User guide

Protecting public forms

How ResponseMint validates public submissions and what to consider before collecting sensitive information.

ResponseMint checks public submissions on the server, applies request limits, and supports Cloudflare Turnstile when keys are configured. A honeypot helps reject simple automated submissions.

Collect only what you need

Avoid requesting sensitive personal information unless the workflow genuinely requires it. Explain why the information is needed and who will use it.

File uploads

Uploaded files are attached to the response and available to the workspace owner through the response inbox. Review file-retention and access requirements before using a public form for regulated or highly sensitive material.

Report a security concern

Email hello@responsemint.io with a clear description and reproduction steps. Do not include real respondent data in the report.