Handling a security incident

Last updated:

Security is Formcentric’s top priority. If you suspect that the security of your account, forms, or processed data has been compromised, you will find all the necessary steps here to act quickly and in a structured manner.

What constitutes a security incident?

A security incident occurs when the confidentiality, integrity, or availability of your data or the Formcentric platform is compromised or put at risk.

Common examples:

  1. Compromised accounts: Suspected unauthorized access to editor or administrator accounts (e.g. via phishing or stolen credentials).
  2. Unexpected data modifications: Unauthorized tampering with form content, system settings, or embedded scripts and extensions.
  3. Data breaches: Unintentional exfiltration, exposure, or publication of confidential form data.
  4. Suspicious system behaviour: Indications of attacks on interfaces (APIs) or unauthorized data exports.

Immediate actions & reporting

Step 1: Secure access & reset API clients

Lock user accounts:
Immediately suspend affected user accounts and/or reset their passwords.

Reset API client secrets:
If you suspect that interface credentials have been compromised, you must renew the Client Secret immediately as an administrator.

Step 2: Report the incident via the security form

Please use the following form to submit the details of the incident directly to our Team.

Step 3: Preserve evidence and cooperate

Once initial contact has been made, please avoid making further configuration changes or modifying data where possible, so as not to complicate the root cause analysis. We will get in touch with you promptly to coordinate next steps.

Important notes on GDPR notification requirements

Feedback