Security

Private research, protected by design.

A concise account of the controls implemented in the current SignalForge architecture.

Authentication

Supabase Auth verifies signed-in users. Protected application routes require verified claims.

Data separation

Cloud records carry authenticated ownership and Supabase Row Level Security is the authoritative isolation layer.

API credentials

Provider keys are encrypted server-side and decrypted in memory only for an authenticated provider request.

Application controls

  • Provider requests execute server-side.
  • Protected routes redirect unauthenticated visitors.
  • The browser receives connection status and a non-secret key hint—not stored ciphertext or plaintext credentials.
  • Production deployment is expected to use HTTPS.
  • Private projects are not intentionally shared between customers.

Responsible limits

No service can promise absolute security. SignalForge does not claim to be unhackable, zero knowledge, or ‘military-grade’. Security controls will continue to be reviewed as Early Access expands.

Report a security concern

A dedicated security address will be published before paid public launch. Early Access users can use the authenticated support channel in the meantime.