SECURITY & TRUST

Protecting the data behind every creator decision.

Streamforge treats confidentiality, integrity, and availability as operating requirements—not a checklist.

Our controls are designed to limit access, protect sensitive data, surface weaknesses, and respond quickly when something needs attention.

Independent validation

Application security evidence reviewed for Google OAuth restricted scopes.

OUR COMMITMENTS

Security is an operating practice.

These commitments shape how we design, operate, and improve Streamforge.

01

Preventative controls

We use access controls, protected secrets, encrypted managed databases, and repeatable deployment configuration to reduce avoidable risk.

02

Vulnerability management

We assess application security, remediate findings, and revalidate the platform through required reassessments.

03

Responsible disclosure

We investigate reports that may affect the platform or customer data and coordinate fixes with the reporter when appropriate.

04

Incident response

Security issues are triaged by severity, escalated to engineering, contained, and reviewed for follow-up improvements.

05

Privacy and data handling

We limit our use of connected-service data to the features customers authorize and document those practices in our Privacy Policy.

INDEPENDENT ASSURANCE

Verified for the Gmail access Streamforge uses.

The assurance below is tied to our Google OAuth application and its restricted Gmail scopes.

APPROVED · MAY 2026

Google OAuth App Verification

Google approved Streamforge for the restricted Gmail read-only and send scopes after the required verification process. Recertification is required annually.

SCOPE · GMAIL READ-ONLY + SEND

INDEPENDENT ASSESSMENT

CASA Tier 2 validation

TAC Security reviewed the application scan, remediation, Self-Assessment Questionnaire, and supporting evidence, then submitted Streamforge’s Letter of Validation to Google.

PROGRAM · GOOGLE OAUTH RESTRICTED SCOPES

Scope note

This assurance is specific to Streamforge’s Google OAuth application and Gmail scopes. It is not a SOC 2 Type I or Type II report.

CONTROL HIGHLIGHTS

Evidence reviewed during assessment.

A practical view of the safeguards included in Streamforge’s supporting evidence.

01 / DATA

Encryption at rest

Managed database storage used in the assessment is encrypted at rest using LUKS.

02 / APPLICATION

Sensitive-data redaction

Sensitive fields are removed from the logging and API serialization paths included in the assessment evidence.

03 / IDENTITY

Secure account recovery

Password reset codes are cryptographically random, time-limited, and invalidated after use.

04 / OPERATIONS

Reproducible operations

Security-relevant deployment and configuration evidence is version-controlled and repeatable.

RESPONSIBLE DISCLOSURE

Report a security issue.

Email security@streamforge.com with a clear description, the affected URL or feature, steps to reproduce, and any supporting evidence. Please avoid accessing or changing data that does not belong to you.