Trust
The practices below are how the platform actually operates today, in the same terms as our Privacy Policy. No marketing gloss, no claimed certifications.
Customer data is stored with row-level security enforced per organisation. Your workspace is scoped to your organisation, and access rules are applied at the database layer, not just in the application.
Social OAuth tokens and API keys are encrypted at rest and scoped to the organisation that connected them.
Access to production data is restricted to authorised administrators.
Authentication events, role changes, and settings updates are recorded to a security log. Security event logs are retained for a minimum of 12 months regardless of plan.
Analytics retention follows your plan (6, 12, or 36 months), and account data is removed from production systems within 30 days of deletion.
Card payments are processed by FluidPay and crypto payments by Helio. Card details are entered in the processor’s secure fields; TheContentForge does not store card numbers.
Publishing runs through roles, approvals, and a queue your team controls. Nothing posts without the permissions you configured.
For teams that use Web3 features: on-chain intelligence is read-only. No custody, no private keys, no trade execution, ever.
Questions from your security review?
Procurement and security teams can reach us directly. We answer plainly, including about what we do not yet have.
Contact the team