Back to home

Security posture

TruthForge handles some of the most sensitive material a company owns: draft statements, board briefings, regulator communications, crisis playbooks. Here is how we protect it.

Workspace isolation

Every client engagement lives in its own workspace, enforced at the database layer with row-level security. Data is never shared across workspaces — not for search, not for aggregation, not for model training.

Encryption

All traffic is TLS 1.2+ in transit. Data at rest is AES-256 encrypted at the storage layer. Secrets are stored in an isolated vault and never surfaced in logs.

No training on your data

Your narrative content, signals, uploaded documents and generated assets are never used to train any model — ours or a third party's. LLM providers are contractually bound to the same restriction.

SOC 2 Type II — in progress

We are actively pursuing SOC 2 Type II certification with a Big Four auditor. Interim controls (access review, logging, incident response) are operational today. Ask on a briefing for the current status letter.

Reporting a vulnerability

If you believe you have found a security issue, please email security@truthforge.ai. We acknowledge within one business day and will keep you informed through remediation.

Last updated September 2026.