Security between your form and the inbox.
Every submission is safeguarded by strict CORS origin whitelisting, silent honeypot traps, cryptographic bot verification, rate limiting, and AES-256 encrypted credential storage.
Security between your form and the inbox.
Every incoming HTTP request passes through an 8-stage automated defense checkpoint before reaching the database or email dispatcher.
API Key Authentication
Distinguishes Browser Public (pk_) vs Server Private (sk_) keys with live/test environments.
CORS Origin Whitelist
Strictly enforces domain boundaries. Unapproved domains are rejected with 403 INVALID_ORIGIN.
Rate Limiting per IP
Default 20 req/min per IP and per form limits prevent brute-force and DDoS flooding.
Silent Honeypot Trap
Hidden _gotcha field catches automated scrapers without annoying human users with puzzles.
Turnstile / reCAPTCHA
Cryptographic bot challenge verification for high-risk lead generation endpoints.
Dynamic Validation
Evaluates input bounds, RFC 5322 email syntax, and disallows dangerous script injection.
Idempotency Key Deduplication
Pass Idempotency-Key to prevent double submissions from double clicks or network reconnects.
Stack Concealment
Strips X-Powered-By & framework headers. Stores file uploads privately outside webroot.
pk_live_...) are safe in frontend code because they are restricted by CORS origins and rate limits.How FormLynk neutralizes attack vectors
Browser Public Key & CORS Origin Shield
Client-side `pk_live_...` keys are safe in frontend code because requests are authenticated against your project's whitelisted domains (e.g. `https://mywebsite.com`). Third-party domain spoofing is immediately terminated at the edge with a 403 INVALID_ORIGIN error.
Silent Honeypot & Turnstile Bot Traps
Automated scraper bots automatically populate hidden fields like `_gotcha`. FormLynk detects these bots silently and returns a fake 200 success response to avoid bot retraining—without burdening real users with annoying image CAPTCHAs.
MIME Signature & Extension Neutralization
All attachments are strictly verified by magic-byte binary signatures. Dangerous executable files (.php, .exe, .sh, .bat, .vbs) are neutralized, renamed with randomized UUIDs, and stored outside web-accessible directories.
Header Stripping & Signature Obfuscation
FormLynk strips framework fingerprint headers (`X-Powered-By`, `Server`, internal paths). Cookie sessions are masked as generic token headers, preventing automated vulnerability scanners from targeting your underlying server stack.
HMAC-SHA256 Signed Outbound Webhooks
Every webhook sent to your internal API, Zapier, Make, or CRM carries an `X-FormLynk-Signature` header computed via HMAC-SHA256 with your private project secret (`sk_live_...`), guaranteeing absolute payload authenticity.
Why Browser Public Keys cannot be hijacked
Unlike traditional API keys that grant full account access, FormLynk's pk_live_ keys are strictly ingestion-only and locked to specific origins. If a bad actor extracts your public key and attempts to submit from another domain, our edge terminates the request immediately.
- Legitimate: Origin: https://mysite.com → HTTP 200 Accepted
- Spoofed: Origin: https://malicious.xyz → HTTP 403 Forbidden
- Server headers concealed with zero stack exposure
HTTP/2 403 Forbidden
Date: Tue, 29 Sep 2026 14:56:00 GMT
Content-Type: application/json
X-FormLynk-Firewall: Active
{
"success": false,
"error": {
"code": "INVALID_ORIGIN",
"message": "Origin 'https://malicious.xyz' is not permitted for pk_live_...",
"action": "Add domain to project whitelist in Admin Portal"
}
}Deploy forms with built-in spam protection
Zero CAPTCHA puzzles for legitimate users. Complete origin shielding from day one.