Web form security is the full set of measures that keep the contact, quote, application and sign-up forms on your site from being abused and protect the personal data they collect. A form is the door through which your site accepts data from outside. Spam bots knock on that door hundreds of times a day, and sometimes someone tries to force the lock. The picture we see most often in the field: an inbox full of fake messages with real customer requests lost among them, and form data piling up in a table for years without ever being deleted. In this article we explain how to secure a form layer by layer.
Spam and bot protection without wearing out visitors
The first reflex against spam bots is usually to add a visual challenge (CAPTCHA). It works, but it also wears out real visitors, and some solutions bring third-party cookies and cross-border data transfers with them. A more balanced approach combines several invisible layers:
- Honeypot field: A hidden field that humans don't see but bots fill in. If it is filled, the submission is rejected.
- Timing check: A form submitted two seconds after the page loaded is very likely not a human.
- Rate limit: Large numbers of submissions from the same address in a short time are stopped.
- Content rules: Messages stuffed with links or matching certain patterns are moved to a separate box.
- Invisible verification, if needed: If the layers above aren't enough, add a verification layer that works without asking the visitor anything. If a third-party service is used, this must be reflected in your cookie and privacy notices.
Injection and malicious input
Every piece of data coming from a form should be treated as untrusted. Injection is when an attacker types a command into a form field instead of data, so that the system executes that command. The main types and their countermeasures:
| Risk | What happens | Countermeasure |
|---|---|---|
| SQL injection | Data is read from or deleted in the database | Parameterized queries; never paste input into the query text |
| XSS (cross-site scripting) | A message opened in the admin panel runs code in the admin's browser | Escape output when rendering it, content security policy |
| Email header injection | The form is used to send spam to others | Reject line-break characters in name and email fields |
| CSRF (cross-site request forgery) | Another site submits the form on the user's behalf | A single-use validation token per form |
Validation should happen both in the browser and on the server. Browser checks are a convenience for the user; server checks are what provide security.
File uploads: the riskiest part
File upload fields, such as those for job applications or for sending drawings or photos with a quote request, are the riskiest part of a form. Our recommendations:
- Allow only the file types you really need, and check the type from the file's content, not its extension.
- Set a maximum file size.
- Store uploaded files with random names in a folder that can't be accessed directly over the web.
- Disable script execution in the upload folder.
- If possible, run files through a malware scan.
- Instead of attaching files to emails, show them to the authorized person in the admin panel.
Files such as CVs and identity documents contain a lot of personal data; making them reachable through a public link carries a serious risk of a breach.
Data minimization: the safest data is data you never collect
One of the core principles of KVKK (Türkiye's Personal Data Protection Law) is that data must be relevant, limited and proportionate to the purpose for which it is processed. When designing a form, ask of every field: "Could we respond to the request without this information?" Asking for a national ID number, date of birth or home address on a contact form is usually unnecessary. Removing unnecessary fields reduces both the risk of a breach and the number of visitors who abandon the form halfway.
Retention periods are part of minimization, too. Contact requests that have been answered should be deleted or anonymized once the defined period ends. We explained how to write the information shown on the form in our article on the website privacy notice, and how to route requests into the sales process without losing them in from web form to CRM.
Form security checklist
- The form runs only over HTTPS
- Invisible bot layers (honeypot, timing, rate limit) are active
- All input is validated on the server; queries are parameterized
- Each form has a validation token
- File upload type, size and storage location are restricted
- Every field has a defined purpose; there are no unnecessary fields
- The privacy notice link is visible before the submit button
- A retention period is defined and enforced for form data
- Notification emails don't carry sensitive data or attachments
How we do it at Globya
On the corporate websites we build, we deliver forms with invisible bot layers, server-side validation and protected file storage. Incoming requests are collected in the admin panel; the notification email carries only a summary, and attachments stay in the panel. We set the retention period with you and build it into the software as a rule. As part of our KVKK compliance approach, these requirements are never left out, and there is no extra charge for them.
Frequently asked questions
Does spam really go down without a CAPTCHA?
On most sites, invisible layers stop the bulk of spam. If that isn't enough, an additional verification layer is added; we recommend trying the methods that don't burden visitors first.
How long should we keep form data?
It depends on the purpose. An answered information request and a job application have different retention periods. Set your periods in line with your retention and destruction policy, and confirm the legal periods with your legal advisor.
Is it a problem for form notifications to arrive by email?
A summary notification is fine. But having sensitive content such as identity details, CVs or health information, along with attachments, circulating by email increases the risk; keeping them in the panel is safer.
Can you test our existing forms?
Yes. Reach us at +90 850 432 55 13 or through our contact page; we will review your forms against this list and send you our findings in writing.
The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.