A Formstack alternative that encrypts answers before submission

Formstack sells to regulated industries and offers plenty of compliance features, but like any hosted form tool it holds your submissions in a form it can read. If your objection is exactly that the provider can read the data, more compliance checkboxes don’t fix it.

ShieldFive Secure Forms closes that gap: each response is sealed to your keys in the respondent’s browser, so the intake is ciphertext to us. It’s a narrower tool, but on the property that matters for sensitive data it doesn’t compromise.

A control, not a control description

Compliance features describe how a provider promises to handle readable data. Encrypting each answer to your public key on the respondent’s device removes the readable data instead — a property of the system rather than a clause you audit annually.

Post-quantum, on every form

Responses are sealed with a hybrid of ML-KEM-1024 and X25519 via the open-source @shieldfive/crypto core. You can read the exact library that does it before you put regulated intake through it.

EU-hosted, DPA on every seat

Ciphertext and metadata stay in the EU, with a GDPR data-processing agreement included on every seat. One fewer sub-processor chain to document in a record of processing activities.

The questions are encrypted too

A form’s title and questions are sealed with a key in the link, so the subject of a sensitive intake is not readable on our servers. Anyone holding the link can read the questions; a link without its key is refused.

Collect answers you can’t leak

Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.

Build a secure form — free

Free for 1 active form at a time · unlimited at €29 per seat · respondents never pay

Questions

Is this a full workflow platform like Formstack?
No. Secure Forms does encrypted intake — build a form, collect sealed answers, decrypt them. It doesn’t replace document workflows or e-sign. What it adds is that responses are encrypted before submission, and the provider holds only ciphertext, never the keys.
Can my whole team read the responses?
Yes. Add seats and the firm’s decryption identity is sealed to each member’s account, so colleagues share one response inbox without sharing personal keys.