Encrypted forms

Encrypted forms that still tell you where the lead came from.

Your form emails you the submission in plain text. A name, a phone number, whatever someone typed into the message box, sitting in an inbox. Encryption fixes that, and in most form tools it takes your reporting with it. Not here.

Every submitted value encrypted Encrypted in transit and at rest Source and journey stay readable

Integrates with the tools you already use.

Salesforce
HubSpot
Pipedrive
Gmail
Twilio
Google Ads
Gravity Forms
Jotform
Webflow
Wix
Calendly
Typeform
The mechanics

Where a form submission is readable

A form submission passes through more hands than people expect. Each stop is a place where the values sit as ordinary text.

The first leg is the easy one. The browser sends the submission to a server, and that trip is encrypted in transit on any form worth using. It has been for years. That is not where the interesting part is.

The interesting part is everything afterwards. The submission gets written down. It gets emailed to you, and to whoever else is on the notification list, and then forwarded to the one person who was not. It ends up in a spreadsheet somebody exported in March. It syncs into a CRM that four people can log into from their phones.

Every one of those is a copy, and a copy is only as protected as the place holding it.

An encrypted form narrows that considerably. The values are encrypted before they are stored, so the copy at rest is not readable text. What you then choose to forward is still yours to decide, which is the part most pages on this subject leave out.

Worth separating two things people use interchangeably. Protection in transit covers the journey from the browser. Form encryption covers what is kept at the other end. You want both, and only one of them is automatic.

What happens to it

What Lead Source does with what people type

  • Every value someone types into your form is encrypted before it is stored. Not only the email address. The phone number, the message box and the custom fields you added last week all go the same way.
  • It is encrypted in transit on the way in, and encrypted at rest once it lands. Two different jobs, both done.
  • Access is controlled at the database rather than in application code, so your leads sit apart from everybody else’s by default rather than by careful programming.
  • You can also decide that a field should not be kept. Switch it off and its value is dropped on the way in, before anything writes it down, on every submission after you make the change. Password fields are dropped on every form, whether you switch anything off or not.
  • Spam and bot protection runs on the same path. Rate limits, honeypot detection and origin checks all sit in front of storage. The junk that arrives at three in the morning does not become part of your lead list.
  • Your data stays yours throughout. Export it, delete it, take it somewhere else.

Not built the form yet?

Everything on this page is on by default in a Lead Source form. Starting from a blank page? Free form templates cover most industries.

See lead capture forms →
The tradeoff nobody mentions

Encryption usually costs you the reporting. Not here.

Turn encryption on in most form tools and a list of other features turns off with it.

Jotform publishes its own list. Form reports, approval flows, autoresponder emails, save and continue, PDF downloads, and every integration except payment gateways. Zapier included. Jotform documents all of it. Zoho Forms puts entries, reports, approvals and tasks behind one access code, and locks notifications, exports, integrations and webhooks by default.

Neither vendor is doing anything wrong. The reason is structural. A platform that cannot read a submission cannot report on it, route it, or hand it to Zapier. Those features are not being withheld from you. They have nothing to work with.

Lead Source does not hit that wall, and the reason is worth a minute.

Think about what attribution data actually is. The campaign that brought the visitor. The referrer. The click ID on the URL they arrived with. The pages they read before they filled anything in. None of that was typed by the person filling in the form. It was collected around them, from the page, so it lands in its own columns rather than inside the encrypted part with the contact details.

So the two halves come apart cleanly. The contact details lock. The source stays readable.

A worked version. Someone clicks a Google Ads listing for a managed services firm, lands on /managed-it, reads /pricing, and submits the form on /contact three days later. You get a lead you can act on: Google Ads, that campaign, those three pages, in that order. What is not sitting in the report is their phone number. That is the point.

Encrypt the sensitive part. Keep the report that tells you which spend paid for it. If you want the longer version of how the source gets captured in the first place, form tracking covers it.

What encryption switches off

The same tradeoff, written down.

Each vendor documents its own list. This is theirs, not ours.

JotformZoho FormsLead Source
Form reportsDisabledBehind an access codeAvailable
Approval flowsDisabledBehind an access codeNot offered
Autoresponder and notification emailsDisabled or not customisableLocked by defaultAvailable
IntegrationsPayment gateways onlyLocked by defaultAvailable
Source and campaign on the leadNot offeredNot offeredAvailable
Who asks for this

Who actually needs an encrypted form

Managed service providers

A prospect’s intake form names their current provider, their contract end date and how many endpoints they run. That is competitive intelligence about somebody else’s business, sitting in your inbox because you asked for it. Most MSP enquiry forms collect all three on the first screen.

Law firms

The first contact form is usually where somebody describes the matter. By the time they press submit you are holding something they have told very few people, and you are holding it before they are a client.

Insurance agencies

Date of birth, licence number, prior claims, sometimes medical detail. An insurance quote form collects more identifying information in ninety seconds than most businesses hold about a customer in a year.

The pattern is the same in all three. The form is the earliest point in the relationship and it collects the most sensitive thing the relationship will ever produce. Everything after it is a copy of that.

If you are building the form itself rather than protecting one you already have, lead capture software is the place to start.

Common questions

Encrypted forms, answered.

What is an encrypted form?

An encrypted form is a form whose submitted values are turned into unreadable data before they are stored. A copy of the stored data is not a copy of your leads. The person filling it in sees an ordinary form. The change is in what happens after they press submit.

What is end to end encryption?

End to end encryption means only the two ends of a conversation can read what passes between them, and nothing carrying it in between can. Lead Source works differently, and it is worth being precise about how. Your submissions are encrypted in transit and encrypted at rest, and Lead Source can decrypt them for you. That is what makes search, export and your notification email work at all.

What is the difference between a secure form and an encrypted form?

Protection in transit stops anyone reading a submission on its way from the browser to the server, and every reputable form does that already. An encrypted form goes further and protects the copy that gets stored. Most of what people mean by secure forms covers both, plus access control, spam handling and what you collect in the first place.

Is form data encrypted when it is stored?

Yes. Every value someone submits is encrypted before it is stored, not only the email address. The phone number, the message and every custom field you added go the same way.

Can I still see where a lead came from if the form is encrypted?

Yes. The source, the campaign and the journey were never typed into the form, so encrypting the submission does not take them away. You see that the lead came from Google Ads and read three pages first. You see the contact details when you open the lead itself.

Do I lose my reporting when I turn encryption on?

Not with Lead Source. Most encrypted form tools switch reporting off when you switch encryption on, because a platform that cannot read a submission cannot report on it. Lead Source reports on the source and the journey, and neither of those was ever part of the submission.

Does encryption change anything for the person filling in the form?

No. They see the same form and fill it in the same way. Encryption happens after they press submit, so there is no extra step and nothing for them to install.

What happens to a field I do not want stored at all?

It is never written down. Switch a field off and its value is dropped on the way in, before storage, on every submission after you make the change. Password fields are dropped on every form, whether you switch anything off or not.

Lock the submission. Keep the report.

Every value encrypted, and the source still readable on every lead that arrives.

Start free

Free to start ยท no card