Security and privacy

Public-sector forms carry personal data and feed case systems. quillflow's design starts from one rule: never trust the browser.

What quillflow does

Risk What happens
Someone edits the page or sends data directly Every submission is checked again on the server by the same engine and the same rules. Hidden answers, unknown fields and forged calculated values are dropped or recomputed.
A form is used to query systems it should not The browser can only run lookups the form declares, with exactly the declared parameters and only plain values. URLs and credentials exist only on the server.
A made-up value where a real one is required Search fields can name a verify lookup; the server runs it again on submit.
Leaking internals Connector and handler errors are logged on the server. The browser gets a plain 502 or 500.
Personal data in caches Lookup responses and submissions are sent with Cache-Control: no-store.
Double submissions Idempotency keys: one case per submission, even with retries at the same moment.
Oversized or malformed requests JSON only, 1 MB by default, and lookup values limited in size and type.
Script injection through form text Text is inserted as text, never as HTML. Liquid is limited to a safe set of tags and filters.
Slow patterns in rules Formulas cannot run code. On .NET, pattern matching has a time limit.
Circular rules Found when the form is compiled, and again when it is loaded.

The web component and the designer need no inline scripts or eval, so both run under a strict Content-Security-Policy.

What stays your job

  • Who may fill in or read what. Put authentication and authorization on the API: .RequireAuthorization(), or authenticate in Node.
  • Connectors decide what data a lookup returns to that user. Return only what the form needs.
  • Rate limiting, especially on lookups that search registers.
  • Retention and storage of submissions, according to your data-protection rules (GDPR). quillflow hands submissions to your handler and does not store them.
  • Publishing: forms are versioned, and a published version must not change. Submissions record the version they were made with.