I'd like to know how common it is for people to allow anonymous external access to K2 SmartForms. We have a number of solutions running on our K2 servers. Some are really important to our company and hold important and private information. It feels like a risk to allow external web access to the same server that runs our SmartForms and workflow designers as well as other K2 forms that are meant for internal people only.
If I'm understanding it correctly, the only thing stopping people from seeing those other forms or hitting the designers is K2's application security, based on our corporate AD group. Is this risky?
If anyone knows of any documentation about options or how this works architecturally, could you please give me the links?