Home
Security & Privacy

Your masters, your metadata, your money.

Release Forge is maintained by an independent team. This page describes the practical controls in the app today, not a certification. If a claim ever doesn't match reality, tell us and we'll fix it.

Payments handled by Stripe

All checkouts and subscriptions run inside Stripe's PCI-DSS Level 1 environment. We never see or store your card number, CVC, or expiry. Stripe just sends us a customer reference and subscription status.

Encrypted in transit and at rest

Every request between your browser and Release Forge uses HTTPS (TLS 1.2+). Your data is stored in Supabase (Postgres) with AES-256 encryption at rest on the underlying volumes.

Row Level Security on every table

Release Forge uses Supabase Row Level Security, so a signed-in user's queries can only ever return that user's rows. Even if a bug tried to fetch someone else's data, the database itself would say no.

Least-privilege service credentials

Third-party tokens you paste in Connect Services are stored server-side, masked on display (last 4 chars only), and only ever used to talk to the service you connected. Never resold, never shared.

You own your data

Export your release metadata, collaborator splits and PRO registrations at any time as CSV. Delete your account and we remove your rows on request.

Report a security issue

Found something? Reach us through the Contact form. We take reports seriously and respond within 3 business days.

Shared responsibility

Release Forge secures the platform. You're responsible for keeping your account password strong, protecting the third-party accounts you connect, and reviewing collaborator invites before sharing splits. Use a password manager and enable two-factor authentication on Google if you sign in with it.

Last updated August 2026.