Patient intake forms encrypted before they’re submitted
A patient intake form collects some of the most sensitive data there is — symptoms, history, medication, mental-health context. Running it through a generic form tool means a readable copy of that on a third party’s servers.
ShieldFive Secure Forms seals each patient’s answers to your keys in their browser. The clinic decrypts responses in-house; we only ever hold ciphertext, so there is no readable intake to breach.
No readable medical history on our side
Symptoms, medication and history are encrypted to the clinic’s public key on the patient’s own device. What we store is ciphertext — there is no readable record for a breach to expose, and none for us to be asked to produce.
Sealed for the life of the record
Answers are sealed with a hybrid of ML-KEM-1024 and X25519 from the open-source @shieldfive/crypto core. Medical records are kept for decades, which is precisely the horizon "harvest now, decrypt later" is aimed at.
Special-category data, EU-hosted
Health data carries the strictest handling duties under GDPR. Ciphertext and metadata stay in the EU, with a data-processing agreement on every seat — a straight answer for the clinic’s own records of processing.
The questions stay private too
The form’s title and questions are encrypted with a key in the link, so a questionnaire about a specific condition is not readable on our servers either. Anyone with the link sees the questions; a link without its key is refused.
Collect answers you can’t leak
Build a form, share the link, and every answer is sealed to your keys in the respondent’s browser — no account for them.
Build a secure form — freeFree for 1 active form at a time · unlimited at €29 per seat · respondents never pay
Questions
- Is this suitable for health data under GDPR?
- Answers are encrypted to your keys before submission and stored only as ciphertext in the EU, with a data-processing agreement included. We never hold your keys. The honest limit: we serve the JavaScript, so the property is “encrypted in the browser, ciphertext at rest”, not a claim that no server could ever be subverted.
- Does the patient need an account?
- No. Patients open the link and fill the form — no account, no app. Only your clinic needs a ShieldFive account.