Serious security, on every form you publish
Encrypted uploads, malware scanning, bot protection, and team-level access control — built into the platform, not sold as add-ons. Your respondents' data is protected before you think about it.
Your respondents' data, protected
Everything submitted through your forms goes through a hardened pipeline before it's stored.
AES-256 envelope encryption
Every uploaded file is encrypted at rest with AES-256 using a unique per-file key — signatures, documents, images, all of it.
Malware scanning on every upload
Files are scanned with ClamAV before storage, with MIME-type and magic-byte validation and strict extension allowlists on top.
Tamper-proof payment totals
On payment forms, totals are recalculated server-side from your price list — editing the page can't change what gets charged.
Bots and abuse, filtered out
Spam protection at the field level, the platform level, and the human level.
CAPTCHA field
Add a CAPTCHA (Google reCAPTCHA v2) to any form to challenge automated submissions before they reach your inbox.
Platform-level bot defense
Cloudflare Turnstile protects sign-up and login, while public form endpoints run browser checks and rate limiting.
Built-in abuse reporting
Every published form carries an anti-phishing notice and a report option, so misuse gets flagged and reviewed fast.
Your account, locked down
The account that owns the data deserves the same protection as the data itself.
Two-factor authentication
Add a second factor to your login. New sign-ups and sign-ins are verified with email one-time codes.
Active session control
See every device signed into your account and revoke any session — or all of them — with one click.
Login history
A visible trail of recent sign-ins, so anything unfamiliar stands out immediately.
Email verification
One-time codes at signup keep throwaway and mistyped addresses out of your workspace.
Team access, precisely scoped
Five roles and seventeen granular permissions decide exactly who can see, edit, export, and administer.
Role-based permissions
From owner to view-only: 5 roles built on 17 granular permissions covering forms, submissions, billing, and members.
Permission-gated exports
Data leaves your workspace only through members explicitly allowed to export it.
Full audit log
Form edits, member changes, billing actions, settings — every significant action is recorded with actor and time.
Explore the Audit Log →Integrations that don't leak
HMAC-signed webhooks
Webhook payloads are signed with HMAC-SHA256 secrets you can rotate with a grace period — receivers can verify every delivery is really from us.
Encrypted integration tokens
OAuth tokens for connected services are stored encrypted at rest, never in plain text.
Frequently asked questions
Related features
File Uploads
Collect documents, images, and media through your forms — validated, scanned, and encrypted.
Learn more →Audit Log
A complete, filterable history of every significant action in your workspace.
Learn more →Webhooks
Send form submissions to any endpoint with signed, retried, and logged deliveries.
Learn more →Collect data like it matters
Every plan ships with the same security foundation — encryption, scanning, bot protection, and access control from day one.
Start Building Free