Sign in Book a demo
Security & Compliance

The HIPAA-compliant form builder built for lead gen.

SOC 2 Type II certified. HIPAA compliance with signed BAA on Pro and above. GDPR, PIPEDA, and TCPA ready. AES-256 encryption, TLS 1.3, and US data residency — not as add-ons. As defaults.

SOC 2 Type II HIPAA BAA on Pro+ ISO 27001 AES-256 at rest TLS 1.3 in transit
SOC 2 Type II
Annual audit. Security, availability, confidentiality.
HIPAA
BAA on Pro and above. PHI field marking. US data residency.
GDPR
EU data residency available. Data processing agreements.
PIPEDA
Canadian data residency. Privacy-first data handling.
TCPA
TrustedForm on every plan. Consent certified per submission.
HIPAA

HIPAA-compliant form builder with signed BAA.

When your lead gen forms ask about health conditions, current coverage, prescriptions, or any Protected Health Information, HIPAA compliance is required — not optional. MakeForms is purpose-built for healthcare lead gen with the technical and administrative safeguards HIPAA mandates.

Signed BAA on Pro and aboveNot Enterprise-only. Standard HHS-aligned Business Associate Agreement. Signed during onboarding. Most compliance teams approve it the same day.
US data residency on every planPHI stays in US-based AWS regions. Not just on your highest tier — on every MakeForms account.
Tenant-isolated encryption keysYour data uses AES-256 encryption keys unique to your tenant. Not shared across customers.
PHI field marking in the editorFlag individual fields as PHI inside the form builder. Marked fields receive additional encryption and are tagged in your CRM payload.
Minimum necessary accessRole-based access controls limit which team members can view PHI fields. Per-form permissions enforced.
Business Associate Agreement
Standard HHS-aligned BAA · Pro and above
Included
Tenant-isolated encryption
AES-256 · Unique keys per account
All plans
US data residency
AWS us-east-1 · All PHI stays in the US
All plans
PHI field marking
Per-field in the form editor
Pro+
TCPA

TCPA compliance with TrustedForm on every submission.

The Telephone Consumer Protection Act requires written prior express consent before making telemarketing calls. $1,500 minimum fine per unconsented call. For lead gen agencies running outbound campaigns, every call to a form-generated lead needs a defensible consent record. MakeForms generates that record automatically.

TrustedForm auto-generated on every submissionOne toggle in the form editor. Every submission gets a tamper-evident certificate — timestamp, IP address, session replay, and consent language captured.
Cert ID in CRM payload automaticallyThe TrustedForm certificate ID lands with the lead in HubSpot, Salesforce, GoHighLevel, or any CRM via webhook. No manual retrieval.
Works on multi-step formsMost form builders break TrustedForm on multi-step forms — the script captures only the first screen. MakeForms generates a complete certificate covering every step at submission.
Independent certificate hostTrustedForm certificates are hosted by ActiveProspect — independently of MakeForms and independently of you. Tamper-evident. Court-admissible.
What TrustedForm captures: Timestamp · IP address · User agent · Page URL · Full session replay · Consent language visible at time of submission · OTP verification status
TrustedForm certificate
Auto-generated · Every submission
All plans
Cert ID to CRM
Automatic · Every lead payload
All plans
Multi-step certification
Every screen captured · Complete cert
MakeForms only
SOC 2 Type II

SOC 2 Type II certified — independently audited annually.

SOC 2 Type II is a third-party audit of MakeForms' security controls over a sustained period — not a point-in-time snapshot. It covers security, availability, and confidentiality. The audit is conducted annually by an independent CPA firm.

Annual independent auditSOC 2 Type II evaluates controls over a minimum 6-month observation period. Not a self-assessment. Not a questionnaire. An independent third-party audit.
Security, availability, and confidentiality trust principlesAll three principles evaluated. Controls mapped to AICPA criteria and documented in the audit report.
Report available under NDAEnterprise customers can request the full SOC 2 Type II report under NDA. Contact your account manager.
SOC 2 Type II
Annual audit · Independent CPA firm
Certified
ISO 27001
Information security management system
Certified
Full report available
Under NDA for Enterprise customers
On request
GDPR + PIPEDA

EU and Canadian data compliance built in.

MakeForms supports data residency in the EU (Frankfurt) and Canada (Montreal) for customers subject to GDPR or PIPEDA. Select your data region during onboarding. Data never leaves your selected region.

EU data residency (Frankfurt)Select EU region during onboarding. All data stored in AWS eu-central-1. No cross-border transfers.
Canadian data residency (Montreal)Select Canada region during onboarding. All data stored in AWS ca-central-1. Meets PIPEDA and provincial privacy law requirements.
Data Processing Agreements availableStandard DPA available for GDPR-regulated entities. Request during onboarding.
Right to erasure supportedData deletion requests processed within 30 days. Contact [email protected].
US data residency
AWS us-east-1 · Default region · All plans
Available
EU data residency
AWS eu-central-1 · Frankfurt · GDPR
Available
Canadian data residency
AWS ca-central-1 · Montreal · PIPEDA
Available
Technical security

Security built into the infrastructure.

Not bolt-on compliance. MakeForms was built HIPAA-first with security controls at every layer of the stack.

Encryption

AES-256 at rest

All data encrypted at rest using AES-256. Tenant-isolated keys — your account's data uses encryption keys that are unique to your tenant, not shared across customers.

Transport

TLS 1.3 in transit

All data in transit encrypted with TLS 1.3. TLS 1.0 and 1.1 disabled. Certificate pinning on all API endpoints. HSTS enforced on all domains.

Access

Zero-trust access

MakeForms employees access production systems only through MFA-enforced VPN with just-in-time provisioning. No persistent access to customer data. Access requests logged and audited.

Infrastructure

AWS with VPC isolation

All infrastructure runs on AWS inside isolated Virtual Private Clouds. No shared compute between tenants. Security groups enforced at the instance level.

Availability

99.9% uptime SLA

Multi-AZ deployment. Automated failover. Daily backups with 30-day retention. Point-in-time recovery available on Enterprise.

Vulnerability

Pen testing + CVE monitoring

Annual third-party penetration tests. CVE monitoring on all dependencies. Security patches deployed within 24 hours of CVE publication for critical vulnerabilities.

Logging

Immutable audit logs

All access to PHI fields, form exports, and admin actions logged immutably. Logs retained 12 months. CloudTrail enabled across all AWS accounts.

Development

Secure SDLC

SAST scanning on every pull request. Dependency vulnerability scanning in CI/CD pipeline. Code review required before production deployments. No direct production pushes.

Ready to review the BAA?

The MakeForms Business Associate Agreement uses standard HHS-aligned terms. Most compliance teams approve it the same day. Available on Pro and above. Request it during onboarding or contact your account manager.

FAQ

Common questions

Does MakeForms sign a HIPAA Business Associate Agreement?

Yes. MakeForms signs a standard HHS-aligned BAA with customers on Pro and above. It is not locked behind an Enterprise contract. The BAA is sent during onboarding and most compliance teams approve it the same day. Contact your account manager or request it at [email protected].

Is MakeForms SOC 2 Type II certified?

Yes. MakeForms holds a SOC 2 Type II certification covering the security, availability, and confidentiality trust service principles. The audit is conducted annually by an independent CPA firm. The full report is available under NDA to Enterprise customers.

Where is my data stored?

By default, all MakeForms data is stored in US-based AWS regions (us-east-1). EU data residency (Frankfurt, eu-central-1) and Canadian data residency (Montreal, ca-central-1) are available for GDPR and PIPEDA compliance respectively. Select your region during onboarding. Data never leaves your selected region.

How does MakeForms handle TrustedForm for TCPA compliance?

MakeForms generates a TrustedForm certificate on every form submission — automatically, with one toggle in the form editor. The certificate captures the timestamp, IP address, session replay, and consent language the prospect saw. The cert ID is included in every CRM payload. Unlike other form builders, MakeForms generates complete multi-step TrustedForm certificates — the script captures every step, not just the first page.

Does MakeForms share my data with third parties?

MakeForms does not sell customer data. Data is shared only with sub-processors necessary to operate the service (AWS for infrastructure, ActiveProspect for TrustedForm). A full sub-processor list is available at makeforms.io/subprocessors. Customers are notified of new sub-processors 30 days in advance.

Is the MakeForms security documentation available?

Yes. SOC 2 Type II report available under NDA (Enterprise). BAA available on Pro and above. Security questionnaire responses available on request. Penetration test executive summary available on request for Enterprise customers. Contact [email protected].
14-day free trial — no credit card

Built for compliance-first lead gen. Ready when your legal team is.

Book a 15-minute compliance demo. We'll walk through the BAA, PHI field setup, TrustedForm configuration, and data residency options. Bring your compliance officer.

No commitment SOC 2 + HIPAA ready Live in 30 minutes