A Formstack alternative that encrypts answers before submission
Formstack sells to regulated industries and offers plenty of compliance features, but like any hosted form tool it holds your submissions in a form it can read. If your objection is exactly that the provider can read the data, more compliance checkboxes don’t fix it.
ShieldFive Secure Forms closes that gap: each response is sealed to your keys in the respondent’s browser, so the intake is ciphertext to us. It’s a narrower tool, but on the property that matters for sensitive data it doesn’t compromise.
A control, not a control description
Compliance features describe how a provider promises to handle readable data. Encrypting each answer to your public key on the respondent’s device removes the readable data instead — a property of the system rather than a clause you audit annually.
Post-quantum, on every form
Responses are sealed with a hybrid of ML-KEM-1024 and X25519 via the open-source @shieldfive/crypto core. You can read the exact library that does it before you put regulated intake through it.
EU-hosted, DPA on every seat
Ciphertext and metadata stay in the EU, with a GDPR data-processing agreement included on every seat. One fewer sub-processor chain to document in a record of processing activities.
The questions are encrypted too
A form’s title and questions are sealed with a key in the link, so the subject of a sensitive intake is not readable on our servers. Anyone holding the link can read the questions; a link without its key is refused.
Collect answers you can’t leak
Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.
Build a secure form — freeFree for 1 active form at a time · unlimited at €29 per seat · respondents never pay
Questions
- Is this a full workflow platform like Formstack?
- No. Secure Forms does encrypted intake — build a form, collect sealed answers, decrypt them. It doesn’t replace document workflows or e-sign. What it adds is that responses are encrypted before submission, and the provider holds only ciphertext, never the keys.
- Can my whole team read the responses?
- Yes. Add seats and the firm’s decryption identity is sealed to each member’s account, so colleagues share one response inbox without sharing personal keys.