Enterprise-Grade by Default
ForgeMD is built with security as a foundation: JWT authentication, bcrypt password hashing, CORS with whitelisted domains, and OWASP-compliant security headers. All data transmitted between your device and our servers uses TLS 1.2 or higher.
Local-First Data Protection
Your content is primarily stored on your device (IndexedDB / encrypted local storage). We do not access, analyze, or mine content stored locally. Cloud sync is optional and only occurs when you explicitly enable it.
Access Control
Role-based access control (RBAC) governs workspace and document permissions. Enterprise customers additionally get SSO (SAML/OIDC), MFA, and audit logs.
Incident Response
In the event of a security incident, affected users are notified within 72 hours of discovery where legally required or where significant risk exists. Post-incident reviews drive preventive measures.