Omnicom Media, Tapper link up to boost campaign performance integrity for clients

Tapper
Pricing
LoginRequest a Demo

Vantage

Win your highest-value customers with predictive signals

Resources

Success stories

Blog

Ad fraud impact 2026

Pricing

Request a DemoLogin
Tapper FormGuard

Every lead, checked before it counts.

Bots, throwaway addresses and repeat fills land in your CRM looking like demand. FormGuard reads the session the way Block does, checks the contact details as they are submitted, and writes a verdict, a score and the reasons onto the lead in Salesforce or HubSpot. Your rules decide what happens next. Nothing is deleted.

Get a demo

Illustrative submissions with generic names, in the layout of the FormGuard intake view.

Powering growth for ambitious brands

Tiffany & Co.
Adidas
Azadea
Punt Roma
Salsa Jeans
Sunglass Hut
Virgin Megastore
Decathlon
Honda
Lexus
Mercedes-Benz
On
TOD
Toyota
Volvo
Dominos
STC
Porsche
Almosafer
Infiniti
Marks & Spencer
LEGOLAND
du
Cleveland Clinic
Nissan
Boggi Milano
Kiko Milano
Hyundai
Chevrolet
Aape
Kiabi
Watsons
Maje Paris
Sandro
Ted Baker
ACE
Tawuniya
TOEFL
Regit
You.gr
Spitishop
Tiffany & Co.
Adidas
Azadea
Punt Roma
Salsa Jeans
Sunglass Hut
Virgin Megastore
Decathlon
Honda
Lexus
Mercedes-Benz
On
TOD
Toyota
Volvo
Dominos
STC
Porsche
Almosafer
Infiniti
Marks & Spencer
LEGOLAND
du
Cleveland Clinic
Nissan
Boggi Milano
Kiko Milano
Hyundai
Chevrolet
Aape
Kiabi
Watsons
Maje Paris
Sandro
Ted Baker
ACE
Tawuniya
TOEFL
Regit
You.gr
Spitishop
The challenge

In your CRM, they all look like leads.

A form fill is the first thing a campaign can see and the last thing it can judge. Your sales team dials the list in the order it arrived, and nothing in the row says which ones were never a person.

The blind spot

Junk that lands as a lead gets counted like one.

It takes a slot in the sales queue, it fills the reports, and it sits in the CRM beside the enquiries that were real. FormGuard puts the verdict on it at the door, so what your team and your reports count as a lead becomes yours to decide.

How it works

Three layers. One verdict. Five fields.

The session, read by the same monitoring script Block uses. The contact details, checked as they are submitted and hashed at ingest. The agreement between the two. The result is written onto the lead, and what FormGuard looks at is a fixed list, and so is what it writes.

Check

01

Three layers, passively. No challenge for the visitor.

Score

02

A verdict and a score, with the reasons as a fixed vocabulary you can filter on.

Write

03

Five fields onto the lead or contact. Nothing else on the record.

Route

04

Your rules: hold, or flag and let the CRM's own assignment rules, workflows and views act on the fields.

A verdict is protective, and that is all it does.

It does not bid, build an audience or change a stage. It puts a fact on the record that your team and your rules can act on.

What it catches

Six ways junk gets into a pipeline.

Each one leaves a different trace: in the session, in the contact details, or in the gap between them.

Bots and automation

Caught byBehaviour and Consistency

Automation fills a form the way a script would: the hidden field a person never sees gets a value, nothing on the page is touched before submit, and the browser announces itself as headless or carries the markers of a driver. The session layer sees all of this before the contact details are read, and the consistency layer notices when the same automation keeps appearing under different names.

headless browserhidden field filledno interaction before submitautomation markers
Your rules

You decide what a verdict does.

Hold a submission before it reaches your team, or let it land flagged and route it by score. Either way it is kept, reviewable and yours.

In your CRM

Five fields on the record. Either CRM.

Verdict, score, reasons, checked at, a reference: on the Lead in Salesforce, on the Contact in HubSpot. Your status, owner, stage and every field your team uses stay yours.

A fixed field set, written down before it is written

Nothing else on the record is touched

Email and phone hashed at ingest, raw values never stored

Verdict written

five fields, nothing else

Pick your CRM

FormGuard for Salesforce and HubSpot

Each page lists exactly what FormGuard reads and writes, in that CRM’s own vocabulary.

FormGuard for Salesforce

Five fields on the Lead: verdict, score, reasons, checked at, reference. Lead Status, Owner, Rating and every field your team uses stay yours.

Every Salesforce detail
No friction

The visitor sees a form. You see the verdict.

No CAPTCHA, no challenge, no extra step. The checks are passive, so a genuine enquiry is never slowed down, and nothing typed into the form is read by the monitoring script.

One script

Block judges the click. FormGuard judges the submission.

One monitoring script, one integration. Block keeps invalid traffic out of your ad account at the click; FormGuard keeps invalid leads out of your pipeline at the submit. Same signals, different moment.

Data

What FormGuard reads, writes, and never touches.

FormGuard reads the signals a browser sends on its own and the behaviour on the page, never what the visitor types: every input field is redacted before processing. For the contact check, email and phone are normalised and hashed with SHA-256 at ingest, and the raw values are never persisted in Tapper’s database, warehouse, logs or queue messages. Scope is a fixed list: a named set of CRM fields read, five FormGuard fields written, no free text in either direction, no other object. Credentials are encrypted with AES-256-GCM at rest; disconnecting revokes the token and deletes them. Data is held per customer, never pooled. Nothing is deleted from your CRM, ever. Where a visitor has not consented to storage the script runs storage-free, and a visitor’s refusal is honoured.

Reads

The signals a browser sends and the behaviour on the page, from the same monitoring script Block uses, and the contact fields it checks, hashed at ingest.

  • behaviour on the page, never what is typed

  • device, browser, network and the ad click

  • email and phone, normalised and hashed with SHA-256

Writes

Five fields on the lead or contact, listed in the disclosure your admin reviews before anything is written. Nothing else on the record.

  • verdict, score, reasons

  • checked at, reference

  • no free text in either direction

Never

Free text, notes, payment data and any other object stay out of scope. Nothing in your own CRM is deleted, merged or archived by Tapper.

  • no free-text or note fields

  • no payment data

  • no delete, merge or archive

When you disconnect

The token is revoked and the stored credentials, encrypted with AES-256-GCM at rest, are deleted. Fields written before you disconnect stay in your own CRM, because they are yours.

  • token revoked

  • credentials deleted

  • written fields stay yours

Frequently asked questions

The questions sales, CRM and security teams ask before a form is connected.

Three layers. The session, read by the same monitoring script Block uses: behaviour on the page, device and browser, network, IP intelligence and honeypot traps a human never sees. The contact details as they are submitted: whether the address and number are well formed, real and consistent with each other. And consistency between the two: whether the country, language and network the browser shows agree with what the form says.

The result is a verdict, a score and the reasons.

No. No CAPTCHA, no challenge, no extra step. The checks are passive, so a genuine enquiry is never slowed down.

The monitoring script redacts every input field before processing and collects no names, emails or financial data.

For the contact check, email and phone are normalised and hashed at ingest, and the raw values are never stored in Tapper’s database, warehouse, logs or queues.

Whatever you decide. In hold mode it is kept aside before it reaches your sales team. In flag mode it lands in your CRM carrying the verdict, and your own rules route it.

Tapper never deletes, merges or archives a record.

FormGuard is designed for Salesforce and HubSpot, each with its own page describing exactly which fields are read and written. Any CRM gets its own disclosure before it is connected.

Block judges the click and keeps invalid traffic out of your ad account. FormGuard judges the submission and keeps invalid leads out of your pipeline. Same script, same signals, different moment.

No. The verdict, score and reasons are fields on the lead in the CRM they use every day. Views, assignment rules and workflows do the rest.

Yes. The reasons are a fixed vocabulary written onto the record, so you can filter on them, report on them and tell us when one is wrong.

See FormGuard on your own forms.

We walk through the three layers, the five fields and your rules with your team before anything is connected.

Get a demo
FormGuard for SalesforceFormGuard for HubSpot