Jotform Encryption: Encrypted Forms 2.0 vs Cyphorm

Jotform offers an end-to-end encrypted form option. This comparison focuses on how its per-form access-code model differs from Cyphorm's account-level public and private key model.

Is Jotform encrypted?

Jotform provides Encrypted Forms 2.0 as an option that form owners enable for individual forms. Jotform says the feature encrypts submissions before they reach its servers, uses the Web Crypto API, and prevents Jotform from reading the encrypted submissions. Owners set an access code for each form; Jotform says a forgotten code cannot be recovered and the data is then inaccessible.

That is a meaningful privacy feature. It should not be confused with Jotform's ordinary forms or with the older encryption mode that may still apply to some existing forms. Check the settings and current documentation for the specific form you are evaluating.

Jotform's Encrypted Forms guide ยท Jotform Encrypted Forms 2.0 overview

How the encryption models differ

QuestionCyphormJotform Encrypted Forms 2.0
Key modelAn account-level RSA public/private keypair. Respondents encrypt to the owner's public key.An owner-created access code for each encrypted form.
Where the private secret is keptThe private key is stored in the owner's browser, protected locally, and is not uploaded through the intended application flow.The access code is required to open encrypted submissions; Jotform says it cannot read the encrypted data.
RecoveryThe owner can restore a private key from a separately protected backup file or QR recovery sheet. Cyphorm cannot recreate a lost key from stored submissions.Jotform says an access code cannot be recovered or reset; forgetting it means losing access to those submissions.
Encrypted-form workflowFocused on collecting encrypted answers and decrypting them in the owner's browser.Jotform's encrypted mode disables or restricts some features, reports, and integrations; payment gateways are an exception noted in its guide.

Both models depend on users protecting their secrets and trusting the browser application they run. Cyphorm's stored-ciphertext design protects against passive access to stored response data; it does not remove the need to trust the code served to the browser.

Where Jotform is stronger

Jotform is a broad form-building platform with a wide set of form workflows. If you need its broader builder features, reports, approval flows, or integrations, compare the exact feature list for the form mode you intend to use. Jotform's own encryption guide lists capabilities that become unavailable or limited when Encrypted Forms is enabled, so check those tradeoffs before switching it on.

Where Cyphorm is different

Cyphorm is built around an owner-held account key rather than a separate access code for each form. The public key can encrypt submissions in the respondent's browser; the owner unlocks the private key locally. Backup files and QR recovery sheets make the owner's recovery plan explicit, while leaving Cyphorm unable to reconstruct a lost private key.

Choose Cyphorm when provider-blind collection and a clear owner-controlled key workflow are central requirements. See how Cyphorm handles encrypted forms or try the client-side encryption demo.

Jotform encrypted forms FAQ

Is Jotform Encrypted Forms 2.0 end-to-end encrypted?

Jotform describes it as end-to-end encryption using the Web Crypto API and says Jotform cannot read submissions encrypted with this feature. This statement is about Encrypted Forms 2.0, not every Jotform form.

Can Jotform recover a lost Encrypted Forms 2.0 access code?

No. Jotform's documentation says the access code cannot be recovered or reset. Keep a secure copy before collecting responses.

How is Jotform encryption different from Cyphorm?

Jotform uses a separate access code for each encrypted form. Cyphorm uses an account-level RSA keypair, with private-key backups managed by the account owner.