep your credentials and recovery methods private.

More about this protection

Organization roles control what team members can access and do. Security-relevant activity is logged to support investigation and accountability.

Customizable security

Organization administrators can manage supported session and IP-access policies within platform safeguards. Available settings do not remove the platform’s baseline protections.

More about this protection

Administrators can configure session-lifetime limits and an IP allowlist over the platform baseline. Policy changes have a recorded history.

04 / Hosting & reliability

Hosting, reliability and security practices

Explore the practices behind service protection and availability.

Download a backup of your data

Organization owners can download a scoped backup using a time-limited private link. Downloadable archives are separate from platform disaster-recovery backups.

More about this protection

Spreadsheet exports include safeguards against formula injection. Organization backup archives are stored privately and delivered through a signed link that expires after 24 hours. A SHA-256 checksum lets you verify the downloaded archive’s integrity.

Service levels and availability

A contractual service-level commitment has not been verified for this page. Availability monitoring alone is not an uptime guarantee.

More about this protection

Availability monitoring helps identify service issues. It is separate from a contractual uptime commitment or service credits.

Hosting and data centers

Hosting and data-center details are under review. Any provider assurance must be distinguished from an assessment of Klarstig’s own service.

Backup and recovery policy

Platform backup and recovery details are under review. Retention, recovery targets, and restore capabilities will be described only for verified operations.

Secure development practices

Secure development includes input validation, access checks, and controlled changes. These practices reduce risk but do not guarantee vulnerability-free software.

More about this protection

Incoming data is checked to reject malformed or unexpected input. Webhook messages are signed using HMAC; receiving systems must verify the signature before trusting or processing the message.

Security testing and audits

Security testing, independent penetration testing, and assurance audits are different activities. This page will identify only assessments supported by current evidence.

Network security

Network protections complement application access controls. Available protections depend on the hosting configuration and the responsibilities assigned to each provider.

05 / Assessments

Assessments and regulated uses

Check the status and scope of assessments and specialized offerings.

Payment security and PCI DSS

Klarstig’s PCI DSS validation status is under review. A payment provider’s validation does not establish Klarstig’s own compliance.

HIPAA-enabled forms

Not available

HIPAA-enabled forms and a customer BAA offering are not currently available. Do not use Klarstig to collect protected health information requiring that arrangement.

StateRAMP / GovRAMP

Not available

Klarstig does not currently offer a StateRAMP/GovRAMP-verified service. A hosting provider’s status does not extend automatically to Klarstig.

SOC 2 assessment status

Not available

An independent SOC 2 report for Klarstig is not currently available. We will identify the report type and scope if an examination is completed.

HECVAT questionnaire

Not available

An evidence-backed HECVAT response is being prepared. A completed, reviewed questionnaire is not currently available.

ISO/IEC 27001 certification

Not available

ISO/IEC 27001 certification for Klarstig is not currently available.

COMMON QUESTIONS

Good questions. Clear answers.

Find out how Klarstig’s safeguards, account settings, and data controls work.

How is information protected in Klarstig?

Klarstig uses HTTPS for data in transit, storage encryption, private file storage, and access controls. Each protection addresses a different part of how information moves through and is stored by the platform.

What can my organization configure?

Organization admins can configure session-lifetime limits and an IP allowlist. These policies sit above the platform baseline, and changes are recorded. Team roles and multi-factor authentication provide additional account protections.

Can I download a backup of my organization’s data?

Yes. Organization owners can generate an organization-scoped backup archive. The archive is stored privately and made available through a signed download link that expires after 24 hours. A SHA-256 checksum is included so you can check the downloaded archive’s integrity.

How can I make a privacy request?

Use the privacy-request process available in Klarstig. This supports requests relating to your personal information, including GDPR- and CCPA-related requests. The process and your rights are described in the applicable privacy information.

Does Klarstig currently have SOC 2 or ISO 27001 certification?

An independent SOC 2 report and ISO 27001 certification are not currently available. The assessments section above lists the current status of these and other advanced capabilities.

Is a HIPAA BAA available?

No. Klarstig does not currently offer a HIPAA Business Associate Agreement. Do not use this page’s security descriptions as a claim that a HIPAA-covered workflow is supported.

Can I choose EU hosting or use my own encryption keys?

EU data residency and customer-held encryption keys are not currently available. Storage encryption is distinct from customer-held keys. See the advanced capabilities section for the current status.

How do signed webhooks protect my integration?

Klarstig signs webhook messages using HMAC. Your receiving system must verify that signature before trusting or processing the message. A signature is useful only when the receiving system checks it.

What does “256 Bit SSL” mean?

Modern HTTPS connections use TLS. The encryption negotiated for a connection and the encryption used for stored data are different; a universal 256-bit claim needs specific supporting evidence.

Does GDPR require all data to stay in the EU?

GDPR does not impose a universal EU-only hosting rule. Transfers outside the EEA need an applicable lawful mechanism and safeguards. EU hosting alone does not establish compliance; Klarstig’s EU residency option is not currently available.

Is downloading my data the same as disaster recovery?

No. A customer archive provides a copy of its documented contents. Platform disaster recovery has separate backup schedules, retention, restore procedures and recovery targets. A download does not necessarily include automatic re-import.

Does spam protection mean CAPTCHA is enabled?

No. Rate limits and automated-abuse checks can operate without a CAPTCHA challenge. CAPTCHA availability and its privacy implications must be described separately.

Does availability monitoring provide an SLA?

No. A service-level agreement is a contractual commitment with defined scope, measurement and remedies. Monitoring or an internal reliability target alone does not create that commitment.

↑ Back to overview