Form integrity
Hidden trap field, posted origin check, and per-form rate limiting keep junk submissions out without ever blocking a real customer.
The page is loading. No inquiry, booking, or provider action is happening in the background.
A lead-capture system that treats the form as a public surface, not a leaky inbox. Junk is filtered with a hidden trap field and origin check; consent and audit entries are written alongside every real submission.
Pick a capability card to see what the system is supposed to do. Provider-state cards below describe the implementation boundary and the proof still required. The two sets must never blur together.
Hidden trap field, posted origin check, and per-form rate limiting keep junk submissions out without ever blocking a real customer.
Real customers never see it. Bots that fill every input get caught. Origin and referer checks sit on top so a spoofed POST never silently succeeds. No service-role key in the browser — the form posts to a verified route that writes through the server-side adapter.
These cards separate implementation from provider proof. They are not live-status badges, and no pending card is presented as a connected customer workflow.
Server-side owner sessions, audit writes, and consent records are implemented through Supabase. Current schema and row readback remain an operator verification step before a live connection claim.
The adapter and webhook contracts are implemented. Exact WABA/phone registration, signed webhook, controlled send/receive, and CRM proof remain pending.
The adapter and callback route are implemented. Provider-generated delivery plus durable outbox and CRM linkage remain pending.
Lite tier implementation fee:
Lite covers the agreed architecture. Standard and Pro add depth, integrations, and verified provider setup. Domain, hosting, AI compute, phone numbers, messaging, and calendar provider costs are billed directly by their providers and are never marked up by IronWake.