Protected access
Accounts are tied to user identity, with controlled sessions and recovery through verified channels.
You should know who can access your account, how information is handled, and which controls apply to the product or project you use.
The level of protection depends on the data, operational criticality, and service being used. JM Forge does not claim certifications, guarantees, or controls that have not been validated.
Accounts are tied to user identity, with controlled sessions and recovery through verified channels.
Each user should access only the projects, products, results, and actions allowed for their role.
Data and executions are handled in the correct organization context to reduce cross-customer exposure.
Retention, export, sharing, and deletion follow the product, contract, and intended use.
Executions, relevant changes, and important events can be retained for support, verification, and auditability when applicable.
Monitoring, backups, recovery, and incident communication are defined according to the solution and service level.
Technical credentials, integration keys, and operational secrets are not intended to be exposed in the customer workflow. Access is handled through identity, permissions, and controlled sessions.
Account access, verified email, and controls appropriate to the level of risk.
Credentials and operational secrets remain in the services responsible for execution rather than being exposed in the browser.
Access is scoped by account, organization, and role where supported, and administrative access can be changed or revoked when necessary.
Sessions can expire or be revoked when necessary.
Each product or project should make clear what information is used, why it is needed, how long it is retained, and how export or deletion is handled.
Subscriptions and payments are processed by specialized providers. JM Forge receives the information needed to reconcile payment and manage access, not raw card details.
Specific conditions for security, availability, retention, and support are defined in the relevant product, proposal, or agreement.
Critical integrations, sensitive information, dedicated environments, and regulatory requirements need their own assessment.