Legal
Security Policy
Last updated: January 2026
1. Our Commitment
Security is engineered into every system we build and every process we run. ForgePoint Systems maintains an information security management system aligned with ISO 27001 and holds Cyber Essentials Plus certification.
2. Secure Development Lifecycle
All client projects follow an SDL: threat modeling at design time, automated static and dependency scanning in CI/CD, mandatory peer review, and independent penetration testing before production release.
3. Infrastructure Security
Our cloud environments enforce least-privilege IAM, network segmentation, encryption in transit (TLS 1.3) and at rest (AES-256), centralized audit logging, and continuous vulnerability management across AWS and Azure.
4. Access & Personnel
All staff complete security training at onboarding and annually. Access to client systems requires hardware-backed MFA, and every engagement operates under NDA with time-limited, auditable credentials.
5. Responsible Disclosure
To report a vulnerability in our systems or this website, contact hello@forgepoint.systems with the subject "Security Disclosure". We aim to acknowledge reports within 48 hours.