Compare · Encryption, not features

Brun vs. general-purpose form builders, compared on encryption.

On the dimension that matters for sensitive inquiries — can the vendor read your submissions? — general-purpose form builders like Typeform, Jotform, and Formspree typically can, because they store submissions in a form the provider can read. Brun can't, by design: every submission is encrypted in the visitor's browser before it sends, and our servers only ever hold ciphertext. This isn't a feature face-off — those tools build and host forms well. It's the one question that decides what a leak would cost you.

How a general-purpose form builder compares to zero-knowledge intake.

“General-purpose form builders” here means tools like Typeform, Jotform, and Formspree as a category. We describe the typical model rather than per-product specifics, because each provider's capabilities differ and change. The decisive row is the first one.

 General-purpose form buildersBrun (zero-knowledge intake)
Can the vendor read your submissions?Yes — stored in a form the provider can readNo — by design, we only ever hold ciphertext
Where is the submission encrypted?On the provider's servers, after it arrivesIn the visitor's browser, before it sends
Who holds the decryption key?The providerOnly your team
What a vendor breach exposesReadable submissionsCiphertext only — useless without your key
What a subpoena to the vendor returnsReadable submissionsCiphertext only — we have no key to hand over
Can submissions be used to train AI?Possible, depending on termsNo — we can't read them, so we can't train on them
How you connect itBuild or embed the provider's formKeep your form; change the action + add one script tag
Where inquiries landProvider inbox / spreadsheet exportA simple lead board only your team can decrypt

What does it mean when a form tool calls itself “secure”?

Usually it means encrypted in transit (TLS) and encrypted at rest — both good, both standard, and neither one stops the vendor from reading your data. Those protect the provider from a stolen disk or a network sniffer; they don't stop the provider, an insider, or a subpoena from reading submissions, because the provider still holds the keys.

“Encrypted at rest” keeps the key with the vendor.

The data on disk is scrambled, but the vendor holds the key and can read everything to render your dashboard, run search, or power integrations. A breach of the vendor's systems exposes readable submissions.

End-to-end encryption keeps the key with you.

Brun encrypts each submission in the visitor's browser before it sends. The key never reaches our servers, so what we store is ciphertext. A breach, an insider, or a subpoena all see the same thing: gibberish. That's a CRM nobody can read, not even us.

When should you actually pick a zero-knowledge tool?

When the inquiries you collect would be a problem if someone else could read them — client matters, candidate pipelines, health or financial details, anything under a duty of confidentiality. For low-sensitivity forms, a general-purpose builder is genuinely fine; Brun is built for the cases where “the vendor can read it” is a dealbreaker.

  • Pick a form builder whenThe inquiries aren't sensitive and you want rich form design, logic, and templates.
  • Pick Brun whenA leaked submission would damage a client, a candidate, or your duty of confidentiality.
  • You don't rebuild anythingKeep your existing form; change the action and add one script tag to encrypt in the browser.

Form builder security, answered.

Is Typeform, Jotform, or Formspree end-to-end encrypted?

As of writing, general-purpose form builders like Typeform, Jotform, and Formspree typically store submissions in a form the provider can read — they encrypt data in transit and at rest, but the provider holds the keys. That is not end-to-end encryption: end-to-end means only you and your team can read the content, and the vendor cannot. Capabilities change, so verify each provider's current security documentation before deciding.

What is the most secure form builder?

For sensitive inquiries, the most secure choice is one where the vendor literally cannot read your submissions. Most form builders are secure in the conventional sense (TLS, encrypted at rest) but the provider still holds the keys. Brun is a zero-knowledge intake tool: each submission is encrypted in the visitor's browser before it sends, so what reaches our servers is ciphertext we can't open.

Which form tool can my vendor not read?

Brun. The contact-form submission is encrypted in the visitor's browser using a key only your team holds, and our servers store an opaque ciphertext envelope. There is no key on our side, so there is nothing for us — or an attacker, or a subpoena — to read. General-purpose form builders typically keep submissions readable to the provider.

Do I have to rebuild my contact form to switch to Brun?

No. You keep the contact form you already have and make two changes: point the form's action at your Brun intake URL, and add one intake.js script tag to the page. The script encrypts each submission in the visitor's browser before it leaves the device. Visitors see no Brun branding and the page exposes no API key or tenant ID.

Is a regular form builder good enough for sensitive intake?

It depends on what you collect. For low-sensitivity inquiries, a general-purpose form builder is fine. For inquiries you can't afford to leak — client matters, candidate pipelines, health or financial details — the question to ask is whether the vendor can read the submission. If the answer is yes, a vendor breach, insider, or subpoena can expose it. Brun is built so the answer is no.

Keep reading

Go deeper on secure intake.

See how the encryption works, what a secure intake form looks like in practice, why end-to-end encryption matters for the inquiries you collect, and why Brun signs no BAA and prohibits PHI. Prefer to see it written for your field? Browse secure intake by industry, or start from the overview on the homepage.

Inquiries only you can read

Switch the one thing that matters: who can read your intake.

Keep the form you have. Point it at Brun, add one script tag, and every submission is encrypted in the visitor's browser before it sends — stored as ciphertext we can't open and worked as leads on a board only your team can decrypt. Get started and go live the same day.

Brun vs. Typeform, Jotform & Formspree on Encryption — Brun CRM