Patient intake forms encrypted before they’re submitted

A patient intake form collects some of the most sensitive data there is — symptoms, history, medication, mental-health context. Running it through a generic form tool means a readable copy of that on a third party’s servers.

ShieldFive Secure Forms seals each patient’s answers to your keys in their browser. The clinic decrypts responses in-house; we only ever hold ciphertext, so there is no readable intake to breach.

No readable medical history on our side

Symptoms, medication and history are encrypted to the clinic’s public key on the patient’s own device. What we store is ciphertext — there is no readable record for a breach to expose, and none for us to be asked to produce.

Sealed for the life of the record

Answers are sealed with a hybrid of ML-KEM-1024 and X25519 from the open-source @shieldfive/crypto core. Medical records are kept for decades, which is precisely the horizon "harvest now, decrypt later" is aimed at.

Special-category data, EU-hosted

Health data carries the strictest handling duties under GDPR. Ciphertext and metadata stay in the EU, with a data-processing agreement on every seat — a straight answer for the clinic’s own records of processing.

The questions stay private too

The form’s title and questions are encrypted with a key in the link, so a questionnaire about a specific condition is not readable on our servers either. Anyone with the link sees the questions; a link without its key is refused.

Collect answers you can’t leak

Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.

Build a secure form — free

Free for 1 active form at a time · unlimited at €29 per seat · respondents never pay

Questions

Is this suitable for health data under GDPR?
Answers are encrypted to your keys before submission and stored only as ciphertext in the EU, with a data-processing agreement included. We never hold your keys. The honest limit: we serve the JavaScript, so the property is “encrypted in the browser, ciphertext at rest”, not a claim that no server could ever be subverted.
Does the patient need an account?
No. Patients open the link and fill the form — no account, no app. Only your clinic needs a ShieldFive account.