Secure
Encrypted Forms

Every submission is encrypted at rest. Enable End-to-End Encryption for true zero-knowledge security — where even we can't read your data.

AES-256-GCM • Encrypted at Rest • Optional Zero-Knowledge E2EE • SSRF Protected

Built for Privacy-First Teams

Collect sensitive data without compromising on security.

🛡

Encrypted at Rest

All submission data is encrypted server-side with AES-256 before being stored. Even a raw database breach exposes only ciphertext. AI grading, analytics, and notifications work seamlessly.

🔒

Optional Zero-Knowledge E2EE

Enable End-to-End Encryption on any form for true zero-knowledge storage. Data is encrypted in the browser with a passphrase only you know — we can never read it. Server-side features like AI grading are disabled in this mode.

Shareable Form Links & Token Links

Every form gets a unique public URL. Paid plans unlock secure token links — one-time-use or time-limited URLs for controlled access to your forms.

📄

Embeddable Forms

Embed forms on any website with a simple iframe snippet. Domain whitelisting and CSP headers ensure only your approved sites can host your forms.

🤖

Anti-Cheat & Bot Protection

Multi-layered spam defense: invisible honeypot fields catch autofill bots, server-side timing analysis flags unnaturally fast submissions, and JavaScript fingerprinting detects headless browsers. Each signal is scored independently — submissions below the threshold are blocked automatically. This is a strong preventative layer, not a catch-all. We are continuously improving our detection methods to stay ahead of evolving bot techniques.

📎

Secure File Uploads

Accept files with real MIME-type detection (not just file extension), randomized storage names, PHP execution blocking, and per-tenant storage isolation with quota enforcement.

Custom SMTP

Send form notifications from your own mail server. SMTP passwords are encrypted at rest with AES-256. Full SSRF protection prevents internal network attacks.

📜

AI Grading & Audit Logs

AI-powered submission grading with configurable rubrics and per-plan usage limits. Complete audit trail for every action — login, form edit, submission, setting change — for full compliance visibility.

✍️

Agreements & E-Signatures

Create reusable agreement templates with placeholder variables, send them for electronic signature, and track status in real time. Full audit trail with timestamps, IP addresses, and signature data. Supports E2E encryption for zero-knowledge agreements.

Simple, Transparent Pricing

All prices listed in USD.

Every account starts with a free 7-day Starter trial. No credit card required.

Free

$0/mo

Get started with basic forms

  • 2 formsTotal active forms you can create and maintain
  • 50 submissions/moTotal form responses allowed per calendar month
  • 15 fields per formMaximum number of question fields on a single form
  • 100 MB storageTotal file upload storage space
Get Started Free

Basic

$10/mo

  • 7 formsTotal active forms you can create and maintain
  • 1,000 submissions/moTotal form responses allowed per calendar month
  • 75 fields per formMaximum number of question fields on a single form
  • 1,500 MB storageTotal file upload storage space
  • File uploadsAccept file attachments on form submissions
  • E2E encryptionOptional AES-256-GCM client-side encryption — true zero-knowledge mode where we can never see your data
  • Remove brandingHide the "Powered by E2E Forms" badge on your forms
  • Anti-cheat protectionTab switch detection, copy prevention, focus tracking, timers
  • Conditional logicShow or hide fields dynamically based on user answers
Get Started — $10/mo

Pro

$29/mo

For growing businesses

  • 25 formsTotal active forms you can create and maintain
  • 5,000 submissions/moTotal form responses allowed per calendar month
  • 200 fields per formMaximum number of question fields on a single form
  • 5,000 MB storageTotal file upload storage space
  • 1,500 AI gradings/moAI-powered automatic answer grading per month
  • File uploadsAccept file attachments on form submissions
  • E2E encryptionOptional AES-256-GCM client-side encryption — true zero-knowledge mode where we can never see your data
  • Agreements & e-signaturesSend digital agreements and collect legally binding electronic signatures with audit trails
  • Custom SMTPSend notification emails from your own mail server
  • Remove brandingHide the "Powered by E2E Forms" badge on your forms
  • Anti-cheat protectionTab switch detection, copy prevention, focus tracking, timers
  • IP loggingRecord respondent IP addresses with each submission
  • CSV exportDownload all form responses as a spreadsheet
  • Form analyticsSubmission volume charts, completion rates, and insights
  • WebhooksAutomatically send submission data to external URLs in real-time
  • Conditional logicShow or hide fields dynamically based on user answers
Get Started — $29/mo

Business

$79/mo

Unlimited everything

  • Unlimited formsTotal active forms you can create and maintain
  • Unlimited submissions/moTotal form responses allowed per calendar month
  • 300 fields per formMaximum number of question fields on a single form
  • 10,000 MB storageTotal file upload storage space
  • 3,000 AI gradings/moAI-powered automatic answer grading per month
  • File uploadsAccept file attachments on form submissions
  • E2E encryptionOptional AES-256-GCM client-side encryption — true zero-knowledge mode where we can never see your data
  • Agreements & e-signaturesSend digital agreements and collect legally binding electronic signatures with audit trails
  • Custom SMTPSend notification emails from your own mail server
  • Remove brandingHide the "Powered by E2E Forms" badge on your forms
  • Anti-cheat protectionTab switch detection, copy prevention, focus tracking, timers
  • AI gradingAutomatic AI-powered grading for quiz and assessment answers
  • IP loggingRecord respondent IP addresses with each submission
  • CSV exportDownload all form responses as a spreadsheet
  • Form analyticsSubmission volume charts, completion rates, and insights
  • WebhooksAutomatically send submission data to external URLs in real-time
  • Conditional logicShow or hide fields dynamically based on user answers
  • Priority supportFaster response times and dedicated support channel
Get Started — $79/mo

Business expanded

$100/mo

  • Unlimited formsTotal active forms you can create and maintain
  • Unlimited submissions/moTotal form responses allowed per calendar month
  • 500 fields per formMaximum number of question fields on a single form
  • 15,000 MB storageTotal file upload storage space
  • 7,000 AI gradings/moAI-powered automatic answer grading per month
  • File uploadsAccept file attachments on form submissions
  • E2E encryptionOptional AES-256-GCM client-side encryption — true zero-knowledge mode where we can never see your data
  • Agreements & e-signaturesSend digital agreements and collect legally binding electronic signatures with audit trails
  • Custom SMTPSend notification emails from your own mail server
  • Remove brandingHide the "Powered by E2E Forms" badge on your forms
  • Anti-cheat protectionTab switch detection, copy prevention, focus tracking, timers
  • AI gradingAutomatic AI-powered grading for quiz and assessment answers
  • IP loggingRecord respondent IP addresses with each submission
  • CSV exportDownload all form responses as a spreadsheet
  • Form analyticsSubmission volume charts, completion rates, and insights
  • WebhooksAutomatically send submission data to external URLs in real-time
  • Conditional logicShow or hide fields dynamically based on user answers
  • Priority supportFaster response times and dedicated support channel
Get Started — $100/mo

Questions & Answers

Can you read my form submissions?
Standard forms: Submission data is encrypted at rest on our servers using AES-256. We can decrypt it to provide features like AI grading, analytics, and email notifications — but a raw database breach would only expose ciphertext.

E2EE forms: With End-to-End Encryption enabled, submissions are encrypted in the browser using AES-256-GCM before data reaches any server. We store only ciphertext. Without your passphrase, nobody — including us — can decrypt submissions. This is true zero-knowledge.
What if I lose my E2EE passphrase?
E2EE-encrypted submissions become permanently unrecoverable. This is by design — it's what makes the system truly zero-knowledge. Standard (non-E2EE) forms are not affected. We strongly recommend storing E2EE passphrases in a password manager.
What happens if my payment fails?
Your account automatically falls back to the Free plan. All your forms and data remain intact, but premium features are disabled until billing is resolved. You'll see a banner in your dashboard to fix the issue.
Is E2E Forms open source?
Not at this time. While the architecture supports self-hosting, we have not open-sourced the code. This is something we may consider in the future.
How does the anti-cheat system work?
Our anti-cheat uses three independent layers: (1) an invisible honeypot field that catches bots filling every input, (2) server-side timing analysis that flags submissions made faster than humanly possible, and (3) JavaScript fingerprinting that detects headless browsers and scripts that don't execute JavaScript. Each signal is scored and weighted independently. Submissions that score below the threshold are automatically blocked. Note: this is a strong preventative measure and significantly reduces spam, but no anti-bot system is a 100% catch-all. We are continuously improving our detection methods.
What are token links?
Token links are special form URLs available on paid plans that provide controlled access. They can be set as one-time-use (link expires after a single submission) or time-limited (link expires after a set period). This is useful for surveys, invitations, or any scenario where you want to restrict who can submit.
How does AI grading work?
AI grading lets you define a rubric for your form, and each submission is automatically scored and given feedback based on your criteria. Usage is metered per plan (e.g., 5,000 or 10,000 graded submissions) because AI processing uses tokens that have real costs. You can monitor your usage in the dashboard. Plans can also be set to unlimited if needed.
Is all data encrypted at rest?
Yes. All submission data is encrypted at rest using AES-256 server-side encryption. E2EE-enabled submissions have an additional layer of client-side encryption that makes them unreadable even to us. SMTP passwords use AES-256-CBC. All data transfers use TLS 1.2+. Sessions use secure, HTTP-only cookies. We recommend using a VPN for additional privacy — we suggest ProtonVPN.
Do you track IP addresses?
By default, E2E Forms does not persistently log or track IP addresses of form respondents. However, if compelled by a valid court order, we may be required to enable limited logging. In such cases, affected users will be notified via email within 30 days of the request. We recommend using a VPN like ProtonVPN for additional anonymity.