Legal

Security Policy

How we protect your data and accounts.

All policies

Effective 17 June 2026 · ForgeAI Studio Ltd (company no. 17175307), West Bromwich, United Kingdom.

Architecture

The Service runs on managed, reputable cloud infrastructure. Data is encrypted in transit (TLS) and at rest. Access to production data is restricted and logged.

Tenant isolation

Every customer's data is isolated by row-level security tied to your organisation. Application code accesses data only within your permission scope.

Secrets & credentials

Integration tokens and API keys are stored in a restricted store that the application front-end cannot read; only server-side functions can use them. We never display a stored secret back to you, and we store inbound API keys only as a hash.

Authentication

We use passwordless sign-in (magic link / OAuth), so there is no password for us to store or for attackers to steal. Sessions are short-lived and refreshable.

Safety gate

A final approval layer reviews outbound content for accuracy, compliance and reputation risk before anything is published — reducing the chance of a damaging post going out.

Reporting

Found a vulnerability? Please email support@growthdept.app with details. We investigate all reports and won't pursue good-faith security research.

Questions about this policy? Email support@growthdept.app.