Formevra — Secure Client Intake & Form Exchange

Terms of Service

Last updated: July 12, 2026

1. Acceptance of Terms

By accessing or using Formevra ("the Service"), you agree to be bound by these Terms of Service. If you do not agree to these terms, please do not use the Service.

2. Service Description

Formevra is a secure, zero-persistence client intake and form exchange platform that enables insurance agents to request sensitive billing details from clients via time-limited, tokenized links. The Service facilitates the secure, encrypted transmission of payment data between clients and their assigned agents.

3. Zero-Persistence Commitment

All sensitive payment data (routing and account numbers) is encrypted with AES-256-GCM and permanently purged as soon as it is successfully uploaded to the carrier's application. No raw payment details are ever permanently stored.

The Service does not retain raw routing or account numbers in any database, log file, or backup. Encrypted ephemeral data is purged immediately upon first agent viewing. This commitment is a core architectural principle and cannot be overridden by any user, agent, or administrator.

4. Agent Responsibilities

Agents using the Service agree to:

  • Use collected payment information solely for processing the client's health insurance application.
  • Complete the Agent Responsibility & Data Handling Acknowledgment before accessing any payment data.
  • Use multi-factor authentication (MFA) for every instance of viewing sensitive payment data.
  • Never share MFA codes, secure links, or account credentials with any other person.
  • Immediately purge payment data after entering it into the carrier's application.
  • Never access payment data during impersonation or quality-control sessions.
  • Report any suspected security incident to the portal administrator immediately.

5. Client Consent

By submitting payment information through the Service, the client authorizes their assigned insurance agent to use the provided information solely for processing the client's health insurance application. The client acknowledges that:

  • Payment details are encrypted and never permanently stored.
  • Data is purged as soon as it is successfully uploaded to the carrier's application.
  • The assigned agent must verify their identity via MFA before viewing any payment details.
  • All access attempts are logged for security and compliance purposes.

6. Security & Access Controls

The Service implements the following security measures:

  • Brute-force protection: Automatic lockout after 5 failed identity verification or MFA attempts.
  • Real-time alerting: Administrators are notified of repeated failures and suspicious activity.
  • Role-based access: Only the assigned agent (and authorized administrators) can access a client's submission.
  • Time-limited links: All client links have an expiration date set by the agent.
  • Immutable audit trail: All actions (creation, viewing, purging, completion) are permanently logged.

7. Limitation of Liability

The Service is provided "as is" for the purpose of facilitating secure payment information collection. While every effort is made to protect data, no system can guarantee absolute security.

The Service providers shall not be liable for any indirect, incidental, or consequential damages arising from the use of the Service. The Zero-Persistence architecture is designed to minimize risk, but agents and clients share responsibility for proper handling of information once it has been viewed and entered into the carrier's application.

8. Changes to These Terms

We reserve the right to update these Terms of Service at any time. Changes will be posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance of the updated terms.

9. Contact

For questions about these Terms of Service, please contact your assigned insurance agent or theFormevra administrator.