KYC and financial intake without a readable copy in the cloud
KYC and financial-onboarding forms collect identity details, income, source-of-funds — a concentrated target. A generic form tool keeps all of that readable on someone else’s servers.
ShieldFive Secure Forms seals each answer to your keys in the applicant’s browser, so the intake is ciphertext to us. You decrypt it in-house when you process the application.
A concentrated target, encrypted
Identity details, income and source-of-funds answers in one submission are close to a complete financial profile. Each is sealed to your public key on the applicant’s device, so the pile a breach would be aimed at simply is not readable where it sits.
Post-quantum, because files outlive the check
Answers are sealed with a hybrid of ML-KEM-1024 and X25519 via the open-source @shieldfive/crypto core. KYC records are retained for years after onboarding, so the encryption is chosen for that horizon rather than for today.
EU-hosted, DPA on every seat
Ciphertext and metadata stay in the EU, with a GDPR data-processing agreement included on every seat — one fewer gap between your AML file and your data-protection file.
Cap it, then close it
Each form carries a response cap and can be closed at any time. A closed form stops accepting new answers while everything already collected stays readable to you — useful when an onboarding window is meant to end.
Collect answers you can’t leak
Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.
Build a secure form — freeFree for 1 active form at a time · unlimited at €29 per seat · respondents never pay
Questions
- Is this strong enough for KYC data?
- Answers are sealed with a post-quantum hybrid (ML-KEM-1024 + X25519) to your keys before submission and stored only as ciphertext in the EU. We never hold the keys — a stronger posture than a form host that retains readable copies. The honest limit: we serve the JavaScript that does the encrypting, so the guarantee is “encrypted in the browser, ciphertext at rest”, not a claim that no server could ever be subverted.
- Can I limit how many responses a form accepts?
- Yes. Each form has a response cap and can be closed at any time; a closed form stops accepting new answers while existing ones stay readable to you.