Skip to content
NarrowForge

NF / Security

Security at NarrowForge

Small products, narrow permissions, boring infrastructure. What follows is what we actually do — not certifications we don't hold.

Minimum required permissions

Each app requests only the scopes its narrow job needs. If a feature would require broad access, the feature is redesigned or dropped.

Least privilege internally

Production access is limited, logged and tied to a support or maintenance reason.

Encrypted transport

TLS everywhere. No plaintext fallbacks for app traffic or webhooks.

No selling customer data

We do not sell, rent or share customer data for advertising. Data is used to operate the product you installed.

Secure development

Dependency monitoring, code review and small, reviewable releases. Small scope is a security feature.

Responsible disclosure

A clear path to report issues, with acknowledgement and coordinated handling.

Report a security issue

Email security@narrowforge.com with the product, a description and reproduction steps. Include a contact where we can acknowledge receipt. Please do not include live customer data beyond what is needed to reproduce.

We do not claim SOC 2, ISO 27001 or similar certifications. If that changes, it will be stated here with scope and dates.