Designed and built with security and privacy in mind

Submittable is proud to exceed industry standards when it comes to protecting
the security and privacy of your organization’s data.

Compliance certifications and security features

Our team is committed to building a platform that helps you collect submissions and
applications easily without compromising privacy or security. Your work, and your
applicant’s data, is safe with us.
SOC 2 Type 2
Submittable completes a third party SOC
2 Type 2 compliance audit every year.
These reports demonstrate that our
systems are set up to assure the security
of customer data, and show how we
operate those controls over an extended
audit period.
Single Sign-On
Submittable supports Single Sign-on
(SSO) with SAML. This allows you to
authenticate users in your own systems
without requiring them to enter additional
login credentials.
Learn more
HIPAA
Submittable completes a third party audit
every year to assure that we are HIPAA
compliant. As part of our privacy
controls, all employees undergo yearly
HIPAA training.
Learn more
GDPR
Submittable has implemented tools and
processes to ensure our compliance with
the latest requirements under the GDPR
and to help our customers comply as
well.
Learn more
FERPA
Submittable complies with FERPA to
protect the privacy of student education
records.
PCI
Submittable does not directly store or
process credit card data. Instead, we rely
on Stripe to provide the industry's best and most secure credit card processing. Stripe is certified to PCI Service Provider Level 1 standards. Our PCI SAQ document is available upon request.
Permissions
We enable multiple different permission levels to be set for your team.
Permissions can be set to include or exclude information like platform settings, billing, and user data.

Frequently asked questions

In addition to the certification and security features listed above, here are some of the
most common security-related questions we get asked.
Where is my data hosted?

Submittable stores data in the Amazon Web Services US East (N. Virginia) region. We use multiple availability zones within this region to ensure durability.

How is data protected or backed up?

Data is stored using Amazon RDS and is encrypted at rest using AES-256. RDS provides automated backups which are retained for 35 days to enable point-in-time restored for the last month. We regularly test these backups manually in addition to the automated verification provided by AWS RDS. File attachments are stored in Amazon S3 which is designed for high durability.

What is your product uptime?

We have an uptime of 99.0% or higher.

Are your employees trained on security?

Yes, all employees complete security awareness and HIPAA best practices training on an annual basis.

How are you prepared for phishing schemes or other attacks?

Our developers have established a baseline for normal system activity to assist in identifying suspicious activity. This means Submittable is prepared for known attacks, like phishing schemes, but also for new unknown threats. Alerts and intrusion detection tools let our team know if unauthorized access does occur, so that response and corrective action can occur quickly. Audit trails lead to the root cause of an attack quickly so we can make quick and informed decisions about how to respond.

Want to learn more about security?

If you have additional questions regarding security or requests for specific compliance documents, we are happy to answer them.
Contact Us About Security