Security at anota
Your forms collect other people's data. This page explains, plainly, how we protect it.
Infrastructure
- anota runs on Microsoft Azure (application, database, and file storage).
- All traffic is encrypted over HTTPS, with a one-year HSTS policy that covers subdomains.
- Subscription payments are processed by Stripe. Your card details never touch our servers.
Accounts and access
- Passwords are stored hashed, never in plain text.
- You can turn on two-factor authentication and sign in with passkeys.
- After repeated failed sign-in attempts, the account is temporarily locked.
- Team roles (Owner, Admin, and others) limit who can see responses, edit forms, or manage keys.
Your data, kept separate
- Every form, response, and file belongs to a workspace, and every lookup — in the app, the REST API, and the MCP server — is scoped to yours.
- Responses are validated on the server, including conditional logic, so nobody can skip a required field by tampering with the browser.
- Uploaded files are checked by type and actual content, stored under server-chosen names, and always downloaded as attachments.
API, MCP, and integrations
- API keys are shown once and stored only as a hash. You can revoke them instantly.
- Every webhook is signed with HMAC-SHA256 so your system can verify it came from anota, and anota refuses to send them to internal or private addresses.
- Integration credentials are stored encrypted.
Report a vulnerability
If you find a security issue, email us at hello@anota.cloud. We answer every report and appreciate responsible disclosure.
See also our Privacy policy.