Security.
Operated by Waelas Ltd · last updated September 2026
You trust Forge with your calendar and your clients’ details. Here is how we look after them, and what to do if you find a problem.
How we protect your data
- Everything is encrypted in transit (HTTPS, with HSTS) and at rest.
- Calendar access tokens are encrypted a second time by us (AES-256-GCM) before they are stored.
- We never store passwords, only salted hashes. You can sign in with Google instead.
- Our database and servers run in London, with point-in-time recovery for the previous seven days.
- Public links to bookings, invoices, proposals and portals use long, unguessable tokens, and are kept out of search engines.
- Error reports are stripped of cookies, credentials and those tokens before they leave our servers.
- Sign-in, booking and every other public form is rate-limited.
- We don’t sell data, show ads, or run tracking or session-recording tools.
The companies that help us run Forge are listed in our Privacy Policy, and our commitments to you as a processor are in the Data Processing Agreement.
Reporting a vulnerability
If you think you have found a security problem, email support@forge.page with the subject “Security report”. Include what you found, where, and the steps to reproduce it.
We ask that you:
- give us reasonable time to fix it before telling anyone else;
- only test against your own account, and never access, change or delete other people’s data;
- don’t run denial-of-service, spam or social-engineering tests, or test physical security.
In return, we will:
- reply within three working days, and keep you updated;
- not pursue or support legal action against you for research done in good faith within these rules;
- credit you when it’s fixed, if you would like us to.
We don’t run a paid bug bounty. Our machine-readable contact is at /.well-known/security.txt.