Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
Compliance timeline
-
June 2024
Trust center first observed in public web archives
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Paperform discloses on its trust center. Linked entries have their own profile in the Trust Index.
72% chain trust: 18 of 25 disclosed subprocessors are themselves in the Trust Index.
- Stripe AU Subscription management, payment processing.
- Intercom Support and account related email notifications
- Atlassian Bug reports and feature request management.
- Google Analytics Analytics, sales attribution, product improvements
- Mailgun Transactional emails sent from no-reply@paperform.co, including emails sent on form submission.
- Postmark Fallback provider for transactional emails sent from no-reply@paperform.co, including emails sent on form submission.
- Sendinblue Fallback provider for transactional emails sent from no-reply@paperform.co, including emails sent on form submission.
- Microsoft Clarity Session recording for usability purposes
- Amazon Web Services Hosting provider
- MongoDB Atlas Database management - hosting on AWS
- New Relic Systems monitoring, application logs.
- GitHub Product development
- PagerDuty Systems monitoring, incident management.
- Vanta Security Compliance Management and Automation.
- Bunny.net CDN and Font hosting
- Slack To manage daily operations and communicate with the team.
- Cloudflare Captcha service
- Google Workspace To manage daily operations and communicate with the team.
- Notion To manage daily operations and communicate with the team.
- Chargebee Subscription management, payment processing.
- OpenAI Engineering
- Anthropic AI Provider
- Google Cloud Cloud provider
- Microsoft Azure Cloud provider
- Anrok Sales tax management
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.