Your data, protected.
Forward CRM is built for operators who can't afford a leak. Here's exactly how we keep your contacts, notes, and pipeline safe.
All traffic is encrypted with TLS 1.2+. Data at rest is encrypted with AES-256 on managed Postgres and object storage.
Email + password with industry-standard hashing, optional Google sign-in, and an optional 4–8 digit PIN lock to gate sensitive screens on shared devices.
Every record is scoped to your account via row-level security policies enforced at the database. No customer can read another customer's data.
Hosted on SOC 2 Type II compliant cloud infrastructure with automated backups, point-in-time recovery, and 24/7 monitoring.
Only a small number of engineers can access production, with audit logging on every action. Support never sees your data unless you explicitly share it.
We don't sell your data and never use your CRM contents to train AI models. You can export or permanently delete your data at any time.
Data location & retention
Customer data is stored in the United States by default. Backups are retained for 30 days. If you delete your account, we permanently erase your data within 30 days, except where retention is required by law (e.g. billing records).
Subprocessors
We use a short list of vetted subprocessors for hosting, payments, email delivery, and AI inference. Each is bound by a data processing agreement. Email hello@forwardcrm.app for the current list.
AI & your data
When you use the AI notepad, the relevant text is sent to a model provider to generate structured output. We do not allow providers to train on your content and do not retain prompts beyond the time needed to return a response.
Incident response
If we detect a security incident affecting your data, we'll notify impacted accounts by email within 72 hours along with the steps we're taking to remediate.
Report a vulnerability
Found something? Please email security@forwardcrm.app with a description and reproduction steps. We respond within 2 business days and won't pursue researchers acting in good faith.