Formsieve checks form submissions for spam. We built it to hold as little as possible, and to keep your forms working if anything goes wrong.
What we keep, and what we do not
- We do not store the content of submissions. It is processed in memory for the one request and then gone. Request bodies are never logged or written to disk.
- We keep request records without the content for 30 days (time, request ID, key and site identifiers, plugin version, status, latency, model version, spam band), then daily totals for 25 months.
- The plugin sends as little as it can: the domain of an e-mail address instead of the address, phone numbers redacted by default, sensitive-looking fields excluded, and a size cap. IP addresses are never sent.
How the service is protected
- Encryption in transit: HTTPS only.
- Encryption at rest: the server's disk is encrypted (AWS EBS encryption), so the database, logs and backups on it are encrypted.
- No open doors: our server accepts no inbound connections. Traffic reaches it through an encrypted, outbound-only Cloudflare Tunnel. Administrative access goes through Cloudflare Access with a service token and an SSH key.
- Isolation: the spam-check API runs outside WordPress, as its own process pool and system user, with a database user that cannot read the website's database.
- Keys: Formsieve keys are stored and looked up as SHA-256 hashes; logs keep only a short prefix of the hash. Our AI-provider keys live only in a protected configuration file on the server. You can rotate your key in your account at any time.
- Strict requests: the API accepts only the fields the plugin sends, refuses browser requests, and caps the request size.
- Access: one named administrator. Multi-factor authentication on our hosting, network, payment, e-mail and AI-provider accounts. Least-privilege cloud credentials.
- Updates: operating-system security updates install automatically every day. WordPress security releases install automatically. Other updates are applied by hand within a week of release.
If something goes wrong
- Your forms keep working. If the service is slow or down, the plugin delivers submissions unchecked (or holds them for review, if you chose that). Billing problems never block a form.
- Limits and breakers: rate limits per key, per site and per network; a daily spending breaker; alerts on errors, latency, spend and unexpected model versions.
- Backups: every night we back up the databases and files on our server to its encrypted disk, and we take a snapshot of that disk. A copy of the backup, encrypted on the server before it leaves, goes to a private Cloudflare R2 bucket outside AWS; Cloudflare does not hold the key. Backups, copies and snapshots are deleted within 14 days.
- Incidents: we follow a written plan to detect, contain and assess incidents, and we notify affected customers without undue delay (target 48 to 72 hours).
Our providers
The companies that process data for us, and how, are listed at /subprocessors/.
Reporting a vulnerability
Write to support@formsieve.com with "Security" in the subject line. We acknowledge reports within two business days. Please do not test the live service without our written agreement (Acceptable Use Policy §4).