Security & data protection

Security that is clear enough to understand and strong enough to trust.

Security should be understandable to the people who depend on it.

You should know who can access your account, how information is handled, and which controls apply to the product or project you use.

What customers can expect

Controls designed to protect the operation without getting in the way of the work.

The level of protection depends on the data, operational criticality, and service being used. JM Forge does not claim certifications, guarantees, or controls that have not been validated.

01

Protected access

Accounts are tied to user identity, with controlled sessions and recovery through verified channels.

02

User and team permissions

Each user should access only the projects, products, results, and actions allowed for their role.

03

Organization separation

Data and executions are handled in the correct organization context to reduce cross-customer exposure.

04

Control over information

Retention, export, sharing, and deletion follow the product, contract, and intended use.

05

History and traceability

Executions, relevant changes, and important events can be retained for support, verification, and auditability when applicable.

06

Response and continuity

Monitoring, backups, recovery, and incident communication are defined according to the solution and service level.

Secure experience

You use the solution. The infrastructure keeps technical secrets out of the user experience.

Technical credentials, integration keys, and operational secrets are not intended to be exposed in the customer workflow. Access is handled through identity, permissions, and controlled sessions.

01

Verified account access

Account access, verified email, and controls appropriate to the level of risk.

02

Sensitive credentials stay server-side

Credentials and operational secrets remain in the services responsible for execution rather than being exposed in the browser.

03

Controlled team access

Access is scoped by account, organization, and role where supported, and administrative access can be changed or revoked when necessary.

04

Revocable sessions

Sessions can expire or be revoked when necessary.

Information lifecycle

Data should have a defined purpose, context, and lifecycle.

Each product or project should make clear what information is used, why it is needed, how long it is retained, and how export or deletion is handled.

  • Collection limited to the intended purpose
  • Separation across accounts, organizations, and projects
  • Retention defined by product or contract
  • Controlled export and deletion processes
Payments

Card details are handled by the payment provider, not stored by JM Forge.

Subscriptions and payments are processed by specialized providers. JM Forge receives the information needed to reconcile payment and manage access, not raw card details.

Transparency

Security boundaries, limits, and responsibilities should be stated clearly.

Specific conditions for security, availability, retention, and support are defined in the relevant product, proposal, or agreement.

Specific requirements

Security requirements should match the risk of the process and the data.

Critical integrations, sensitive information, dedicated environments, and regulatory requirements need their own assessment.