Encrypted Forms That Even the Form Provider Cannot Read

Cyphorm encrypts answers in the respondent's browser before submission. The server stores the encrypted response payload; the form owner keeps the private key needed to read it.

Try Cyphorm Free See How Encryption Works

What is an encrypted form?

“Encrypted form” can refer to several different protections. HTTPS/TLS encrypts a connection while answers travel between a browser and a website. Encryption at rest protects stored files or disks. Both are valuable protections, but neither alone means the form provider lacks the keys or application access needed to process response contents.

Client-side or end-to-end encryption means the browser encrypts the answer before it is sent, using a key the service does not possess. The server can store and return ciphertext without having the private key needed to turn the response back into readable answers.

How Cyphorm encrypts a form response

  1. Respondent browser: collects the answer values and prepares the response payload locally.
  2. AES-GCM: generates a fresh 256-bit AES key and encrypts the response with a random 12-byte initialization vector.
  3. RSA-OAEP: wraps that one-time AES key with the form owner's public RSA key.
  4. Transmission and storage: sends the encrypted payload, wrapped AES key, and IV; the server stores those encrypted fields with response metadata.
  5. Owner browser: uses the owner's locally held private key to unwrap the AES key and decrypt the response in the browser.

Cyphorm uses the browser's Web Crypto API for these operations. The interactive demo shows the same local encryption function with harmless sample values and does not submit them.

What Cyphorm can and cannot see

Visible to the service

  • Account and form administration data
  • Form schema and field labels
  • Response timestamps, counters, and related operational metadata where applicable
  • Encrypted response payload, wrapped key, and IV

Not available from stored response data alone

  • Readable response answers
  • The owner's private decryption key through the intended application flow
  • Plaintext restored by the server from ciphertext alone

This is a statement about the intended application flow and stored server-side data. Because Cyphorm serves the browser code that performs encryption, a compromised or deliberately modified application could capture plaintext or keys. Users must trust the browser code they receive, their devices, and their key handling.

When encrypted forms matter

Provider-blind response collection can be useful when your workflow asks respondents to share confidential information. Review these examples and decide whether the key-management tradeoff fits your organization:

Encrypted form vs. secure form

“Secure form” is a broad description that can include TLS, access controls, spam prevention, encryption at rest, and operational safeguards. “Encrypted form” is more specific only when the product explains what is encrypted, where encryption happens, who controls the keys, and who can decrypt the answers. Ask about the properties that match your threat model instead of relying on a label.

Key recovery and the tradeoff

If the provider does not hold the private key, the provider also cannot recreate a lost key from stored responses. Cyphorm lets owners make separately protected backup files and QR recovery sheets. Keep backups in a place you control and test that they can be restored before collecting important responses.

Encrypted forms FAQ

What is an encrypted form?

An encrypted form protects submitted answers. With client-side encryption, a browser encrypts response contents before sending them, so the provider stores ciphertext instead of plaintext answers.

How do I encrypt an online form?

Choose a form product that encrypts the response in the browser before transmission and uses a key the provider does not hold. Then plan how authorized owners will securely access and back up that key.

Are online forms encrypted?

Many use HTTPS/TLS, and some encrypt stored data at rest. Those controls do not automatically mean responses are end-to-end encrypted or unreadable to the provider.

Can a form provider read my responses?

It depends on the product and mode. A product that only encrypts transport or storage may still process plaintext; a client-side design can keep response contents encrypted from the provider, subject to its browser-code and key-management trust boundary.

Does HTTPS make a form end-to-end encrypted?

No. HTTPS protects data while it travels to the service. The service may still decrypt or process it after receipt.

What happens if I lose my private key?

Restore it from a backup file or QR recovery sheet. If every copy is lost, the encrypted responses cannot be decrypted; the provider cannot reconstruct the key from ciphertext.

Can Cyphorm read encrypted submissions?

Cyphorm does not receive the owner's private key through the intended application flow, so stored response data alone cannot be decrypted by the service. Users still need to trust the browser code delivered by the site.