Trust

Security at Forge

Built to survive the same scrutiny your own security team would apply to it.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across every workspace tier.

SSO & fine-grained access

SAML and OIDC single sign-on, SCIM provisioning, and role-based access control on Enterprise plans.

Isolated infrastructure

Enterprise workspaces run AI review, indexing, and CI/CD execution on infrastructure isolated from the shared platform.

Continuous monitoring

Infrastructure and application activity is monitored around the clock, with automated alerting on anomalies.

Immutable audit logs

Every workspace action is written to an audit log that can be streamed to your own SIEM on Enterprise plans.

Independent review

Our infrastructure and access controls undergo regular third-party penetration testing and review.

Forge processes some of the most sensitive material an engineering team has: its source code. Security isn't a feature we bolted on — it's the constraint every other part of the product is built around.

Your code stays yours

Source code connected to Forge is used only to power the features you've explicitly enabled for your workspace — AI review, documentation generation, Knowledge Search, and CI/CD. It is never used to train models shared across other customers, and it is never sold or shared with third parties for their own purposes.

Compliance

Forge maintains a SOC 2 Type II report, available under NDA for teams evaluating the platform. Enterprise workspaces can additionally request infrastructure isolation and private networking configurations to meet stricter compliance requirements.

Reporting a vulnerability

If you believe you've found a security issue in Forge, we want to hear about it. Email security@forge.dev with details and we'll acknowledge your report within one business day.