YakForms
Trust

How YakForms protects a forms estate

Your estate is the documents your regulator reads. This page says what we actually do, and is deliberate about what we have not done yet.

Where it runs

YakForms runs either in your own tenancy or in ours on infrastructure in the EU. Deploy agents run inside your environments and pull the work assigned to them over an outbound connection — there is no inbound path from us into your network, and no firewall rule to open.

Asset storage

Form assets are content-addressed: a revision is identified by the digest of its bytes, so a change is detectable and a rollback is exact. Blobs are encrypted at rest, and sensitive configuration fields are encrypted at the column level rather than only at the disk level. Customer-managed keys are available on Enterprise.

Identity and access

  • SSO over OIDC or SAML, so access follows your joiners-and-leavers process.
  • SCIM provisioning and de-provisioning.
  • Multi-factor authentication, including TOTP and passkeys, with rate limiting on every authentication path.
  • Role-based authorization per estate, and scoped API keys per integration.

The audit trail

Every import, revision, validation run, review decision, waiver, release and deployment is recorded with an actor and a timestamp. The log is exportable, because an audit trail you cannot hand to an auditor is not one.

Getting your estate back

Every revision, manifest, review decision and audit entry exports as files plus NDJSON, at any time, without asking us. Exit is a feature, not a negotiation.

What we have not done yet

YakForms is not currently SOC 2 or ISO 27001 certified. We will say so here when that changes rather than implying it in the meantime. If your procurement process requires a certification we do not hold, tell us early — it is a real answer we can give you in a week rather than a conversation to have in month three.

A data processing agreement, our subprocessor list and a security questionnaire response are available on request.