TL;DR: Beyond encryption and 2FA, Formshive has a number of security practices baked in that protect you and your users — from hashing IP addresses to running its own captcha, to never storing passwords at all.
Your IP Address Is Hashed Before It’s Stored
When someone submits a form, Formshive records some metadata for analytics — device type, browser, rough location. But the IP address itself is SHA-256 hashed before it ever hits the database.
That means we can detect patterns (like repeated submissions from the same source), but we can’t look up someone’s actual IP address after the fact. It’s a one-way operation. Even if the database were compromised, there’s no list of real IP addresses to leak.
No Third-Party Captcha
Most form services use Google reCAPTCHA. That means every time someone fills out your form, Google gets a request too — with all the tracking that comes with it.
Formshive uses ALTCHA instead. It’s a self-hosted, proof-of-work captcha that runs entirely on our infrastructure. No external requests, no tracking pixels, no data shared with third parties. Your visitors solve a computational challenge that’s verified server-side using HMAC-SHA256 signatures — and that’s it.
No Passwords to Steal
Formshive doesn’t have a password database. You sign in through Google, GitHub, Microsoft, or Nostr — providers that handle authentication with their own security teams, 2FA infrastructure, and breach monitoring.
There’s no password reset flow, no “we stored your password in plaintext” incident waiting to happen, no credential stuffing attack surface. If you want an extra layer of protection, you can enable two-factor authentication on top.
Spam Detection Without Outsourcing Your Data
Spam filtering usually means sending your form data to a third-party API for analysis. Formshive handles it locally with two mechanisms:
- Email reputation tracking: If a specific email address has submitted forms before and most of those were flagged as spam, new submissions from that address are automatically flagged.
- Bayesian text analysis: A built-in classifier evaluates the content of submissions against learned spam patterns. No external API calls, no data leaves the server.
Both run on our infrastructure. Your form submissions aren’t being fed to someone else’s machine learning pipeline.
File URLs Expire
When someone uploads a file through your form, it’s stored securely in a private S3 bucket. You can access it through the dashboard or email notifications, but the download link is a signed URL that expires after 7 days.
That means even if a link leaks — forwarded email, shared screenshot — it won’t work forever. After a week, it’s dead. You can always generate a fresh link from the dashboard.
API Keys Have Scopes and Budgets
If you use the API, you can create keys that only have access to what they need. A key for reading form submissions doesn’t need write access. A key for a specific integration doesn’t need access to your billing.
Each key also has a budget — a spending limit that caps how much it can do. If a key is compromised, the damage is bounded.
Immutable Audit Logs
Every significant action in your account — logins, configuration changes, data access, billing events — is logged to an append-only audit trail. Old entries are purged automatically after the retention period.
If something looks off, you can trace exactly what happened, when, and from where.
Built With Rust
Formshive’s backend is written in Rust. For users, the practical upside is that an entire category of security vulnerabilities — buffer overflows, use-after-free, null pointer dereferences — simply can’t happen. The language eliminates them at compile time.
This isn’t a silver bullet, but it removes the most common attack vectors that have led to major breaches in software written in C, C++, or other memory-unsafe languages.
Encryption Is Still the Big One
We covered encryption modes in detail back in January. The short version: you can choose between no encryption, server-side encryption (we protect it, we can read it), or public-key encryption via Nostr (only you can read it). The mode is locked once set — it can’t be downgraded later.
None of these features require you to configure anything. They’re just how Formshive works.