A Microsoft Forms alternative that encrypts responses in the browser

Microsoft Forms is convenient inside the Microsoft ecosystem, but responses sit in Microsoft 365 in a form Microsoft can read, often processed outside the EU. For confidential surveys — health, HR grievances, whistleblowing — that’s the wrong posture.

ShieldFive Secure Forms seals each answer to your keys on the respondent’s device and stores only ciphertext in the EU. The platform running the form never holds your keys.

Not another copy inside the tenant

A Microsoft Forms response lands in a tenant your admins, your compliance tooling and Microsoft can all reach. Here the answer is encrypted to your public key in the respondent’s browser, so what is stored is ciphertext nobody on our side or yours can open without your key.

EU-hosted, under EU jurisdiction

Ciphertext and metadata stay in the EU, with a GDPR data-processing agreement on every seat. For a grievance or whistleblowing channel, "where is it processed and who could be compelled to produce it" is not a hypothetical question.

Even the questions are encrypted

The form’s title and questions are encrypted with a key that lives in the link, so a survey about harassment or redundancies is not sitting readable on our servers either. Anyone with the link can read the questions; a link without its key is refused.

No sign-in, which is the point

Microsoft Forms often ties a response to an identity in the tenant. Here the respondent opens a link and submits with no account at all — the difference between a channel people will use for something sensitive and one they will not.

Collect answers you can’t leak

Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.

Build a secure form — free

Free for 1 active form at a time · unlimited at €29 per seat · respondents never pay

Questions

Where are responses stored?
Ciphertext is stored in the EU, and a GDPR data-processing agreement is included on every seat. Because answers are sealed to your keys before submission, we process only ciphertext and never hold your keys.
Is this good for anonymous or sensitive surveys?
Yes. Respondents submit with no account, and the answers reach us only as ciphertext — so there is no server-side copy of the responses to leak or subpoena in plaintext.