Jotform Inc.

United States · owned by Independent (United States) · www.jotform.com · 19 vendors

Jotform is an AI-powered online form builder and workflow automation platform serving over 35 million users worldwide. It enables individuals and organizations to create secure forms, collect data, accept payments, and automate workflows without coding. The company offers a full suite of products including form building, e-signatures, app creation, AI agents, and enterprise-grade solutions for industries such as government, healthcare, and education.

Resilience scores

Disruption prediction

Jotform Inc. has an estimated 11% probability of disruption in the next 6 months.

15 of Jotform Inc.'s 19 vendors monitored for disruptions.

Technology vendors

Services catalogue

7 services in catalogue across 4 categories; runs on 19 sub-vendors.

Insights

Last updated 2026-08-11 · revision 2

19 direct vendors, 223 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Jotform exhibits a strong foundation for migration readiness, primarily due to its existing multi-cloud active-active architecture (GCP and AWS), which demonstrates operational maturity in cloud environments. The presence of modern frontend technologies (React, JavaScript/Node.js) and robust API/Webhook capabilities facilitates the integration and potential migration of newer service components. Jotform's comprehensive regulatory compliance (GDPR, CCPA, HIPAA, SOC 2 Type II, ISO 27001, PCI DSS Level 1) and established data residency options across multiple countries are significant advantages, as they indicate a strong understanding and existing frameworks for managing complex data governance and compliance requirements during a migration. Consistent business growth also suggests the financial capacity to fund significant migration efforts. However, a primary challenge for migration readiness lies in the reliance on PHP and MySQL for the core backend. Migrating a large, established application built on these technologies can be complex, potentially requiring substantial refactoring or re-platforming if moving towards a more modern, microservices-based, or serverless architecture. The data regarding vendor relationships is ambiguous; while 'Total Vendors: 0' is stated, 'Total Services: 13' are listed with vendor HQ countries in the Netherlands, United States, and Canada. If these represent external vendor dependencies, the 'Vendor Lock-in Risk' being unknown could introduce unforeseen complexities or costs during a migration. Clarifying and mitigating potential lock-in with these 13 services would be crucial for a smooth migration.

Compliance

10 in-scope frameworks identified; showing 3.

HECVAT — Compliant

Jotform has completed the HECVAT assessment for its Enterprise product, demonstrating commitment to higher education security standards. Risk is Low because HECVAT is a voluntary assessment toolkit used by higher education institutions to evaluate vendor security, not a regulatory requirement with enforcement penalties.

Evidence: https://www.jotform.com/security/, https://www.jotform.com/enterprise/hecvat/

StateRAMP — Partially Compliant

Jotform is in the StateRAMP 'Security Snapshot' program (a preliminary stage before full authorization), not yet fully StateRAMP authorized. FedRAMP authorization is not claimed. Risk is Medium because: (1) Jotform Government is built to NIST SP 800-53 Rev. 5 controls (common to both FedRAMP and StateRAMP); (2) being in 'Security Snapshot' status means Jotform has not yet achieved full StateRAMP authorization, limiting its ability to serve certain state/local government customers with strict procurement requirements; (3) federal government customers requiring FedRAMP authorization cannot use Jotform without an ATO (Authority to Operate); (4) the government sector is a target market for Jotform Enterprise, making this gap commercially significant.

Evidence: https://www.jotform.com/security/, https://www.jotform.com/government/, https://www.jotform.com/help/all-you-want-to-know-about-jotform-government/

CCPA — Compliant

Jotform explicitly claims CCPA compliance and is headquartered in San Francisco, California, making CCPA directly applicable. Risk is Low because: (1) Jotform has a dedicated CCPA compliance page; (2) as a California-based company, CCPA compliance is a core legal obligation; (3) Jotform's privacy infrastructure (data subject rights, opt-out mechanisms) supports CCPA requirements; (4) the CCPA/CPRA framework is well-established and Jotform has had years to implement compliance measures.

Evidence: https://www.jotform.com/ccpa/, https://www.jotform.com/security/, https://www.jotform.com/privacy/

Financials

Three-year financials

Financial Resilience Score: 7/10

Jotform is a mature, bootstrapped, privately held SaaS company with a nearly two-decade operating history and no external VC funding or publicly disclosed debt. The company has repeatedly described itself as profitable, and industry estimates place annual revenue in the US$100M–$300M range as of 2023–2024. Its SaaS recurring revenue model, large freemium base converting to paid tiers, and rapidly growing enterprise segment (reported +620% enterprise customer growth in 2020, +50% overall revenue growth in 2020) suggest strong underlying financial health. A cost base concentrated in Turkey provides margin advantages relative to US SaaS peers. However, resilience cannot be fully verified due to the complete absence of audited, publicly filed consolidated financial statements. The company is not SEC-registered, publishes no annual accounts, and has no investor relations disclosures. Third-party estimates (Growjo, ZoomInfo, Latka, PitchBook) are not primary sources. Key risks include intense competition from well-capitalized rivals (Google Forms, Microsoft Forms, Typeform, DocuSign, Airtable, AI-native tools), geopolitical/currency concentration in Turkey, data-security exposure (HIPAA, payments), and key-person dependency on founder-CEO Aytekin Tank. The lack of outside investors also means no obvious external capital cushion in a downturn.

Key strengths: Bootstrapped, self-funded, and reportedly profitable with no VC dilution or disclosed debt, SaaS recurring revenue model with 35M+ users across 190+ countries, Rapidly growing enterprise segment (+620% enterprise customer growth reported in 2020), Reported +50% YoY revenue growth in 2020, Diversified product suite (Forms, Sign, Apps, Tables, Workflows, AI Agents, Store Builder), Low-cost engineering base in Turkey supporting margins, 20-year operating history with consistent user growth (1M in 2013 → 35M+ in 2025), Blue-chip enterprise customer logos (Shell, Ford, Netflix, Alaska Airlines, AMA)

Risk factors: No audited public financials; revenue, EBIT, equity, and cash position not verifiable, Intense competition from Google Forms, Microsoft Forms, Typeform, DocuSign, Airtable, and AI-native tools, Commoditization risk in core form-building product, Geopolitical and currency concentration risk in Turkey (main engineering base), Data-security and privacy exposure (HIPAA, payments, PII), Key-person dependency on founder-CEO Aytekin Tank, No external investors means no obvious external capital source in a downturn

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report