Security at Forge
Built to survive the same scrutiny your own security team would apply to it.
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across every workspace tier.
SSO & fine-grained access
SAML and OIDC single sign-on, SCIM provisioning, and role-based access control on Enterprise plans.
Isolated infrastructure
Enterprise workspaces run AI review, indexing, and CI/CD execution on infrastructure isolated from the shared platform.
Continuous monitoring
Infrastructure and application activity is monitored around the clock, with automated alerting on anomalies.
Immutable audit logs
Every workspace action is written to an audit log that can be streamed to your own SIEM on Enterprise plans.
Independent review
Our infrastructure and access controls undergo regular third-party penetration testing and review.
Forge processes some of the most sensitive material an engineering team has: its source code. Security isn't a feature we bolted on — it's the constraint every other part of the product is built around.
Your code stays yours
Source code connected to Forge is used only to power the features you've explicitly enabled for your workspace — AI review, documentation generation, Knowledge Search, and CI/CD. It is never used to train models shared across other customers, and it is never sold or shared with third parties for their own purposes.
Compliance
Forge maintains a SOC 2 Type II report, available under NDA for teams evaluating the platform. Enterprise workspaces can additionally request infrastructure isolation and private networking configurations to meet stricter compliance requirements.
Reporting a vulnerability
If you believe you've found a security issue in Forge, we want to hear about it. Email security@forge.dev with details and we'll acknowledge your report within one business day.