LEGAL / SECURITY
Security
Your business data, treated like it matters. Plain answers about how ERP-Forge isolates, protects, and hands back your data. No badge wall, no vague promises.
Tenant isolation on every query
Every database query is scoped to your company in the data layer itself, not left to individual screens to remember. Your data never appears in another tenant's workspace.
Role-based access control
Permissions are defined per module and per action: who can view costs, who can approve payroll, who can adjust stock. People see exactly what their role allows.
Audit logs
Actions across the system are recorded with who, what, and when, so you can trace any change back to a person and a moment.
Encryption in transit
All traffic runs over HTTPS with TLS, and the application ships strict security headers including a content security policy.
Secure authentication
Passwords are stored as salted hashes, sessions are managed server-side, and sign-in is rate-limited. SSO is available on Enterprise plans.
Billing you can verify
Payments run through Stripe. Webhooks are signature-verified and idempotent, and we never see or store your card number.
Your data stays yours
Export everything as CSV or JSON at any time. If you cancel, you keep export access for 30 days before deletion. Data deletion requests are honored through a documented process.
- Full export in open formats, anytime
- 30-day export window after cancellation
- Deletion on request through a documented process
Found a vulnerability?
Write to security@erp-forge.com and we will respond quickly. We appreciate responsible disclosure.