Explainer
End-to-end encrypted forms, explained
"Encrypted" can mean very different things. Here's the difference, and why it matters for anything sensitive you collect.
Encrypted at rest vs end-to-end
Almost every form builder encrypts data "at rest": the files on their servers are scrambled, but the company holds the key and decrypts answers whenever it needs to. That protects against a stolen hard drive, not against the company, its staff, a breach of its systems or a legal request.
End-to-end encryption means the answer is scrambled on the respondent's device and can only be unscrambled on yours. The company in the middle stores it but can never read it.
How SealForm does it
- Your account has a key pair, protected by a vault password that never leaves your browser.
- Each form has its own key, shared with your teammates browser to browser.
- The respondent's browser encrypts every answer and file with the form's public key before sending.
- Only your team's browsers can decrypt responses. SealForm's servers only store ciphertext.
- Built on audited, open cryptography: libsodium, Argon2id, XChaCha20-Poly1305 and X25519.
What still works
Privacy usually means giving things up. SealForm keeps the features: an AI builder that only sees your questions, Google Sheets sync from your browser, CSV export, teams, custom domains, and Slack, Microsoft Teams, Zapier and Make through a relay in your own Cloudflare account.
The honest trade-off
If everyone who can unlock a form loses their password, its responses can't be recovered. There's no back door, by design. Add teammates and keep your password in a password manager.
Templates to start from
- New Patient Intake Form
- Therapy Client Intake Form
- Legal Client Intake Form
- Confidential HR Complaint Form
- Research Study Consent Form
- Secure Contact Form
Questions
What can SealForm see?
Your form's questions (they're shown to anyone with the link), when a response arrived and how large it was, plus a salted hash of the sender's IP for spam limits. Never the answers or your keys.
Do respondents need to install anything?
No. Encryption happens in their browser automatically when they submit.
How can integrations work if SealForm can't read answers?
Either your own browser decrypts and sends them (Google Sheets, CSV), or a small relay you deploy to your own Cloudflare account does. SealForm only ever passes along ciphertext.
Try an encrypted form
Unlimited forms free. No card required.