Security
Spam & abuse
Every submission runs through honeypot checks, per-form rate limiting, optional captcha (Cloudflare Turnstile or reCAPTCHA), and your custom keyword rules before it's accepted.
Secret detection
If a submission looks like it contains an API key, token, or password, we flag it so you can rotate the credential — real secrets don't belong in form fields.
Outbound webhooks
Webhook URLs must use HTTPS and are validated to prevent requests to private or internal network addresses (SSRF protection). Generic webhooks are signed so you can verify authenticity.
Uploads
Uploaded files are size-limited and screened against a denylist of dangerous types. Downloads are authenticated and scoped to your workspace.
Data protection
Set retention windows per site, erase a person's data on request (DSAR), and review an audit log of every access. See our Privacy policy and Data Processing Agreement.