Security without unsupported claims
CloudForge documents controls that are actually implemented. Framework support is not a certification.
Framework support
Technical safeguards
EU data residency
Production and customer data for the current service are operated in the EU; customer-specific contractual commitments are documented separately.
Transport encryption
Public endpoints use HTTPS. Internal transport and certificate configuration are monitored operationally.
Tenant isolation
API access is constrained through organization context, roles and server-side tenant checks.
MFA for privileged roles
Platform and privileged organization roles require MFA and a verified session.
Auditable administration
Critical user, MFA, membership and organization changes are stored as audit events.
Secure delivery
Release contracts, type checks, tests, isolated preflights, health checks and controlled rollback are part of deployment.
Vulnerability disclosure
Found a security issue? Report it directly. We will acknowledge receipt as quickly as possible.
security@cloudforge.teamResponsible disclosure. Do not publish exploit details before a coordinated fix.