Security & Data Integrity

At ForgeDash, we understand that we aren’t just managing your business—we are guarding your livelihood. ForgeDash is built security-first: sensitive fields are encrypted, every business's data is isolated inside the database itself, and every change to your books leaves a permanent record.

01Zero-Exposure Data Encryption

We treat your most sensitive data with absolute isolation.

  • Column-Level Encryption: Your bank details and National Insurance number, and your customers' email addresses and phone numbers, are encrypted in the database — never stored in plain text.
  • Encrypted Everywhere: Traffic is encrypted in transit (TLS), and backups are encrypted before they leave our server. A copied backup without the key is unreadable.
  • Secure Key Management: Encryption keys live in a secrets vault, separate from the data they protect, and are never shipped to your browser.

02Immutable Audit Trails

For financial accountability and HMRC readiness, every action has a permanent record.

  • Universal Logging: Every modification to a ledger entry is automatically captured by our Universal Audit Worker.
  • State Capture: We record the exact "Before" and "After" state of every financial change, providing a complete history for your books.
  • Append-Only: No user, and no part of the application, can edit or delete an audit entry — so your accountant gets one reliable history.

03Proactive System Defense

We don't just react to threats; we build shields against them.

  • Rate Limiting: We implement "Leaky Bucket" protection to prevent unauthorized data scraping or brute-force attacks.
  • Row-Level Isolation (RLS): Every read and write is checked against your business inside the database engine, not just in the app — and automated tests prove another workshop cannot reach your records on every release.
  • Continuous Backups: We use off-site backups and have rehearsed recovery. Backup cadence, recovery point and recovery time are checked operationally; they are not guaranteed by this page.

04Infrastructure & Sovereignty

Your data stays in the EU, on infrastructure we run.

  • EU Residency: Your data is stored on our dedicated server in Germany, with encrypted backups in Stockholm, Sweden. Both are in the EU.
  • Dedicated Server: ForgeDash runs on a dedicated server we operate ourselves, rented from netcup GmbH in Germany — not a shared hosting platform. Backups are stored with Amazon Web Services in Stockholm.
  • Verified Callbacks: Payment events from Stripe are checked against Stripe's signature, and our own background workers authenticate with a shared secret, so nothing outside can post into your books.
  • The "No-Sell" Guarantee: Your financial data is your property. We never sell, rent, or share your data with third-party lenders, brokers, or advertisers.

05Account Security

The front door is as strong as what it protects.

  • Strong Passwords Only: Passwords must be at least 10 characters, and any password that has appeared in a known data breach is refused at sign-up.
  • Re-Authentication: Changing your password requires you to prove it is you again, so an unattended signed-in phone cannot lock you out of your own account.
  • Rotating Sessions: Sign-in sessions use short-lived tokens that rotate automatically. You can also sign in with Google.
  • Passkeys: Sign in with your phone's fingerprint or screen lock, or Windows Hello on your PC, instead of a password. A passkey cannot be phished or reused on another site, and your fingerprint never leaves your device — we only store a public key.

06Built for Compliance

Our architecture is ready for the highest standards by design.

  • Privacy Controls: Full data portability and encrypted storage.
  • Card Payments via Stripe: Card details go straight to Stripe (PCI DSS Level 1) and never touch our servers.
  • ICO Registered: Official registration with the Information Commissioner's Office.

Have questions about our security practices?

Contact Security Team