Security.

Operated by Waelas Ltd · last updated September 2026

You trust Forge with your calendar and your clients’ details. Here is how we look after them, and what to do if you find a problem.

How we protect your data

  • Everything is encrypted in transit (HTTPS, with HSTS) and at rest.
  • Calendar access tokens are encrypted a second time by us (AES-256-GCM) before they are stored.
  • We never store passwords, only salted hashes. You can sign in with Google instead.
  • Our database and servers run in London, with point-in-time recovery for the previous seven days.
  • Public links to bookings, invoices, proposals and portals use long, unguessable tokens, and are kept out of search engines.
  • Error reports are stripped of cookies, credentials and those tokens before they leave our servers.
  • Sign-in, booking and every other public form is rate-limited.
  • We don’t sell data, show ads, or run tracking or session-recording tools.

The companies that help us run Forge are listed in our Privacy Policy, and our commitments to you as a processor are in the Data Processing Agreement.

Reporting a vulnerability

If you think you have found a security problem, email support@forge.page with the subject “Security report”. Include what you found, where, and the steps to reproduce it.

We ask that you:

  • give us reasonable time to fix it before telling anyone else;
  • only test against your own account, and never access, change or delete other people’s data;
  • don’t run denial-of-service, spam or social-engineering tests, or test physical security.

In return, we will:

  • reply within three working days, and keep you updated;
  • not pursue or support legal action against you for research done in good faith within these rules;
  • credit you when it’s fixed, if you would like us to.

We don’t run a paid bug bounty. Our machine-readable contact is at /.well-known/security.txt.