← Back to ForgeMail

Trust

Security and trust

Last updated: August 6, 2026

ForgeMail is a workspace for company email on domains you verify. Putting DNS and customer conversations through a product means you should know how sign-in, sending rails, deliverability controls, AI assistance, and data retention work. This page states what the product does today — not certifications we have not earned.

Availability

The product is currently offered to businesses located in the United States. Workspace data is processed in the United States. Eligibility details are in the Terms of Use; what we collect is in the Privacy Policy.

Sign-in

You authenticate with Google Identity Services. We store the account fields needed to keep you signed in (name, email, Google subject identifier) and set a session cookie on app.forgemail.app. We do not receive or store your Google password. There is no email/password login.

Sending and receiving rails

Outbound send and inbound receive run on Amazon SES under ForgeMail’s platform configuration. Delivery, bounce, and complaint events arrive via SNS webhooks; those webhooks verify signatures before we act on them. We do not offer bring-your-own AWS SES today.

Domain verification and authentication

Before you send as your brand, you claim a domain and publish DNS records we show you: ownership TXT, DKIM for send authentication, and recommended DMARC for receiver policy. Domains are globally claimed — access for other people is through approved membership on the owning account, not by re-claiming the same domain elsewhere.

Suppression and unsubscribe

Bounces, complaints, and unsubscribes suppress future campaign and transactional mail to that recipient. Compliance footers (physical address and unsubscribe) are injected server-side on outbound campaign and transactional mail; we do not trust client-supplied HTML for those fields.

AI assistance — humans send

On inbound mail, ForgeMail can triage, summarize, and draft a reply in your brand voice. Those artifacts are assistive. Outbound replies require an explicit human send action. The product default is not unsupervised AI replies to customers. ForgeMail does not use customer email content to train ForgeMail’s own models; see the Privacy Policy for AI subprocessors and how message content is processed.

Account scoping

Workspace data — domains, templates, lists, messages, AI artifacts, and suppressions — is scoped to the account that owns it. Users may hold memberships on more than one account; the active session selects which account you are operating in.

Product analytics

When enabled for an environment, we send coarse product-usage events (setup steps, verification outcomes) to PostHog to find friction — not message content. Details are in the Privacy Policy.

Data retention

We retain account and workspace data for as long as your account is active and as needed to operate the Service, meet legal obligations, or resolve disputes. For access, correction, or deletion requests, email hello@forgemail.app. Details on what we collect and which processors we use are in the Privacy Policy.

What this page is not

This is not a SOC 2, ISO, or similar certification claim. When those attestations exist, we will say so here. Until then we describe the controls you can inspect in the product.

Contact

Security or trust questions: hello@forgemail.app.

Related: Privacy Policy · Terms of Use.