This document is provided for general information and should be reviewed by your own legal counsel before you rely on it.
Security & Responsible Disclosure
Last updated: June 26, 2026
We take the security of TKO Forge seriously and design it with layered defenses.
How we protect your data
- Encryption in transit (TLS) and at rest.
- Multi-tenant isolation with least-privilege access controls.
- Optional two-factor authentication and a workspace policy to require it.
- Server-side secret storage; secrets are never exposed to the browser.
- Rate limiting, signed links, audit logging, and anti-abuse protections.
- Email compliance controls (unsubscribe handling and suppression).
Reporting a vulnerability
If you believe you've found a security issue, please email legal@tkoforge.com (or see tkoforge.com/.well-known/security.txt). Please:
- Give us reasonable time to investigate and remediate before public disclosure.
- Do not access, modify, or delete data that isn't yours.
- Avoid privacy violations, service degradation, and spam.
We appreciate good-faith research and will not pursue action against researchers who follow this policy.
Contact
Security: legal@tkoforge.com · TKO Cloud Solutions · tkoforge.com.
© 2026 TKO Cloud Solutions. All rights reserved.