WPForms, Gravity Forms & Ninja Forms store submissions in plaintext. Sensitive data remains readable on the server.

Your form plugin is exposing your clients’ data.

Patient intake. Legal documents. HR records. Insurance applications. Standard form plugins store submissions where your server and host can read them.

ZK Forms encrypts every field before it leaves the visitor’s browser. Your server receives ciphertext. Only you hold the key.

RSA-2048 + AES-256-GCM
HIPAA-ready architecture
Zero plaintext on server
Private key stays local
Who it’s
for

Your users trust you with their data. Protect it.

Healthcare

HIPAA

Patient intake, medical history, insurance data. HIPAA requires protecting this at rest and in transit.

Legal & law firms

Privilege

Client intake, case details, confidential disclosures. Attorney-client privilege doesn’t survive a plaintext breach.

HR & staffing

PII

Employment applications, background authorizations, payroll data. PII exposure creates significant liability.

Mental health providers

HIPAA

Intake questionnaires, session notes, sensitive disclosures. Among the most protected health data under HIPAA.

Insurance & finance

Regulatory

Policy applications, financial statements, SSNs. Regulatory requirements demand encryption at rest.

Education & counseling

FERPA

Student records, enrollment forms, counseling intake. FERPA and state privacy laws apply.

The
difference

Encrypted in the browser. Stored as ciphertext.

Standard form plugins

  • WordPress receives readable submission data
  • HTTPS protects it in transit, then the server can read it
  • A server breach can expose stored submissions
  • Hosts and integrations can access readable data

ZK Forms

  • Submission data is encrypted inside the visitor’s browser
  • HTTPS carries data that is already ciphertext
  • WordPress receives and stores ciphertext
  • Your private decryption key stays in your browser
How it
works

Four steps. Zero plaintext.

01020304
01

Visitor submits the form

Nothing leaves their device yet.

02

Browser encrypts the data

AES-256 encrypts the data before anything is sent.

03

Server receives ciphertext

Unreadable without your key. Your host cannot see it either.

04

Only you decrypt it

Your private key lives in your browser only. It never leaves.

Compare

Full-featured forms. Client data stays encrypted.

Swipe to compare

FeatureZK FormsWPFormsNinja FormsGravity Forms
End-to-end encrypted submission payload
Server stores ciphertext, not readable values
Private decryption key stays in the browser
HIPAA-ready architecture
Drag-and-drop form builder
Conditional logicPaid add-onPaid add-on
Multi-step formsPaid add-onPaid add-on
20+ field types, including signature, file upload and repeaterNot statedNot statedNot stated
Encrypted key backup and restore
Client-side CSV export
Email notifications without form dataNot statedNot statedNot stated
No reCAPTCHA required
Starting price$25/yr$49/yr$99/yr$59/yr
Pricing

Zero Knowledge protection at every scale.

Free
$0 / yr
  • 1 form
  • 100 submissions per month
  • 5 fields per form
  • 1 site
Start free
Most popular
Pro
$25 / yr
  • 10 forms
  • Unlimited submissions
  • Unlimited fields
  • 1 site
Choose Pro
Agency
$79 / yr
  • Unlimited forms
  • Unlimited submissions
  • Unlimited fields
  • 5 sites
Choose Agency

Stop exposing your clients’ data.