NF / Security
Security at NarrowForge
Small products, narrow permissions, boring infrastructure. What follows is what we actually do — not certifications we don't hold.
Minimum required permissions
Each app requests only the scopes its narrow job needs. If a feature would require broad access, the feature is redesigned or dropped.
Least privilege internally
Production access is limited, logged and tied to a support or maintenance reason.
Encrypted transport
TLS everywhere. No plaintext fallbacks for app traffic or webhooks.
No selling customer data
We do not sell, rent or share customer data for advertising. Data is used to operate the product you installed.
Secure development
Dependency monitoring, code review and small, reviewable releases. Small scope is a security feature.
Responsible disclosure
A clear path to report issues, with acknowledgement and coordinated handling.
Report a security issue
Email security@narrowforge.com with the product, a description and reproduction steps. Include a contact where we can acknowledge receipt. Please do not include live customer data beyond what is needed to reproduce.
We do not claim SOC 2, ISO 27001 or similar certifications. If that changes, it will be stated here with scope and dates.