Trust & Security
At Reforged Labs, your trust is our foundation. We design every system, policy, and tool with one goal: to protect your data and uphold transparency at every stage of our AI solutions.
Data Security
We implement enterprise-grade security across all levels of our infrastructure to safeguard your information.
- Encryption: All data is encrypted in transit (TLS 1.3+) and at rest (AES-256 encryption).
- Access Controls: Role-based access controls (RBAC) with least privilege principles.
- Network Security: Firewalls, intrusion detection, and continuous vulnerability scanning are in place across all environments.
- Secure Development: Our engineering process includes code reviews, dependency auditing, and automated security testing for every release.
- Penetration Testing: External experts conduct regular third-party penetration tests to identify and mitigate risks.
Privacy and Data Handling
We believe your data is yours — not ours.
Reforged Labs only collects data necessary for legitimate service delivery and AI model optimization under explicit consent.
Reforged Labs only collects data necessary for legitimate service delivery and AI model optimization under explicit consent.
- We never train proprietary AI models on your creative assets or marketing data without your permission.
- Data is anonymized or pseudonymized when used for analytics or research.
- Any data used for training or improvement is anonymized, isolated, and opt-in only.
- Our systems comply with GDPR, CCPA, and other applicable data privacy regulations.
- Retention Policy: User data is retained only as long as needed or until you request deletion.
Compliance and Certifications
We align our security and privacy programs with internationally recognized frameworks:
- SOC 2 Type II (in progress)
- GDPR-compliant infrastructure
- ISO 27001-aligned internal controls
- Annual third-party security audits
- Proactive vulnerability disclosure framework
Employee Security and Access
Security is part of our culture.
- Every employee undergoes background screening and mandatory security training.
- Access to sensitive systems follows the principle of least privilege.
- Multi-factor authentication (MFA) is mandatory for all access of company assets.
- Internal access is logged, monitored, and reviewed regularly.
Sharing Your Data
Reforged Labs will never sell your personal information. We may work with third-party service providers (e.g., for payment processing) to deliver services on our behalf. These partners will only use your data for agreed purposes, ensuring compliance with legal requirements.
In certain circumstances, we may be legally obligated to share your data, such as in the case of legal proceedings or regulatory requests.
In certain circumstances, we may be legally obligated to share your data, such as in the case of legal proceedings or regulatory requests.
Infrastructure and Reliability
Our AI infrastructure is built for reliability, scalability, and resilience.
- Hosted on AWS and GCP, leveraging their SOC 2 and ISO-certified data centers.
- Geo-redundant storage with real-time backups and disaster recovery planning.
- Redundant failovers with multi-region replication.
- Disaster recovery and business continuity plans tested quarterly.
- 99.9% uptime SLA with transparent status reporting and monitoring.
Responsible Disclosure
We value the security community's efforts to keep our ecosystem safe.
If you discover a potential vulnerability, please report it responsibly:We investigate every report promptly and appreciate your contributions to improving our platform's safety.
If you discover a potential vulnerability, please report it responsibly:We investigate every report promptly and appreciate your contributions to improving our platform's safety.
Transparency and Incident Response
We maintain a clear, accountable process for handling security incidents.
- Immediate triage and mitigation upon detection.
- Notification to affected users within 72 hours of confirmed incidents.
- Post-incident reviews drive continuous improvements to prevent recurrence.
- Status updates and maintenance notices are published in advance.
Contact Our Security Team
If you have any questions, security concerns, or requests regarding your data:We're always available to help ensure your confidence in Reforged Labs remains unshakable.


