Trust

Built for controlled team workflows

The practices below are how the platform actually operates today, in the same terms as our Privacy Policy. No marketing gloss, no claimed certifications.

Workspace isolation

Customer data is stored with row-level security enforced per organisation. Your workspace is scoped to your organisation, and access rules are applied at the database layer, not just in the application.

Credential encryption

Social OAuth tokens and API keys are encrypted at rest and scoped to the organisation that connected them.

Restricted production access

Access to production data is restricted to authorised administrators.

Security logging

Authentication events, role changes, and settings updates are recorded to a security log. Security event logs are retained for a minimum of 12 months regardless of plan.

Retention you can predict

Analytics retention follows your plan (6, 12, or 36 months), and account data is removed from production systems within 30 days of deletion.

Payments never touch our servers

Card payments are processed by FluidPay and crypto payments by Helio. Card details are entered in the processor’s secure fields; TheContentForge does not store card numbers.

Human approval over blind automation

Publishing runs through roles, approvals, and a queue your team controls. Nothing posts without the permissions you configured.

Read-only on-chain intelligence

For teams that use Web3 features: on-chain intelligence is read-only. No custody, no private keys, no trade execution, ever.

Questions from your security review?

Procurement and security teams can reach us directly. We answer plainly, including about what we do not yet have.

Contact the team