Security & Trust

Last updated: August 2026

This page states what’s true today, plainly, including the parts that aren’t built yet. If you’re filling out a security review, everything below should save you an email. If it doesn’t, ask us directly and we’ll answer without a sales call.

Do you retain our input text?

No

Deleted after the job completes, on every plan.

Do you keep the embedded vectors?

No

Returned to you, not retained on our side.

Is traffic encrypted?

TLS 1.3

AES-256-GCM. TLS 1.2 minimum, older refused.

Do you have SOC 2 or ISO 27001?

Not yet

No third-party certification today. Said plainly, not buried.

Can we sign a DPA?

Per contract

No self-serve template yet. Negotiated per contract.

Is SSO available?

Team and up

SAML SSO with SCIM provisioning on Enterprise.

Can we keep data off your infrastructure entirely?

Forge Local

Same engine, your own AWS account.

Data handling

Your input text is processed to generate embeddings and is not stored after the job completes. Embedded vectors are returned to you and are not retained on our side. This is unconditional: it applies to every plan, not just paid tiers. See Terms of Service ยง6.

What we do retain: account information (email, name, hashed password), billing metadata via Stripe, and usage metadata (request counts, token volumes, timestamps) for billing reconciliation. Usage records are kept on a rolling 90-day window for hourly detail, with daily aggregates retained indefinitely for your own usage history. Infrastructure telemetry (node health, alert history) is pruned after 30 days. Full detail in the Privacy Policy.

Encryption and access

  • All traffic is encrypted in transit with TLS 1.3 (AES-256-GCM); TLS 1.2 is the minimum accepted and older versions are refused.
  • Passwords are hashed with bcrypt; API keys are stored as SHA-256 hashes, never in plaintext.
  • Session tokens (JWT) expire after 15 minutes.
  • mTLS client identity is available on every tier: Ed25519 client certificates in place of bearer tokens, with no shared secret to rotate.
  • Infrastructure access is restricted to authorized personnel.

Sub-processors

We share data only with the vendors below, and only for the purpose listed. We do not sell your data, to these or anyone else.

Sub-processor Purpose
Stripe Payment processing
Twilio SMS delivery for infrastructure alerts (internal ops only, not customer-facing)
Cloudflare API gateway, CDN, edge caching
Fly.io / RunPod Infrastructure hosting for the control plane and inference nodes

Single sign-on and administration

Team plans include SSO and central billing and administration for the whole org. Enterprise adds SAML SSO with SCIM provisioning, audit logs and role-based access, private networking, and data residency options. Details and current pricing are on the pricing page.

What we don’t have yet

We’re a small team. We do not hold a SOC 2, ISO 27001, or other third-party security certification today, and we don’t yet have a self-serve, signable Data Processing Agreement template. If either is a hard requirement for your organization, tell us early: DPAs are negotiated per contract, and an early signal on your timeline is what gets one in place before it blocks anything.

Forge Local

If your documents can’t leave hardware you control at all, Forge Local runs the same engine on your own AWS account: nothing crosses our infrastructure. For many procurement reviews this is the shortest path through, because there’s no third-party data flow to review in the first place.

Questions

Contact us with a security or compliance review, and we’ll respond within one business day.