Security & Trust

Your manufacturing data, protected by design

ForgeSphere security architecture
Multi-tenant isolation

Every operational table carries organization_id. Row-level security policies make cross-tenant reads or writes impossible.

Encryption in transit & at rest

TLS 1.2+ everywhere. Database encrypted at rest. Signed URLs for private files.

Granular RBAC

27 default roles, per-module/action permissions, approval rules by value, department and margin.

Immutable ledgers

Posted inventory and financial transactions are append-only. All changes are audited.

Audit trail

Every sensitive action is recorded with actor, before/after data, timestamp and IP.

Permission-aware AI

The copilot follows the user's permissions and never posts transactions without explicit human approval.