Legal

Security Policy

Last updated: January 2026

1. Our Commitment

Security is engineered into every system we build and every process we run. ForgePoint Systems maintains an information security management system aligned with ISO 27001 and holds Cyber Essentials Plus certification.

2. Secure Development Lifecycle

All client projects follow an SDL: threat modeling at design time, automated static and dependency scanning in CI/CD, mandatory peer review, and independent penetration testing before production release.

3. Infrastructure Security

Our cloud environments enforce least-privilege IAM, network segmentation, encryption in transit (TLS 1.3) and at rest (AES-256), centralized audit logging, and continuous vulnerability management across AWS and Azure.

4. Access & Personnel

All staff complete security training at onboarding and annually. Access to client systems requires hardware-backed MFA, and every engagement operates under NDA with time-limited, auditable credentials.

5. Responsible Disclosure

To report a vulnerability in our systems or this website, contact hello@forgepoint.systems with the subject "Security Disclosure". We aim to acknowledge reports within 48 hours.