Security

Keep HighLevel as the source of truth

Update Records with Forms is built to move data safely between a HighLevel record and the person reviewing it – without becoming a second, shadow copy of your CRM.

Access lifecycle

Temporary access, not a CRM login

A generated form link gives controlled access to one specific form context. The recipient does not receive a HighLevel user account – the workflow decides which record, which fields are visible, which are read-only, which are editable, and which are required.

Every newly generated form link has an expiry. Once a link expires, it cannot be reactivated – generate a new link if access is needed again. There is no "no expiry" option and no manual per-link revoke feature.
  • Link Expiry is entered as a number of days.
  • Decimals are allowed (for example, 0.5 days).
  • Blank defaults to 7 days.
  • Maximum is 3,650 days.
  • Links can be configured as single-submit or multiple-submit.
Verification

Confirm it's really them before the form opens

Send Verification Code adds an extra check for Contact and Opportunity forms: before the form loads, the recipient has to enter a one-time code sent to the phone number or email address already on that record.

How it works

The recipient opens the link, requests a code, and enters the 6-digit code they receive by SMS – or by email, if there's no phone number on file, or automatically as a fallback if SMS delivery can't be confirmed. Only after the code is verified does the form itself load.

Works across devices

The code can be requested on one device and entered on another – for example, request it on a desktop, receive the text on a phone, and type the code back in on the desktop. There's no single-device link to click.

Contact and Opportunity only

Send Verification Code is available when the workflow action targets a Contact or an Opportunity, since verification relies on a phone number or email address already stored on that record.

Verified access lasts 48 hours

Once a code is verified, that browser can access the form without re-verifying for up to 48 hours, capped by the link's own expiry – whichever comes first. After that, a new code is required.

No link previews or scanners can trigger it

Loading the link never sends a code or grants access by itself – a code is only ever sent after the recipient explicitly requests one, so link-preview bots and inbox scanners can't trigger a send or burn an attempt.

Rate limited against guessing

Code requests and code attempts are both rate limited per link, so verification can't be brute-forced or used to spam a Contact's phone or inbox.

Verification codes are sent as real SMS/email messages through your own connected HighLevel account and carry your account's own standard HighLevel sending costs – see Pricing.

1. What the service stores

Operational credentials and metadata required to operate the service – the minimum needed to authenticate to your HighLevel account, generate and validate form links, and route submissions back to the correct record.

2. What it does not persist

The service does not persist CRM field values or submitted form contents as a duplicate CRM database. HighLevel remains the single place your record data lives.

3. Secure record-specific links

Opaque secure tokens identify authorised form context – the link itself carries no readable reference to the underlying record.

4. Record IDs stay behind the form

The Record ID never appears in the public form or its URL. Recipients interact with a normal form, not a CRM identifier.

5. Credentials stay server-side

Account credentials and API access are handled server-side and are never exposed to the person filling out a form.

6. Protect against stale updates

If a field the recipient is changing was also updated in HighLevel after the form was opened, that field – not the whole submission – is blocked and shown in place with the current HighLevel value and what the recipient had entered. This is a deliberate, field-level block, not "last save wins," but it doesn't require reloading the form or losing anything else that was entered; a concurrent edit to a different field elsewhere on the record has no effect on the submission at all.

7. Account and location separation

Form generation and submission handling are scoped to the specific HighLevel account and location the workflow ran in.

8. Rate limiting and file safety

Form access and submission are rate limited, and uploaded files are handled defensively before being attached back to the record.

9. Link lifecycle

See Temporary access, not a CRM login above for the full expiry and submission-mode rules.

10. Code verification

See Confirm it's really them before the form opens above for how Send Verification Code protects Contact and Opportunity forms.

Give people a safe way to touch your CRM data

US$15/month after trial · 14-day free trial

Start 14-day free trial