Security, Bot Defense & GDPR Privacy
Protect your endpoints with Cloudflare Turnstile, disposable email blocking, keyword filtering, GDPR Zero-IP masking, and AES-256-GCM encryption.
End-User Security & Anti-Abuse Controls#
Every form in EntryWise can enable layered spam and abuse defenses independently from the Console Security tab:
| Protection Layer | Configuration | How It Protects Your Form |
|---|---|---|
| Honeypot Trap (_gotcha) | Always active | Silently drops automated bot submissions with a decoy 200 OK so scrapers never retry. |
| Disposable Email Blocker | blockDisposableEmails: true | Rejects 55+ burner/temp-mail domains (Mailinator, GuerrillaMail, YOPmail, 10MinuteMail, Sharklasers) at the edge. |
| Blocked Keywords Filter | blockedKeywords: string[] | Case-insensitive phrase filter across all submitted values to silently drop SEO/crypto spam. |
| Cloudflare Turnstile | turnstileSecretKey | Verifies cryptographic Turnstile tokens at the edge with zero visual CAPTCHA friction. |
| Max Payload Size Cap | maxPayloadBytes (1KB–1MB) | Prevents oversized JSON payload DoS attacks per form. |
GDPR Zero-IP Mode & Automatic Retention Pruning#
Need strict GDPR / EU data minimization compliance? Enable Zero-IP Mode (disableIpLogging: true) on any form so submitter IP addresses are masked as 0.0.0.0 before touching the database.
You can also set a Custom Retention Window (retentionDays: 7, 30, 90, 365) so older submissions are automatically purged on schedule.
All third-party API keys (Resend, Airtable, Notion, Turnstile) are encrypted at rest with AES-256-GCM. All outbound webhooks pass through strict SSRF validation blocking localhost, RFC1918 private networks, and cloud metadata IPs (169.254.169.254). All CSV exports neutralize spreadsheet formula injection (=, +, -, @).
