FormLynk — Connect your forms. Send anywhere.
DEFENSE-IN-DEPTH SECURITY

Security between your form and the inbox.

Every submission is safeguarded by strict CORS origin whitelisting, silent honeypot traps, cryptographic bot verification, rate limiting, and AES-256 encrypted credential storage.

Origin Isolation
Strict CORS
Whitelisted domain lock
Bot Mitigation
94.3% Deflected
Honeypots + Turnstile
Attachment Storage
Private UUID
Magic-byte sanitized
Webhook Signatures
HMAC-SHA256
Cryptographic verification
07DEFENSE-IN-DEPTH

Security between your form and the inbox.

Every incoming HTTP request passes through an 8-stage automated defense checkpoint before reaching the database or email dispatcher.

01

API Key Authentication

Distinguishes Browser Public (pk_) vs Server Private (sk_) keys with live/test environments.

PassedAUTHENTICATED
02

CORS Origin Whitelist

Strictly enforces domain boundaries. Unapproved domains are rejected with 403 INVALID_ORIGIN.

PassedORIGIN_VERIFIED
03

Rate Limiting per IP

Default 20 req/min per IP and per form limits prevent brute-force and DDoS flooding.

PassedUNDER_LIMIT
04

Silent Honeypot Trap

Hidden _gotcha field catches automated scrapers without annoying human users with puzzles.

PassedCLEAN
05

Turnstile / reCAPTCHA

Cryptographic bot challenge verification for high-risk lead generation endpoints.

PassedCHALLENGE_PASSED
06

Dynamic Validation

Evaluates input bounds, RFC 5322 email syntax, and disallows dangerous script injection.

PassedSCHEMA_VALID
07

Idempotency Key Deduplication

Pass Idempotency-Key to prevent double submissions from double clicks or network reconnects.

PassedUNIQUE_TRANSACTION
08

Stack Concealment

Strips X-Powered-By & framework headers. Stores file uploads privately outside webroot.

PassedCONCEALED
Responsible Disclosure: Browser Public keys (pk_live_...) are safe in frontend code because they are restricted by CORS origins and rate limits.
Read Security Architecture →
ARCHITECTURE SPECIFICATIONS

How FormLynk neutralizes attack vectors

01
EDGE INGESTIONCORS Isolation

Browser Public Key & CORS Origin Shield

Client-side `pk_live_...` keys are safe in frontend code because requests are authenticated against your project's whitelisted domains (e.g. `https://mywebsite.com`). Third-party domain spoofing is immediately terminated at the edge with a 403 INVALID_ORIGIN error.

SECURITY METRIC:Edge Origin Verification • 0ms Server Load
02
BOT DEFENSEHoneypot Trap

Silent Honeypot & Turnstile Bot Traps

Automated scraper bots automatically populate hidden fields like `_gotcha`. FormLynk detects these bots silently and returns a fake 200 success response to avoid bot retraining—without burdening real users with annoying image CAPTCHAs.

SECURITY METRIC:94.3% Bot Scrapers Deflected • Zero User Friction
03
FILE SANITIZATIONPayload Sanitizer

MIME Signature & Extension Neutralization

All attachments are strictly verified by magic-byte binary signatures. Dangerous executable files (.php, .exe, .sh, .bat, .vbs) are neutralized, renamed with randomized UUIDs, and stored outside web-accessible directories.

SECURITY METRIC:Isolated Private Storage • Binary Magic-Byte Check
04
STACK CONCEALMENTConcealment Layer

Header Stripping & Signature Obfuscation

FormLynk strips framework fingerprint headers (`X-Powered-By`, `Server`, internal paths). Cookie sessions are masked as generic token headers, preventing automated vulnerability scanners from targeting your underlying server stack.

SECURITY METRIC:Zero Framework Signatures • Hardened Response Footprint
05
DATA INTEGRITYWebhook Security

HMAC-SHA256 Signed Outbound Webhooks

Every webhook sent to your internal API, Zapier, Make, or CRM carries an `X-FormLynk-Signature` header computed via HMAC-SHA256 with your private project secret (`sk_live_...`), guaranteeing absolute payload authenticity.

SECURITY METRIC:Cryptographic Tamper-Proofing • SHA-256 Signatures
LIVE DEFENSE BEHAVIOR

Why Browser Public Keys cannot be hijacked

Unlike traditional API keys that grant full account access, FormLynk's pk_live_ keys are strictly ingestion-only and locked to specific origins. If a bad actor extracts your public key and attempts to submit from another domain, our edge terminates the request immediately.

  • Legitimate: Origin: https://mysite.com → HTTP 200 Accepted
  • Spoofed: Origin: https://malicious.xyz → HTTP 403 Forbidden
  • Server headers concealed with zero stack exposure
edge/cors_firewall.log403 BLOCKED
HTTP/2 403 Forbidden
Date: Tue, 29 Sep 2026 14:56:00 GMT
Content-Type: application/json
X-FormLynk-Firewall: Active

{
  "success": false,
  "error": {
    "code": "INVALID_ORIGIN",
    "message": "Origin 'https://malicious.xyz' is not permitted for pk_live_...",
    "action": "Add domain to project whitelist in Admin Portal"
  }
}

Deploy forms with built-in spam protection

Zero CAPTCHA puzzles for legitimate users. Complete origin shielding from day one.