Skip to main content

LEGAL / SECURITY

Security

Your business data, treated like it matters. Plain answers about how ERP-Forge isolates, protects, and hands back your data. No badge wall, no vague promises.

STATED FROM THE RUNNING CODEBASEERP-FORGE LEGAL
01

Tenant isolation on every query

Every database query is scoped to your company in the data layer itself, not left to individual screens to remember. Your data never appears in another tenant's workspace.

02

Role-based access control

Permissions are defined per module and per action: who can view costs, who can approve payroll, who can adjust stock. People see exactly what their role allows.

03

Audit logs

Actions across the system are recorded with who, what, and when, so you can trace any change back to a person and a moment.

04

Encryption in transit

All traffic runs over HTTPS with TLS, and the application ships strict security headers including a content security policy.

05

Secure authentication

Passwords are stored as salted hashes, sessions are managed server-side, and sign-in is rate-limited. SSO is available on Enterprise plans.

06

Billing you can verify

Payments run through Stripe. Webhooks are signature-verified and idempotent, and we never see or store your card number.

07

Your data stays yours

Export everything as CSV or JSON at any time. If you cancel, you keep export access for 30 days before deletion. Data deletion requests are honored through a documented process.

  • Full export in open formats, anytime
  • 30-day export window after cancellation
  • Deletion on request through a documented process
08

Found a vulnerability?

Write to security@erp-forge.com and we will respond quickly. We appreciate responsible disclosure.

RELATED DOCUMENTTrust