Forward
Security

Your CRM data is safe here.

Forward is designed to hold the relationships that matter to your business. Here's exactly how we protect that data — from the moment you write it down to the day you delete it.

Encrypted at every layer

Your browser talks to Forward over TLS 1.2+. Your data is stored on encrypted Lovable Cloud managed Postgres and object storage. We never store passwords or PINs in plain text.

Identity is your own

Sign in with email and password, or Google OAuth. Add an optional 4–8 digit PIN to lock sensitive screens on shared devices. Forward only works for your account.

One account, one database view

Every contact, deal, note, and task is walled off from every other account at the database level. The database itself enforces the boundary, not just app code.

Managed, patched cloud infrastructure

Forward runs on Lovable Cloud, a managed Supabase environment. The platform handles database patching, scaling, and security hardening so we can focus on keeping the product safe.

Automatic daily backups

Your database is backed up daily with roughly 14 days of retained snapshots. If something goes wrong, you can restore to a recent snapshot from the Cloud dashboard.

Your data is not the product

We do not sell your data, share it with advertisers, or use your CRM content to train AI models. You can export everything or permanently delete your account at any time.

Least-privilege access

Support staff cannot browse your CRM data. We access production only when required for operational support, and only with audit trails. You control what you share.

Continuous security checks

Lovable runs built-in security scans on code, dependencies, and database policies. Critical findings block publishing until they're resolved, so issues don't reach production.

What happens to your data

Your contacts, notes, deals, and email history live in your own isolated database row space. They are encrypted at rest, transmitted securely, and only available when you are signed in. We do not use your content for product analytics, AI model training, or marketing segmentation. You can request a full export or delete your account at any time; deletion is permanent within 30 days except where the law requires us to keep billing records.

Backups & availability

Forward is hosted on Lovable Cloud, which provides a managed PostgreSQL database with automatic daily backups. Approximately 14 days of snapshots are retained, and you can restore to any available snapshot from the Cloud dashboard. Restoring rolls your data back to that snapshot, so any work done after that point will need to be re-entered. The platform also scales the backend and runs the app on a global edge network so your data is available when you need it.

Email sync

When you connect Outlook, Forward only reads the metadata and content needed to log emails to your contacts. We do not store your email password. OAuth access is scoped to Mail.Read and can be revoked by you at any time from your Microsoft account.

AI & your content

AI Note and the assistant send relevant text to model providers to turn notes into structured CRM data. Providers are not allowed to train on your content, and we do not retain prompts beyond the time needed to return a response. If you use the assistant to read documents, those files are only accessed when you explicitly ask.

Subprocessors

We rely on a small, vetted list of subprocessors for hosting, payments, email delivery, and AI inference. Each is bound by a data processing agreement appropriate to its role. Email hello@forwardcrm.live for the current list.

Incident response

If we detect a security incident that affects your data, we will notify impacted accounts by email within 72 hours with an explanation of what happened and the steps we are taking.

Report a vulnerability

Found something? Please email security@forwardcrm.live with a description and reproduction steps. We respond within 2 business days and won't pursue researchers acting in good faith.