Trust centre · Incidents
Incidents & reporting
One address, two subject tags, a stated acknowledgement target — and a plain account of what exists today versus what arrives with commercial launch.
Reporting
Report a vulnerability or a privacy incident
| Channel | Detail |
|---|---|
| Contact | hello@axforge.ai — currently one operational mailbox, honestly labeled: operational · privacy · security. Dedicated security@ and privacy@ aliases arrive at launch. |
| Subject tag | SECURITY for vulnerability reports · PRIVACY for privacy incidents. The tag routes your report to the right review. |
| Acknowledgement target | 2 business days. |
| PGP key | Not yet published — a PGP key arrives with commercial launch. |
| Public status page | Not yet published — a public status page arrives with commercial launch. |
- Include what you found, where, and how to reproduce it. Please do not include personal data or live customer content in a report.
Breach notification
Our commitment as a processor
Where AxForge processes personal data on a customer's behalf and a personal-data breach occurs, AxForge notifies the affected controllers without undue delay after becoming aware of it, as GDPR Article 33(2) requires. The controller/processor split — which data falls on which side — is set out in the privacy policy and the Data Processing Agreement (draft).
After an incident
How we communicate afterwards
Affected customers are notified directly — not via a blog post they have to find. The notification covers a timeline of what happened, the impact on their data and service, and the remediation taken. Once the public status page ships at commercial launch, service-affecting incidents will also be visible there.
Related
Nearby in the trust centre
Version 0.1 (launch draft) · Effective 2026-08-26
- 2026-08-26 — first published version of this page.