Responses are often the most sensitive thing a team collects, so this page describes what CanvasFlow actually does to protect them — with real numbers where there are numbers, and a list of what we haven’t built yet.
Last updated 31 July 2026
The question that matters most, so it gets checked in three independent places rather than once at the door.
A public form has to accept requests from strangers, so the limits are what keep that from becoming a liability.
Most of these are correctness guarantees. They are on this page because a response set you can’t trust is its own kind of failure.
The full inventory of what is and isn’t stored is in the privacy policy.
A security page listing only strengths tells you nothing, because every product has gaps. Here are ours, so you can decide with the real picture.
Our Content-Security-Policy allows inline scripts, because the framework injects its startup script inline. That means the policy restricts where code can be loaded from but won't stop script injected into the page itself. Tightening it to a per-request nonce is planned.
We don't currently keep a per-form audit trail of which collaborator viewed which responses. Add collaborators deliberately, since removing someone doesn't tell you what they already read.
CanvasFlow has not been independently penetration-tested and holds no compliance certification. We would rather say that than imply otherwise.
If one of these is a blocker for the data you had in mind, it’s better to know now than after you’ve collected it.
We’d genuinely rather hear it from you than find out the hard way. Report what you found, how to reproduce it, and what you think the impact is. We’ll confirm we received it, keep you posted while we fix it, and credit you if you’d like to be credited.
Please test only against your own account and your own forms, don’t run automated scans or load tests against the service, and don’t access, alter, or retain anyone else’s responses. Report it and stop there — that’s enough to prove the point, and we won’t pursue researchers who stay within those lines.
Use the feedback option inside the app to reach us — it routes straight to us. Mark it as a bug and mention it’s security-related so we prioritise it.