Full transparency about how Forge Innovations Limited protects, manages, and secures your financial data.
Security
Six layers of security built into the foundation, not bolted on after.
Our security practices align with the ISO 27001 framework — covering access control, cryptography, operations security, and secure development.
Every account requires TOTP-based two-factor authentication. Verification is enforced on new devices and periodically thereafter.
Accounts are automatically locked after repeated failed login attempts. Admin-only unlock ensures compromised credentials cannot be exploited.
New accounts require manual admin approval before accessing any financial data. No self-service access to sensitive information.
Every database query is scoped to the authenticated user's organisation using PostgreSQL Row-Level Security policies.
All admin actions — user approvals, role changes, data syncs — are recorded in an append-only audit log with timestamps.
Data
A clear breakdown of the data synced from your accounting software.
Integration Scopes
Forge cannot modify, create, or delete any data in your connected accounts. Here are the exact scopes we request:
| OAuth Scope | Purpose |
|---|---|
| openid profile email | Identify your Xero user account |
| accounting.transactions.read | Read invoices, bills, and credit notes |
| accounting.contacts.read | Read customer and supplier contacts |
| accounting.settings.read | Read organisation settings and chart of accounts |
| accounting.reports.read | Read financial reports (Balance Sheet, P&L) |
| payroll.employees.read | Read employee names, employment types, and start dates |
| payroll.payruns.read | Read pay run totals, net pay, PAYE, and KiwiSaver contributions |
Infrastructure
Third-party services that process data on our behalf.
Access to raw data is strictly controlled:
Your Rights
Under the New Zealand Privacy Act 2020, you have the right to:
Request a copy of all personal data we hold about you.
Ask us to correct any inaccurate information.
Request permanent deletion of your data.
Your data remains in Xero — we only hold a synced copy.
For any privacy enquiries, contact us at privacy@forgeinnovations.nz
Request
Whether you're an active client or have previously provided information to Forge, you can request access to, correction of, or deletion of the data we hold. We aim to process all requests within 30 days.