Learn · For consultants & boutique agencies
Client intake software for consultants who can’t afford a leak.
Brun is client intake software for consultants and boutique agencies that treats a prospect’s inquiry the way your NDAs already do. Each submission is encrypted in the prospect’s browser before it sends, so the vendor is left with an opaque envelope it has no key to open. Only your firm holds that key, so only your firm can read the inquiry.
A secure client intake form wired to a simple CRM turns confidential deal flow, RFP scope, and strategy into leads nobody outside your firm can read. This page shows why an ordinary consulting intake form exposes every inquiry, and how Brun is different.
What is secure client intake software for consultants?
Secure client intake software is a consulting client intake form with browser-side encryption: each submission is sealed before it leaves the prospect’s machine. The acquisition target, the turnaround plan, the budget — the readable version stays on their device, and a vendor’s database only ever receives ciphertext.
For a consulting or agency practice, that matters most because most inquiries already fall under an NDA or a duty of confidentiality before you’ve even scoped the engagement. The secure intake page walks through exactly how that guarantee holds up.
Why does an ordinary consulting intake form put you at risk of breach?
Consultants capture highly confidential prospect information — deal flow, strategy, RFP scope — through generic web forms and CRMs where the vendor, and anyone who breaches the vendor, can read every submission.
The CRM vendor can read every confidential word
The form vendor’s staff, whatever tools they’ve connected, and anyone who breaches their database all see the same readable version of a matter your NDA already promised to keep confidential:
- Prospect-disclosed NDA terms and the existence of a confidential engagement
- Deal flow and M&A target names shared in an initial inquiry
- Proprietary client strategy, competitive positioning, and internal pain points
- RFP details, scope, and budget/authority disclosures
- Names and roles of stakeholders and decision-makers at the prospect’s company
A leaked inquiry can be an NDA breach
Consultants and agencies routinely operate under signed, often mutual, NDAs and a professional duty of confidentiality. A leaked or vendor-readable intake submission can constitute an NDA breach, create contractual liability, and trigger GDPR/data-protection exposure for inquiries from EU clients — which is what makes a form the vendor literally cannot read a direct control.
How does Brun keep a confidential inquiry unreadable?
From a prospect’s screen to a lead on your board, ciphertext the whole way.
Sealed in their browser.
The form itself doesn't change: same fields you already ask — business challenge, scope, stakeholders, budget — same layout, no Brun branding, no account or app to install. They describe the engagement and hit send. Before it ever leaves the device, a small script encrypts the submission with your workspace's public key — a key that can seal a message shut but has no power to unseal it. What reaches the network is already ciphertext; the deal names, RFP scope, and strategy never travel in the clear.
Screened. Never opened.
Once the envelope passes a structural check, we accept it and keep it on file as ciphertext — nothing else. We hold no key capable of opening it, so an NDA-covered detail stays unreadable everywhere but one place: the device of the person you trust to open it.
We store gibberish.
stored on our serversSealed from our view: every prospect inquiry, lead, and internal note. Visible to us only where it has to be: your account email, billing status, and any support request you file.
Unlocked on your board.
You open your inbox and your own browser does the unlocking — the key stays inside your firm. A confidential inquiry is readable on the consultant's device that decrypted it, and on no other machine anywhere. Once decrypted, the inquiry is re-sealed under your workspace key and lands on a simple CRM board — a lead you can qualify, assign to a partner, and move from New to Won through your pipeline.
The script on your contact page holds no decryption power — it carries only a public intake handle, meaningless without the key your team keeps. Full mechanics →
Ordinary consulting intake form vs. zero-knowledge intake.
For a consulting practice, the real question is whether your NDA promises survive contact with your own intake form. An ordinary form hands the vendor a readable copy regardless of what you signed; Brun keeps that promise by never storing anything readable in the first place.
| Ordinary consulting intake form | Brun zero-knowledge intake | |
|---|---|---|
| Where it's encrypted | In transit only (TLS), then decrypted on arrival | In the prospect's browser, before it sends |
| Can the CRM vendor read the inquiry | Yes — deal names and RFP scope land in their plaintext database | No — they store ciphertext only |
| What a vendor breach exposes | Readable deal flow, strategy, and stakeholder names | Ciphertext only |
| What a subpoena to the vendor returns | Readable confidential inquiries | Ciphertext only |
| NDA / confidentiality posture | Vendor is a third-party recipient of NDA-covered content | Vendor is out of scope — it never holds the plaintext |
| Setup | Often a rebuild or a hosted form you must migrate to | Two changes to the form you already have |
Do I have to rebuild my form or move off my site?
No. You keep the consulting intake form and the website you already have. Connecting it to secure intake is exactly two changes — no rebuild, no hosted page, no backend work, and nothing your prospects can see.
- <form action="/your-old-endpoint">
+ <form action="…/public/intake/your-handle">
+ <script src="…/intake.js">Consulting client intake questions, answered.
What is the best client intake software for consultants who handle confidential deal flow?
Look for intake software that secures the inquiry itself, not just the connection to it. Most consulting CRMs (HubSpot, Dubsado, Copper) store your prospects' submissions in a form the vendor can read — encrypted at rest, but the vendor holds the keys — so the provider, and anyone who breaches that boundary, can read deal names, strategy, and RFP details. Brun is different: it encrypts every submission in the prospect's browser before it sends, so Brun stores only ciphertext it cannot decrypt. Only your team holds the key, which is exactly the posture you want when an inquiry is already covered by an NDA.
Do I have to replace my website or contact form to use a secure intake tool?
No. That is the main reason boutique agencies choose Brun over all-in-one suites like Dubsado or HoneyBook that push you onto their hosted forms and portals. Brun keeps your existing website and your existing contact form. You add a small snippet so the form encrypts each inquiry in the visitor's browser before it's sent, and the decrypted lead lands on a simple CRM board for your team. Your brand, your site, your form — just unreadable to everyone but you in transit and at rest.
How does encrypted client intake help me stay compliant with NDAs and client confidentiality?
When a prospect describes a confidential matter — an acquisition target, a turnaround, an RFP under embargo — that information is often already covered by a mutual NDA or your duty of confidentiality the moment it lands. With a conventional CRM, you've effectively disclosed it to a third-party vendor. With Brun, the inquiry is encrypted in the browser and stored as ciphertext Brun cannot read, so no third party ever holds the confidential content. That keeps the vendor out of scope as a data recipient and reduces your NDA and GDPR exposure.
What fields can a consulting client intake form capture, and are they all protected?
You can capture everything a consulting intake form normally needs — business challenge, success metrics, stakeholder names and roles, budget and procurement status, and RFP scope. The difference with Brun is that every one of those fields is encrypted in the prospect's browser before submission. Whether the field holds a phone number or the name of an M&A target, Brun stores only ciphertext, and only your team can decrypt it into a workable lead.
How is Brun different from a CRM like HubSpot or Copper for consultants?
HubSpot and Copper are excellent at pipeline and marketing, but their web forms write prospect data into a database the vendor can read, and you typically move your forms onto their platform. Brun focuses on one thing those tools don't: zero-knowledge intake. You keep your own form, the inquiry is encrypted client-side, and Brun never sees the plaintext. New inquiries still arrive as leads on a board you can work, so you get the lead-management workflow without handing your confidential deal flow to a SaaS provider.
How much does secure client intake software cost for a solo consultant or small agency?
Brun is priced for independent consultants and boutique teams alike, and the options are shown when you pick a plan at signup. Every one of them includes the same core guarantee: inquiries are encrypted in the browser and stored as ciphertext Brun cannot read. Even a solo consultant gets vendor-unreadable intake without paying an enterprise premium for it.
Go deeper on encrypted intake.
- What zero-knowledge secure intake isThe category, defined in plain language: how a submission is encrypted in the browser and stored as ciphertext the vendor cannot read.
- Why your intake must be encryptedThe exposure every readable inquiry creates, from vendor breaches to subpoenas to AI training sets — and the way end-to-end encryption removes it.
- The compliance claims we don’t makeHow zero-knowledge storage plays with confidentiality duties — and why Brun signs no BAA and prohibits PHI.
- Brun overviewEverything Brun does on one page — sealed intake plus a small CRM board for boutique teams.
- See your industryBrowse secure intake for every vertical Brun serves, from law firms to accountants.
Not legal advice
This page describes Brun’s architecture and how it relates to client confidentiality; it is general information, not legal advice. Your confidentiality and data-protection obligations depend on your specific engagements — confirm your compliance posture with qualified counsel.
Inquiries only your firm can read
Start securing your prospect inquiries.
Brun is zero-knowledge client intake software for consultants and boutique agencies: prospect inquiries encrypted on the prospect’s machine, stored as ciphertext nobody at Brun can open, worked as leads inside your firm alone. Two edits connect your form — and your confidential deal flow never lands with another SaaS vendor.