Secure online forms, and how to tell if yours is one.
You collect names, phone numbers and whatever people type into the message box. Most people worry about the trip from the browser to the server. The trip is fine. The risk is every copy that exists by Friday.
Integrates with the tools you already use.
Where a form leaks, and it is rarely the form
A form is secure when every stage between the visitor typing and you reading is protected. Most audits look hard at the first stage and wave the rest through.
The notification email
A submission arrives as plain text in an inbox. Then it gets forwarded to the person who handles quotes, who forwards it to the tech who is going to do the work. Three inboxes, none of them yours, all of them searchable by whoever has the login.
The export nobody deleted
Somebody pulled a spreadsheet for a report in March. It is in a downloads folder on a laptop that has since been to a conference.
The shared login
One account, four people, one password in a group chat. That is a common way form data gets seen by someone it was not meant for. No amount of protection on the form itself touches it.
Asking for more than you need
Every field is a liability you volunteered for. A date of birth you never look at is still a date of birth you are holding.
No spam handling
A form with nothing in front of it fills with junk. Real enquiries get lost in it, and the person doing the sorting stops reading carefully by about the fortieth one.
Four of those five are about what happens after the submission lands. That is the useful thing to take from this section.
How Lead Source protects a submission
- Submissions are protected from the moment they are sent. Protected on the way in, and protected once they land, which are two different jobs and both get done.
- Access is controlled at the database rather than in application code. Your leads sit apart from everybody else’s by default, not because somebody remembered to write the check.
- Nothing is left behind in the visitor’s browser. No cookies, no client-side storage. The tracking layer sits outside cookie-consent scope.
You decide what gets kept. Switch a field off and its value is dropped on the way in, before anything writes it down, on every submission after you make the change. Password values are dropped on every form whether you ask or not.
Spam and bot protection sits in front of all of it. Rate limits, honeypot detection and origin checks run before storage, so your lead list stays a lead list.
Your data is yours throughout. Export it, delete it, take it elsewhere.
For the detail on how the stored copy is protected, encrypted forms covers it properly. If your obligations are the pressing part, start with GDPR compliant forms.
Not built the form yet?
Everything on this page is on by default in a Lead Source form. Starting from a blank page? Free form templates cover most industries.
Protecting the lead, and still knowing where it came from
Locking a form down usually costs you information. That is the trade every tool in this category asks you to make, and most buyers make it without arguing.
It is worth arguing about. The reason the trade exists is that a platform which cannot read a submission cannot report on it either. Fair enough. The mistake is assuming the report you want is made of submission data.
It is not. The campaign that brought the visitor, the referrer, the click ID on the URL they arrived with, the pages they read before they filled anything in. Nobody typed any of that into your form. It was collected around them, from the page, and it is kept separately from what they submitted.
So the two halves come apart. The personal details lock. The source stays readable.
Concretely. Someone clicks a Google Ads listing for a managed services firm, lands on /managed-it, reads /pricing, and fills in the form on /contact three days later. Your report says Google Ads, that campaign, those three pages, in that order. Their phone number is not in the report, because it does not need to be.
That is the whole argument for doing both at once. You protect the thing that needs protecting, and you keep the thing that tells you which spend paid for it. If the capture side is new to you, form tracking is the longer explanation, and you can test what your own form records right now.
Who needs to care about this more than most
Managed service providers
Your enquiry form asks who they use now, when the contract ends, and how many endpoints they run. That is a competitor’s account detail, sitting in your inbox, because you asked for it and they told you. Most MSP enquiry forms collect all three on the first screen.
Law firms
The contact form is where somebody describes the matter, usually in more detail than they meant to. You are holding it before they are a client and before anything is privileged.
Insurance agencies
Date of birth, licence number, prior claims, sometimes health detail. An insurance quote form collects more identifying information in ninety seconds than most businesses hold about a customer in a year.
The common thread is timing. The form runs at the point where somebody has decided to trust you but has no evidence yet that they should. Protecting it is the first thing you do for them, and they will never see it.
If you are choosing the form itself rather than fixing one you have, lead capture software is the place to start. Secure lead capture covers the run from submission to CRM record.
Secure forms, answered.
What is a secure form?
A secure form is one where the submission is protected at every stage between the visitor typing and you reading it. That covers the trip from the browser, the copy that gets stored, who can open it, and what you asked for. A form that only protects the first of those is doing about a quarter of the job.
How do I know if my form is secure?
Follow one submission all the way through and write down every place it stops. The inbox it emails, the people it gets forwarded to, the spreadsheet somebody exported, the CRM record, the login that opens all of it. Then ask which of those you actually control.
What makes a contact form insecure?
Usually not the form. The common causes sit elsewhere. A plain text notification email that gets forwarded around, an old export in somebody’s downloads folder, a shared login. Then fields nobody ever reads, and no spam handling in front of any of it.
Is it safe to collect personal details through a website form?
Yes, when the submission is protected on the way in, protected once stored, and only openable by the people who need it. That is a normal thing for a business to do. The care goes into what happens after it lands, which is the part that tends to get less attention.
Does a secure form slow anything down for the visitor?
No. They see an ordinary form and fill it in the same way. Everything described here happens after they press submit, so there is nothing extra for them to do and nothing to install.
Can I stop a form storing a field I do not want?
Yes. Switch the field off and its value is dropped on the way in, before anything writes it down, on every submission after you make the change. Password values are dropped on every form regardless. The cheapest security improvement available is asking for less.
Do I lose my marketing reporting if I lock the form down?
Not with Lead Source. The source, the campaign and the pages someone read were never part of what they typed into the form, so protecting the submission does not remove them. You still see which spend produced the lead.
Protect the submission. Keep the report.
Every enquiry protected from the moment it is sent, with the source still attached.
Start freeFree to start · no card











