Skip to content

Security and Subprocessors

How jpforms (https://jpforms.com) is run, where your data sits, and who else touches it.

Everything a buyer has to check before adopting the service is on this page, so that checking it costs no correspondence.

How the platform is built

These hold for every service we run. They are repository-wide rules rather than per-product decisions, and tests fail the build when one of them drifts.

Where your data lives

Controls specific to this service

Subprocessors

The following processors handle data on our behalf, to the extent needed to run the service. Each is engaged under its own data protection terms.

Cloudflare

Hosting, storage, the browser that renders a form's pages, and the model that reads what each box is for. Documents stay inside Cloudflare's network.

Country: United States

Stripe (api.stripe.com)

Subscription billing: the account email, the amount and the plan. Card details never reach us — Checkout is hosted by Stripe.

Country: United States

Resend (api.resend.com)

Transactional email: the recipient address and the message, including sign-in links, reminders and billing notices.

Country: United States

A new subprocessor is published here at least 30 days before it begins processing your data.

Independent attestations

We hold no third-party attestation — no SOC 2, no ISO 27001. We say so plainly rather than leaving the section out, because an omission reads like an oversight and a buyer deserves to know which it is.

Reporting a vulnerability

If you find a vulnerability, tell us through the disclosure form (/legal/disclosure). We acknowledge a report promptly, and we will not pursue legal action over research carried out in good faith to investigate one.

Changes to this page

This page changes as the service does. A new subprocessor is posted in advance; any other material change is posted with the date it takes effect.

Last updated: 2026-09-07