Security & data.
What we do to keep your company's data separated, permissioned, and yours.
Authenticated access
Every account signs in through Firebase Authentication. ClearForge never stores your password in plain text.
Company separation
Every company's data is isolated by rule at the database level — one company can never read another's projects, users or files.
Role-based permissions
Admin, General and External roles each get exactly the access they need, enforced on the server — not just hidden in the app's UI. See our Roles page for the full breakdown.
External-user restrictions
Client and partner seats are read-only by default, with one specific exception: completing a sign-off they were sent.
Activity history
Items and sections keep a timestamped activity trail of what changed and when.
Cloud infrastructure
Data is stored on Google Cloud's Firestore and Storage — the same infrastructure Google's own products run on.
Data export
Cancel any time and you get a 30-day window to download a full export of your company's data, including photos, before it's permanently deleted.
Retention and deletion policies are still being finalised as part of our legal review — this page will be updated once they're confirmed.