Overview
For Access, Must Be On: Team, Enterprise, or Government Cloud
NOTE: TX-RAMP is only in scope for Government Cloud
FormAssembly is a web-based application that is offered as a SaaS solution. Data and the type of data to be collected depends on the company using the service to collect it.
Compliance








Documents
Risk Profile
Product Security
Reports
Self-Assessments
Data Security
App Security
Legal
Data Privacy
Access Control
Infrastructure
Endpoint Security
Network Security
Corporate Security
Policies
Security Grades

Knowledge Base
- Are the policies and procedures reviewed and updated at least annually?
- Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
- Are application security policies and procedures reviewed and updated at least annually?
- Are application security policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained to guide appropriate planning, delivery, and support of the organization's application security capabilities?
- Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit?
Trust Center Updates
FormAssembly has successfully completed an audit for ISO 27001 covering FormAssembly. The organization worked with A-LIGN to perform a detailed audit of its controls as they relate to ISO 27001.
- Original Certification Date: June 14, 2021
- Recertification Date: July 18, 2023
- Expiry Date: June 14, 2024
A-LIGN Compliance and Security, Inc. certifies that the organization operates an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2013.
The certificate and report can now be downloaded in the portal.
FormAssembly's controls are assessed by A-LIGN, who specialize in compliance across multiple industries, on an annual basis.
FormAssembly annually performs a SOC-2 Type-2 assessment. Our most recently available report covers from December 1, 2022 - May 31, 2023. An updated review period is scheduled with our auditors, and we expect an updated report to be available in mid-2023.
The SOC 2 report includes management’s description of FormAssembly’s trust services and controls as well as A-LIGN’s opinion of FormAssembly’s system design. You can find it under the Reports section of this Security Portal.
We maintain a SOC 2 Type 2 certification as a result of this regular audit activity and can share the most recent SOC 2 report with our customers upon request and under a non-disclosure agreement. The SOC 2 is a report based on the Auditing Standards Board of the American Institute of Certified Public Accountants' (AICPA) existing Trust Services Criteria (TSC). The purpose of this report is to evaluate an organization’s information systems relevant to security.
The scope of this report covers controls supporting the FormAssembly App and Enterprise/Compliance plans.
The following policies had be updated and added back to the security portal:
- Access Control
- Breach Investigation and Notification (BIN)
- Compliance Audits and Communications
- Data/Media Management
- Encryption
- Information Security
- Mobile Device Security and Media Management
- Risk Management and Risk Assessment
- Secure Software Development and Product Security
- System Audits, Monitoring and Assessments
- Third Party Security
- Threat Detection and Prevention
- Vulnerability Management
The following policies had be updated and added back to the security portal:
- Business Continuity and Disaster Recovery
- Business Continuity and Disaster Recovery Plan
- Incident Response Policy
Version 4.04 of CAIQ Security Questionnaire has been uploaded and is ready for download.
HECVAT Lite Version 3.03 is now in the FormAssembly Customer Trust Portal
Version 3.03 of Higher Education Community Vendor Assessment Toolkit has been uploaded and is ready for download.
FormAssembly's ISO 27001 Surveillance Assessment Year 2 Final Report is now available to request and download.
FormAssembly's SOC 2 Type 2 Report is now available to request and download.
If you need help using this Trust Center, please contact our Cybersecurity Risk team.
If you think you may have discovered a vulnerability, please send us a note.