Security and privacy

Protecting your clients' information is a professional obligation. We treat it as one too.

Last updated: August 18, 2026

You are asking software to read documents your clients trusted you with and your name is on. That deserves a straight answer rather than a badge wall. Here is how TrustForge keeps your data safe.

Where your data lives

Your data stays in a private, secured environment that we operate and control on Microsoft Azure, one of the most trusted platforms in the industry. It is encrypted at all times, so even in the unlikely event someone gained access to the underlying systems, the information itself would be unreadable and could not be copied out.

Getting in

Access to the app is protected by Microsoft's authentication services, the same secure sign-in technology used across enterprise and government systems. Your people sign in with the Microsoft 365 or Google Workspace account they already have. There is no separate TrustForge password for your firm to manage, and access follows whatever controls you already run.

One firm cannot see another

We have built firm-level separation directly into the app, so your firm's data is walled off from every other firm's. There is no possibility of it crossing over.

Nothing leaves

None of your firm's data is ever shared with outside services or third parties. What you put into TrustForge stays in TrustForge.

This is the discipline we came from

Security and privacy matter deeply to my business partner and me. We are not attorneys. We are IT professionals who have spent our careers building secure systems and IT security operations. Protecting sensitive data is the discipline we came from, and we have built TrustForge around it from the ground up.

The attorney stays in control

This is a security property, not just a product one. TrustForge does not edit your documents. It reads a design sheet and a trust, reports where they differ, and cites the passage each flag came from. Every change is made by you, in your own drafting software, after you decide the flag is real.

Still being formalized

TrustForge is in limited release. These are in progress, and we would rather name them than imply we already have them.

Third-party penetration testing and remediation report

SOC 2 Type II readiness assessment

Documented sub-processor list and data processing agreement

Formal incident response and breach notification policy

Business continuity and backup posture

Running a security review

If your firm has a questionnaire or your carrier has requirements, send them over. We will answer honestly, including where the answer is currently no. Reach us at hello@trustforge.estate.