Security
How far-end protects submissions and privacy.
far-end is built so that collecting form data does not mean collecting more than you need.
Private by default
- IP addresses and User-Agents are hashed, never stored raw.
- Submission payloads are never logged.
- Statistics cannot group by fields that look like personal data.
Only your sites
Only the origins you allow can read or write. The origin check runs on the server before any write, so it is the real boundary, not just a browser convenience.
No CAPTCHA
A one-time challenge plus a small proof of work stops scripted abuse without a third-party CAPTCHA and without tracking visitors.
Spam filtering
Built-in filters catch disposable email domains, links, and spam keywords. Apply them to any field. A submission that trips a filter is dropped quietly and gets the same success response as the honeypot, so spammers learn nothing.
No enumeration
Unknown forms are hidden from visitors who are not on your allowlist. Error messages are generic so they do not reveal how the service works.