Security by design, not by promise
FormaBase handles money and personal information for every product it runs. Verification makes people accountable; the architecture and the review process are what actually stop bad actors. We rely on both.
Each layer stops a different kind of threat, so no single control has to be perfect.
| Layer | Protection | Stops | Status |
|---|---|---|---|
| Who gets in | Creators pass a government ID and live identity check, and sign the Creator Agreement, before any access | Anonymous or throwaway Creators | In progress |
| Account security | Two-factor sign-in required for every Creator and administrator | Stolen accounts | In progress |
| Blast radius | A product holds only its own database and a key scoped to itself | One product reaching money, identities or other products | In progress |
| Customer data | Products receive only the customer fields they need; payment details never leave Stripe | Data harvesting through a product | In progress |
| Code entry | Creators cannot push to production or deploy; every change is a reviewed pull request | Unreviewed code in production | In progress |
| Automated screening | Dependency, vulnerability and secret scanning, static analysis and AI review on every release | Malware, backdoors and hidden data flows | Planned |
| Human approval | A person approves the first release and anything the screening flags | What automation misses | Planned |
| Runtime | Per-product rate limits, anomaly alerts and an instant kill switch | Damage from anything that gets through | Planned |
Identity and access
In progressCreators are verified up front. Before submitting a product or receiving any development access, every Creator completes the same identity check through a dedicated verification provider: a government ID and a live identity match. FormaBase stores the result, the date and a provider reference, never the image of the document.
Affiliates are verified when they set up payouts. They never ship code, so the check happens where it matters: before money moves.
Access is personal and least-privilege. Two-factor sign-in is required for Creators and administrators. A Creator can reach only the product they are assigned to, and only in development. Every administrative action is written to an audit log.
Secrets never leave the Core
In progressPayment, email, messaging and AI keys exist only inside the Core. A product holds exactly two secrets: its own Core key and the address of its own database. Creators never see production values; the Core sets every product's environment when it provisions or updates it.
If a key were ever exposed, the Core can rotate that product's keys in one step, because it issued them. A release is blocked if a secret appears in source code, history, or the code sent to browsers.
Reviewed releases
PlannedEvery product release passes automated screening, then human approval for first launches and anything the screening flags. The same screening runs on every later update, not only at launch.
- Dependency allowlists and known-vulnerability checks
- Secret scanning of source code and of the code shipped to browsers
- Static analysis and an AI review for hidden routes, obfuscated code and undisclosed network calls
- Products may call only the Core and approved third-party services
The Creator Agreement backs this up: Creators commit to disclosing every external service and package they use, and never to add malware, backdoors, hidden payment flows or undisclosed data collection.
| Protection | Detail | Status |
|---|---|---|
| Encryption in transit | Every FormaBase address is served over HTTPS only, with HTTP Strict Transport Security | Live |
| Browser security headers | Framing blocked, content-type sniffing disabled, strict referrer policy, camera, microphone and location off | Live |
| Payment details | Card data is handled by Stripe and never touches FormaBase servers | In progress |
| Encryption at rest | Databases and files are stored with providers that encrypt data at rest | In progress |
| Data minimization | Products receive only the customer fields they need, through the SDK | In progress |
| Money records | The ledger is append-only: corrections are new entries, never edits | In progress |
For what personal information we collect and why, see the Privacy Policy.
Runtime protection
PlannedLive products run with per-product rate limits and alerts for unusual behavior. If something goes wrong, FormaBase can revoke a product's key and take its deployment offline in one step, without affecting any other product.
Independent testing
PlannedFormaBase will commission an independent penetration test of the Core before participant registration opens, and repeat it as the platform grows.
If you believe you have found a security issue in FormaBase or any FormaBase product, please email security@formabase.app with enough detail for us to reproduce it. We will acknowledge your report, keep you updated, and credit you if you would like.
Please act in good faith: give us reasonable time to fix the issue before disclosing it, avoid accessing or changing other people's data, and do not degrade the service. We will not pursue anyone who reports an issue this way. Our contact details are also published at /.well-known/security.txt.