Security at a Glance
Encryption: TLS in transit, AES-256 at rest
Data Storage: Offline by default — tools run locally
Tracking: None — we don’t monitor tool usage
Privacy: GDPR-compliant, full data control to you
Servers: Secure cloud hosting with regular audits
How Your Data is Kept Safe
1. Encryption in Transit (TLS 1.2+)
All communication between your browser and ForgeDocks is encrypted. Even if intercepted, data can’t be read. What we encrypt: login credentials, account settings, payment info.
2. Encryption at Rest
Sensitive data on our servers (billing info, passwords) is encrypted using AES-256. Encryption keys are stored separately and rotated regularly.
3. Password Security
Your password is:
- Hashed using bcrypt (one-way encryption)
- Salted to prevent rainbow-table attacks
- Never stored in plain text anywhere
- Required to be strong (8+ characters, mixed case + number)
4. Offline-First Architecture
- Tools run locally — calculations happen in your browser
- No server-side data — tool data never sent to Forge servers
- Offline mode — tools work with no internet
- localStorage only — data stored in your browser, only you can access
What this means: We can’t access your data — we don’t have it. No surveillance. No data leaks from Forge.
5. Account Security
What we do:
- Hashed, salted passwords
- Secure session management
- IP logging for suspicious logins
- Email notification for new device logins
- Optional 2FA (coming soon)
What you should do:
- Use a strong, unique password
- Don’t share login credentials
- Log out on shared devices
- Change password if compromised
- Keep your email secure
6. Regular Security Audits
- Penetration testing: Third-party experts test annually
- Vulnerability scanning: Automated weekly scans
- Code review: All code reviewed before deployment
- Incident response: Issues addressed within 24 hours
7. Compliance & Standards
- GDPR compliant (EU data protection)
- CCPA compliant (California privacy)
- SSL/TLS standard (industry encryption)
- PCI DSS compliant (payment processing via Stripe)
What Forge Does NOT Do
- ❌ We don’t track tool usage
- ❌ We don’t sell your data
- ❌ We don’t sync tool data to servers
- ❌ We don’t use cross-site tracking
- ❌ We don’t collect tool inputs or outputs
What You Control
Your Data
- View: Log in to see what data we have
- Export: Download data in CSV/JSON format
- Delete: Request permanent account deletion
- Download tools: Save to your computer for offline use
Your Privacy Settings
Log in › Account › Preferences to control marketing email opt-in/out, data sharing preferences, communication frequency, and analytics participation.
Third-Party Services
We use these services for infrastructure and payments. All are PCI/GDPR compliant and operate under Data Processing Agreements (DPAs) with Forge.
Stripe: Payment processing · AWS: Cloud hosting · SendGrid: Email delivery
What to Do If You Suspect a Breach
If your account may be compromised
- Change your password immediately
- Check your login activity
- Email security@forgedocks.com with details
- Monitor your payment method
If you find a security vulnerability
Please report it responsibly to security@forgedocks.com. Include what the vulnerability is, how to reproduce it, and any affected systems. We’ll acknowledge within 24 hours.
Best Practices for You
- Use a strong password (12+ characters, mixed case + numbers)
- Enable 2FA when available (coming soon)
- Keep your email secure — it’s your account recovery method
- Don’t share credentials
- Log out on shared devices
- Verify links — phishing emails may impersonate Forge
- Export data regularly and back up to your computer
- Report suspicious activity to security@forgedocks.com
Frequently Asked Questions
Where is my data stored?
Tool data stays on your device only. Account and billing data is stored in encrypted databases on secure cloud servers (AWS EU).
Can Forge employees see my data?
No. Data is encrypted and access is restricted. Tool data is never accessible — it’s on your device.
Can I use Forge in countries with strict data protection?
Yes. We comply with GDPR (EU), CCPA (California), and similar laws globally.
What if Forge gets hacked?
Only encrypted data would be exposed. Passwords are hashed (useless to attackers). Tool data is on your device, not on Forge servers.
Can I use Forge offline?
Yes. All tools work offline. Download once, use anytime, anywhere.
Security question? Email security@forgedocks.com · Privacy question? Email privacy@forgedocks.com