Privacy · Forms · Encryption
Can Form Builders Read Your Submissions?
The answer depends on how a product handles response keys—not just whether a page says “encrypted.”
· Updated · By the Cyphorm Team
Online forms often handle information people would not want exposed broadly: client details, internal feedback, health information, or reports. To understand who can read those answers, ask where they are encrypted and who has the keys to decrypt them.
Three questions to ask about encryption
- Is the connection protected? HTTPS/TLS encrypts traffic between a browser and a service endpoint.
- Is stored data encrypted? Encryption at rest protects stored media and backups against certain types of exposure.
- Who holds the response decryption key? End-to-end or client-side encryption can keep the provider from decrypting response contents if the key is held only by the intended users.
These protections are not interchangeable. A provider can use strong transport and storage safeguards and still need to process readable answers to provide its service. That is not automatically a flaw; it is a choice about the trust model and workflow.
How to evaluate a specific form product
Products differ, and individual products can offer multiple modes. Read current first-party documentation for the exact feature you plan to use. Check where encryption happens, who controls the key, whether the provider can reset it, which exports or integrations receive readable answers, and what happens when you lose access.
- Google Forms: what Google says about transit and storage encryption
- Typeform: published security, data-storage, and GDPR materials
- Jotform: Encrypted Forms 2.0 access codes and feature tradeoffs
- BlockSurvey: another privacy-first encrypted survey product
What client-side encryption changes
With client-side encryption, the browser encrypts response answers before sending them. The service can receive ciphertext and still handle data needed to operate the form, such as account information, form schema and field labels, response timing, or counters. Ask the vendor which metadata remains visible and how the private key is managed.
Cyphorm encrypts response contents in the respondent's browser using a fresh AES-GCM key wrapped with the form owner's RSA public key. The owner decrypts locally with the private key. This means stored server-side response data alone does not provide readable answers; it does not protect against compromised or deliberately changed browser code that could capture plaintext before encryption.
The homepage demo uses the actual local encryption function with temporary sample values and does not send or store them.
When provider access matters
A provider-blind design may be useful when answers contain information that should be readable only by designated people in your organization. Consider not only the vendor but also your own access controls, respondent notices, device security, retention, backups, and any exports to other services.
Explore client intake risks and safeguards, encrypted employee feedback, and sensitive reporting channels.