Every lead, checked before it counts.
Bots, throwaway addresses and repeat fills land in your CRM looking like demand. FormGuard reads the session the way Block does, checks the contact details as they are submitted, and writes a verdict, a score and the reasons onto the lead in Salesforce or HubSpot. Your rules decide what happens next. Nothing is deleted.
NOTHING DELETED
Next
User
Daniel
Lena
Checking
Amira K.
Acme · Paid search
amira.k@example.com
Phone
555-0134
Source
Paid search
Company
Acme
Behaviour
Contact
Consistency
Record
Amira K.
Acme
FormGuard
not written by Tapper
the same five fields in Salesforce or HubSpot
Illustrative submissions with generic names, in the layout of the FormGuard intake view.
Powering growth for ambitious brands




































































In your CRM, they all look like leads.
A form fill is the first thing a campaign can see and the last thing it can judge. Your sales team dials the list in the order it arrived, and nothing in the row says which ones were never a person.
New leads|This morning
Amira K.
Acme/Paid search
Priya
User #44071
No company given/Display
Sam
Daniel R.
Agency/Paid social
Noor
Lena M.
Consultancy/Organic
Priya
Qwzx Plmk
asdf/Referral
Sam
Jonas P.
Retail brand/Direct
Noor
The same six submissions as the intake line above. Illustrative.
Ad click
Your form
Your CRM
Counted as a lead
Held
Junk that lands as a lead gets counted like one.
It takes a slot in the sales queue, it fills the reports, and it sits in the CRM beside the enquiries that were real. FormGuard puts the verdict on it at the door, so what your team and your reports count as a lead becomes yours to decide.
Three layers. One verdict. Five fields.
The session, read by the same monitoring script Block uses. The contact details, checked as they are submitted and hashed at ingest. The agreement between the two. The result is written onto the lead, and what FormGuard looks at is a fixed list, and so is what it writes.
Amira K.
amira.k@example.com
Phone
555-0134
Source
Paid search
Behaviour on the page
Email and phone
Do the two agree
Onto the lead or contact
no other field is touched
Check
01
Three layers, passively. No challenge for the visitor.
Score
02
A verdict and a score, with the reasons as a fixed vocabulary you can filter on.
Write
03
Five fields onto the lead or contact. Nothing else on the record.
Route
04
Your rules: hold, or flag and let the CRM's own assignment rules, workflows and views act on the fields.
A verdict is protective, and that is all it does.
It does not bid, build an audience or change a stage. It puts a fact on the record that your team and your rules can act on.
Six ways junk gets into a pipeline.
Each one leaves a different trace: in the session, in the contact details, or in the gap between them.
Bots and automation
Name
Work email
hidden field
Automation fills a form the way a script would: the hidden field a person never sees gets a value, nothing on the page is touched before submit, and the browser announces itself as headless or carries the markers of a driver. The session layer sees all of this before the contact details are read, and the consistency layer notices when the same automation keeps appearing under different names.
You decide what a verdict does.
Hold a submission before it reaches your team, or let it land flagged and route it by score. Either way it is kept, reviewable and yours.
after the stamp
User #44071
Invalidrule 01
Held
kept aside, reviewable
kept and reviewable, never deleted
Flagged
lands with its five fields
Routed
to your assignment rules
Five fields on the record. Either CRM.
Verdict, score, reasons, checked at, a reference: on the Lead in Salesforce, on the Contact in HubSpot. Your status, owner, stage and every field your team uses stay yours.
A fixed field set, written down before it is written
Nothing else on the record is touched
Email and phone hashed at ingest, raw values never stored
Lead recordWRITES 5 FIELDS
Details
Related
Activity
Daniel R.
Agency
FormGuard
FormGuard Verdict
PicklistFormGuard Score
NumberFormGuard Reasons
Multi-select picklistFormGuard Checked At
Date/TimeFormGuard Reference
Textmirrored on the Contact when the lead converts
Lead Status
yoursOwner
yoursRating
yoursnot written by Tapper
Verdict written
five fields, nothing else
The visitor sees a form. You see the verdict.
No CAPTCHA, no challenge, no extra step. The checks are passive, so a genuine enquiry is never slowed down, and nothing typed into the form is read by the monitoring script.
What the visitor sees
No CAPTCHAno challenge, no extra step
What you see
Qwzx Plmk
qwzxplmk@example.net/Referral
Nothing is deleted
Block judges the click. FormGuard judges the submission.
One monitoring script, one integration. Block keeps invalid traffic out of your ad account at the click; FormGuard keeps invalid leads out of your pipeline at the submit. Same signals, different moment.
<script src="https://monitor.tapper.ai/bundle.js" async>Ad click
Landing
Browsing
Submit
One script on the page. Same signals, a different moment. Illustrative.
What FormGuard reads, writes, and never touches.
FormGuard reads the signals a browser sends on its own and the behaviour on the page, never what the visitor types: every input field is redacted before processing. For the contact check, email and phone are normalised and hashed with SHA-256 at ingest, and the raw values are never persisted in Tapper’s database, warehouse, logs or queue messages. Scope is a fixed list: a named set of CRM fields read, five FormGuard fields written, no free text in either direction, no other object. Credentials are encrypted with AES-256-GCM at rest; disconnecting revokes the token and deletes them. Data is held per customer, never pooled. Nothing is deleted from your CRM, ever. Where a visitor has not consented to storage the script runs storage-free, and a visitor’s refusal is honoured.
Reads
The signals a browser sends and the behaviour on the page, from the same monitoring script Block uses, and the contact fields it checks, hashed at ingest.
behaviour on the page, never what is typed
device, browser, network and the ad click
email and phone, normalised and hashed with SHA-256
Writes
Five fields on the lead or contact, listed in the disclosure your admin reviews before anything is written. Nothing else on the record.
verdict, score, reasons
checked at, reference
no free text in either direction
Never
Free text, notes, payment data and any other object stay out of scope. Nothing in your own CRM is deleted, merged or archived by Tapper.
no free-text or note fields
no payment data
no delete, merge or archive
When you disconnect
The token is revoked and the stored credentials, encrypted with AES-256-GCM at rest, are deleted. Fields written before you disconnect stay in your own CRM, because they are yours.
token revoked
credentials deleted
written fields stay yours
Frequently asked questions
The questions sales, CRM and security teams ask before a form is connected.
Three layers. The session, read by the same monitoring script Block uses: behaviour on the page, device and browser, network, IP intelligence and honeypot traps a human never sees. The contact details as they are submitted: whether the address and number are well formed, real and consistent with each other. And consistency between the two: whether the country, language and network the browser shows agree with what the form says.
The result is a verdict, a score and the reasons.
No. No CAPTCHA, no challenge, no extra step. The checks are passive, so a genuine enquiry is never slowed down.
The monitoring script redacts every input field before processing and collects no names, emails or financial data.
For the contact check, email and phone are normalised and hashed at ingest, and the raw values are never stored in Tapper’s database, warehouse, logs or queues.
Whatever you decide. In hold mode it is kept aside before it reaches your sales team. In flag mode it lands in your CRM carrying the verdict, and your own rules route it.
Tapper never deletes, merges or archives a record.
FormGuard is designed for Salesforce and HubSpot, each with its own page describing exactly which fields are read and written. Any CRM gets its own disclosure before it is connected.
Block judges the click and keeps invalid traffic out of your ad account. FormGuard judges the submission and keeps invalid leads out of your pipeline. Same script, same signals, different moment.
No. The verdict, score and reasons are fields on the lead in the CRM they use every day. Views, assignment rules and workflows do the rest.
Yes. The reasons are a fixed vocabulary written onto the record, so you can filter on them, report on them and tell us when one is wrong.
See FormGuard on your own forms.
We walk through the three layers, the five fields and your rules with your team before anything is connected.
