Skip to main content
The Forgeby HustleForge

How The Forge protects your business

One place for every Forge policy and control — plainly stated, kept current, and never overstated.

AI use & disclosure

Parts of The Forge use AI to draft, summarize, and route information faster than a person could alone — for example, drafting a reply or flagging an anomaly for review. AI-assisted output is labeled where it appears, and anything that commits your business (a sent message, a charge, a schedule change) requires a human to approve it before it takes effect. We do not use your business data to train models for other customers.

Data ownership & export

Your business data belongs to you. You can export your customers, jobs, and records at any time in a standard format, and you keep that data if you leave The Forge. We do not sell your data, and we do not share it with other customers or unrelated third parties.

Encryption

Data is encrypted in transit (TLS) between your devices and The Forge, and encrypted at rest in our production data stores. Secrets and credentials are stored in dedicated secret managers, not in application databases or source code.

Access controls

Access to your business's data is scoped to your business — employees see only what their role permits, and every account is protected by strong sign-in (including optional multi-factor authentication). Administrative access to production systems is limited to the people who need it to keep the platform running, and that access is logged.

Every Forge policy, in one place

Read the full detail behind any of the summaries above, or the legal terms that govern your account.

Security

Buyer-facing overview of access, encryption, monitoring, and backups.

View Security

Security FAQ & Architecture

Security by role, industry data boundaries, how a control matures, and how a request flows end to end.

View Security FAQ & Architecture

Security Control Inventory

The full control-by-control registry — current status, scope, limitations, and verification dates for every security control.

View Security Control Inventory

Certification Status

Where The Forge stands on SOC 2, ISO 27001, HIPAA, and PCI DSS — stated plainly.

View Certification Status

Shared Responsibility

What HustleForge protects and what your business controls.

View Shared Responsibility

Integration Security

How connections to your accounting, payroll, payment, and industry systems are authorized, scoped, monitored, and revoked.

View Integration Security

Privacy Policy

What personal information we collect, why, and how you can access, correct, or delete it. Includes our call-recording and transcription disclosure (Section 9).

View Privacy Policy

Submit a Privacy Request

A short form to request access, correction, deletion, export, or an opt-out — no account required.

View Submit a Privacy Request

Accessibility Statement

Our accessibility target and how to reach us if you hit a barrier using the site or the platform.

View Accessibility Statement

Subprocessors

Every third party that touches your data in the course of running The Forge, and what each one does.

View Subprocessors

Terms of Service

The agreement that governs use of The Forge website and platform.

View Terms of Service

Refund Policy

How refunds and cancellations work across Forge plans and services.

View Refund Policy

Ready to see how The Forge fits your business?