Trust & Security

Your data stays where you put it.

For businesses that need their data on infrastructure they control, ForgeSend offers Private Deployment — a dedicated setup arranged directly with the team. AES-256-GCM encryption at rest. No telemetry. No surprises.

How we protect your data

01Architecture

Built for control

For businesses that need their data on infrastructure they control, ForgeSend offers Private Deployment — a dedicated setup arranged directly with the team. Your data never touches our infrastructure unless you choose the cloud-hosted tier.

02Encryption

AES-256-GCM credential encryption

Every OAuth token and SMTP credential stored in ForgeSend is encrypted at rest with AES-256-GCM using a key you control. The encryption key lives in your environment — not in the database. Even a full database dump exposes no usable credentials.

03Transparency

Transparent by design

ForgeSend is proprietary software. The send path and encryption implementation are transparent to your team — no telemetry callbacks, no obfuscated modules, and no hidden billing layers. Every external call your deployment makes is to providers you configured.

04Isolation

Workspace isolation

Every piece of data in ForgeSend — contacts, campaigns, inboxes, enrichment ledger entries — is scoped to a workspace. Cross-workspace access is enforced at the service layer, not just in the UI. Multi-tenant deployments keep client data fully separated.

Security specification

Credentials at restAES-256-GCM, key in env
TransportTLS 1.3 for all API + SMTP connections
Auth tokensJWT in httpOnly cookies, 7-day expiry
Two-factor authTOTP 2FA via any authenticator app, with backup codes
Password hashingbcrypt with per-user salt
OAuth tokensEncrypted before write, decrypted on use
SMTP passwordsAES-256-GCM, never stored in plaintext
Workspace isolationEnforced at service layer per request
Data ownershipPrivate Deployment: all data stays on infrastructure you control. Cloud: standard SaaS.
Audit logEvery action tracked with actor attribution (Manual, AI Assistant, or API Key) and expandable per-record detail

What we will never do.

Six hard commitments. Not aspirations — these are things we will not do regardless of commercial pressure.

Sell or share your data

Your contacts, campaigns, and pipeline data are never sold, licensed, or shared with any third party under any condition.

Train AI models on your data

Your sequences, lead lists, and campaign content are never used to train AI models. When AI processes your input, it returns output — nothing is retained.

Access your inbox without consent

Email integrations are opt-in and revocable at any time. We do not access mailbox content outside of explicit connection grants.

Store your card details

Payment card data never touches ForgeSend servers. All card processing is handled directly by Stripe (PCI DSS Level 1). We retain only an encrypted payment reference token.

Allow cross-workspace data access

Workspace isolation is enforced at the database and service layer. No user, support agent, or process can query data across workspace boundaries.

Retain data after account deletion

After cancellation or termination, you have 30 days to export your data. After that export window, deletion begins. Personal data — including backup copies — is permanently deleted within 90 days of the termination date. There is no hidden retention window.

Staff access policy

ForgeSend staff cannot access your workspace data.

Under normal operations, no employee has access to workspace contents — contacts, campaigns, inbox data, or enrichment records. Support investigations require explicit authorisation, are fully logged, and are conducted only with the account holder's knowledge. With Private Deployment, you control access to your own infrastructure entirely — we have no path into it.

Data residency

Cloud tier data is hosted in the United Kingdom.

All cloud-hosted ForgeSend accounts are stored on servers physically located in the United Kingdom. Data is not replicated to regions outside the UK without explicit disclosure. Private Deployment customers choose their own residency — your infrastructure, your jurisdiction.

Sub-processors

ForgeSend uses sub-processors according to deployment model. Stripe is used for billing where applicable. Anthropic is used for ForgeSend-managed cloud AI Copilot only — Private Deployment customers do not use ForgeSend-managed Anthropic processing by default.

Stripe
PurposePayment processing
DataBilling data only
RegionUK / US
AnthropicCloud only
PurposeAI sequence generation
DataPrompt content only
RegionUS
Google Cloud Storage
PurposeFile storage
DataUploaded files
RegionUK
Backblaze B2
PurposeBackup storage
DataDatabase backups
RegionEU

Who you're dealing with.

ForgeSend is operated by a registered UK company. You can verify these details independently.

Registered nameStudio Launch Ltd
Company number16430935
JurisdictionEngland and Wales
Registered officeTwelve Quays House, Egerton Wharf, Wirral, CH41 1LD
GDPR roleData processor — you remain the data controller
Verify on Companies House →Read the DPA →
Private Deployment

ForgeSend offers Private Deployment for qualified businesses — none of the platforms audited on the ForgeSend compare hub publicly offer an equivalent.

For businesses that need their data on infrastructure they control, ForgeSend offers Private Deployment — a dedicated setup arranged directly with the team. Your lead lists never touch ForgeSend-managed servers. Your credentials are yours.

Explore Private Deployment →

Infrastructure & compliance

🔒
Encryption in transit
TLS 1.3 for all API and SMTP connections
🗄️
Encryption at rest
AES-256-GCM for all stored credentials and tokens
💾
Data backup
PostgreSQL backups built in for Private Deployment
🇬🇧
UK GDPR posture
ForgeSend cloud is hosted in the UK and supported by a DPA. With Private Deployment, lead and campaign data stays on infrastructure you control.
📋
SOC 2 in progress
Certification planned for the cloud-hosted tier
📬
Responsible disclosure
Found a vulnerability? Email [email protected]
View live system status at status.forgesend.cloud →

Common questions

Can I get ForgeSend as a Private Deployment?

Yes, for qualified businesses. Private Deployment is a dedicated setup arranged directly with the team — reach out to discuss your requirements.

Where is the encryption key stored?

The AES-256-GCM encryption key is a base64-encoded 32-byte value that lives in your .env file as ENCRYPTION_KEY_BASE64. It is never written to the database. If someone obtains a database dump without the key, all stored credentials are unreadable.

What data does ForgeSend send to Anthropic?

Private Deployment instances make no calls to Anthropic by default. The AI Sequence Copilot feature on the cloud-hosted tier uses the Anthropic API to generate sequence copy — your prompt structure is processed to produce output; no lead data or credentials are sent. Private Deployment customers who enable AI Sequence Copilot supply their own Anthropic API key. Sending infrastructure never touches Anthropic.

What is the difference between Private Deployment and cloud-hosted?

Private Deployment: a dedicated setup on infrastructure you control, arranged directly with the team, with no per-seat fee. Cloud-hosted: we run ForgeSend for you, standard SaaS data handling applies, SOC 2 certification is in progress for this tier.

What happens to my data if I cancel?

You can export everything at any time — contacts, campaigns, inbox history — before cancelling. After cancellation, you have 30 days to export your data. After that export window, deletion begins. Personal data — including backup copies — is permanently deleted within 90 days of the termination date. There is no hidden retention window and no re-activation lock-in.

Who can access my data?

ForgeSend staff cannot access workspace data under normal operations. Support investigations require explicit authorisation, are fully logged, and are conducted only with the account holder's knowledge. With Private Deployment, you control access to your own infrastructure entirely — we have no access to it.

Does ForgeSend support UK GDPR requirements?

ForgeSend cloud data is hosted in the United Kingdom. A Data Processing Agreement is available for customers that need processor terms covering sub-processors, data retention, security measures, and breach notification under UK GDPR. Private Deployment customers run the core platform on infrastructure they control, giving them direct control over where their data is stored.

Is a signed DPA available?

Yes. ForgeSend provides a Data Processing Agreement covering how Studio Launch Ltd processes personal data on behalf of customers as a data processor under UK GDPR. It covers sub-processors, data retention, security measures, breach notification, and data subject rights. You can read it on the Data Processing Agreement page.

Where is my cloud data stored?

ForgeSend cloud data is hosted on servers physically located in the United Kingdom. Data is not replicated to regions outside the UK without explicit disclosure. Private Deployment customers choose their own infrastructure and jurisdiction.

Your data. Your rules.

Private Deployment for businesses that need it. AES-256-GCM encryption. No telemetry. No surprises.

Security posture last reviewed: June 2026