I need to get some assurances around the encrypted forms

  • Profile Image
    Andy Loughran 
    Asked on February 25, 2016 at 05:33 AM

    Hi,

    Your product looks great, and the encrypted form functionality is something that I'm very interested in using.  Do you have any documentation or third party accreditation to assure me that the encrypted forms provide a zero-knowledge platform where you are able to assert that you do not store any of the encrypted data on your servers before the data encryption occurs?

    Regards,

     

    Andy Loughran

  • Profile Image
    aytekin
    Answered on February 25, 2016 at 11:29 AM

    Unfortunately no, we don't have a 3rd party accreditation. It is only our word. We are 10-year company with perfect security record. 

  • Profile Image
    Andy Loughran 
    Answered on February 25, 2016 at 11:45 AM
    That’s not exactly true.
    I see on your forums that someone created a multi-page encrypted form and it was persisted as non-encrypted. Can you explain how that error could have occurred if your server has zero-knowledge of the unencrypted forms?
    Regards,
    Andy Loughran
    ...
  • Profile Image
    aytekin
    Answered on February 25, 2016 at 11:54 AM

    I found the thread:

    http://www.jotform.com/answers/669768-Data-submitted-as-encrypted-form-is-showing-up-unencrypted-on-form-that-have-multiple-pages

     

    The encryption was not working on multi-page forms but once the problem is reported it was promptly fixed. The javascript code that handles the multiple pages was in conflict with the javascript that encrypts the data before submission.