Not a log written after the fact. A checkpoint that runs at decision time, outside the system being questioned. You encode the policy, a human keeps authority, and the record verifies offline.
When an agent approves a payment, flags a customer, or changes a setting, the trail it leaves is produced by the same stack under review. That may show what happened. It gives an auditor, a regulator, an insurer or a board no independent basis for why the evidence justified the action.
Not AI policy in the abstract. Specific supervisory language about agents that act, and about firms being unable to reconstruct how the system got there.
Civil penalty in a June 2026 SEC settlement with an asset manager over trade allocation. Charged as a controls failure, not fraud. The gap was evidence that the control ran, at the time, before the trade.
Eighteen months later, in an exam or a deposition, the question is never what the system produced. It is which evidence it relied on, which system asserted that evidence, which rule applied and whether it passed, and who held authority at the moment it mattered. Forge produces that record at decision time and signs it. You keep the underlying material; Forge keeps the proof of what governed the decision and exactly how.
No regulator endorses, approves or certifies any vendor, and nothing above is an endorsement of Forge Orbital. These are obligations landing on firms. We quote them because the firms we build for are the ones who have to satisfy them, and because we would rather show you the demand than assert it. Sources: FINRA 2026 Annual Regulatory Oversight Report; ESMA Supervisory Briefing ESMA74-1505669079-10311; SEC Division of Examinations FY2026 priorities.
Forge sits outside the decision path. It will not mark a decision confident without evidence carrying a named source system and a named constraint or approval. That floor is in the code, it cannot be configured to zero, and nobody here can switch it off for a customer.
No language model anywhere in the signed path. The same inputs produce the same record, every time, which is what makes replay a real check rather than a fresh guess. Unverified control evidence is weighted at zero.
An Ed25519 signature anyone can check with the public key, on a laptop, with no network and no account with us. If we disappeared tomorrow, every record you hold still verifies.
{
"record_id": "FDR-70E6D5554748391E03F3028E28495C97",
"selected_action": "block",
"confidence": 0.5,
"abstained": false,
"assessment_mode": "completed_assessment",
"decision_type": "reviewable_decision",
"workflow_type": "enterprise_agent_pre_action",
"replay_key": "9766c4113426f9171ac1c8757b25c11dad3c9432ad246999f01f8d764663b4ff",
"input_binding": {
"hash_algorithm": "sha256",
"canonicalization": "forge-tagged-json-f64be-v1",
"api_operation_sha256": "6f0367d5afe76e1f12868ef7b0b1fbbe5a05baac1b3d49c8273d68824eb60312"
},
"signature": {
"algorithm": "ed25519",
"schema_version": "forge-record-signature/v2",
"key_id": "ed25519:b3d7a886f4c46d5c83b3e8d717b51a9870ffd54cb805e7595ddcc778f42f8316",
"public_key": "fcHOwf6pUvO7jm6sjHMpFs3dOdlx/2AvuBaQDExoKM0="
}
}
A partner-owned agent proposed a 450 USD refund. The customer’s own policy engine asserted a hard limit of 250. Forge returned block, before execution, naming the constraint and the system that asserted it. There is no dashboard. The record is the interface: it returns to your systems, lands in your evidence store, and a regulator or counterparty verifies it offline with the public key, with no account here and without asking our permission.
A merger-arb research agent re-rates a live deal off expert transcripts, filings and a licensed data feed, and produces a recommendation for the PM order pad. Another desk was wall-crossed on the acquirer financing two weeks ago. These are the numbers the engine actually returned.
X-API-Key: fi_••••
decision_options
execute · hold · escalate · block
evidence[0] 0.72
expert_transcript_library
"Former divisional VP describes
integration cadence consistent
with a Q3 close."
evidence[1] 0.95
sec_edgar
"Merger proxy sets the vote,
no financing condition."
evidence[2] 0.41
alt_data_catalog
"Licence diligence 16 months
stale against a 12-month
policy window."
hard_constraint
issuer_not_restricted
source control_room
passed false
issuer_not_restricted
passed: false
Name restricted since 2026-07-02 under a wall-crossing on acquirer financing. The agent's retrieval window opened after that.
abstained false
confidence 0.50
posterior uniform
posterior_semantics
"uniform_placeholder_
not_inference"
confidence_semantics
"neutral_placeholder_for_
deterministic_rule; not a
probability that the gate
disposition is correct"
signature ed25519
key_id b3d7a886…
The engine did not reason its way to this answer, so it says so. It labels its own posterior uniform_placeholder_not_inference and its own confidence not a probability that the gate disposition is correct. A system that invents a confident-looking number for a decision it reached by rule is the exact thing your regulator is trying to catch. Forge writes down which one happened.
And what it does not do. Forge does not detect material nonpublic information and cannot certify that an agent's context was clean. It records that a named barrier system asserted a result, at a stated time, against a stated list version. It does not observe the agent either: the evidence rows are what your integration declares. What Forge forces is that the enumeration exists, at decision time, and cannot be repudiated afterward.
And it replays either way. This one was blocked, but an execute would carry the same replay_key, the same signed basis and the same evidence rows. Months later an auditor, an LP or a regulator takes the normalized inputs, re-runs them through the same engine version, and gets the same result, or the record does not hold up. The signature proves the bytes are the ones Forge issued. The replay is what proves the content, which is why we keep the two claims separate. Neither check needs our servers, our cooperation, or our continued existence.
The signature proves the authenticity and integrity of the delivered bytes. Deterministic replay is what supports the decision content. We publish that distinction rather than blur it, and the records are tamper-evident under verification.
A notary attests after the fact and has one output. Forge runs before the action, tests it against the rules you encoded, and returns allow, hold, escalate or block. Four outcomes, because something was actually evaluated.
Your logs are written by the stack under review, and they tell you what happened. Forge is outside that stack and records why the evidence justified the action, which is the question an examiner asks and a log cannot answer.
Feature attributions explain a model to a data scientist. Forge records the decision boundary: which named control system asserted what, which rule passed or failed, and where a human held authority. That is what survives a deposition.
Forge takes no authority and executes nothing. You encode the policy, a human keeps authority, and whether your system honours the disposition is a property of your integration, which any assurance argument has to account for openly.
Checking one model with a second model leaves you holding two probabilistic systems and still no ground truth. Forge is deterministic code. The same inputs return the same record every time, which is what makes re-running a decision a check rather than a resample.
There is no language model anywhere in the signed path and the API holds no model keys. Nothing in the record depends on a vendor’s model version, so a decision made today still replays after the model behind your agent has been swapped.
Forge reads from whatever control systems you already run, so the engine fits any high-consequence workflow. We are concentrating first where the regulated decision is sharpest. Select one to explore it.
Once an agent proposes, routes or executes a consequential action, human-in-the-loop review stops being timely, scalable or feasible. The reviewable artifact has to be produced at decision time or it does not exist at all. Forge evaluates the proposed action against the policy you encoded and returns a signed record before it executes, so you keep capacity instead of adding a checkpoint.
Banks, insurers and asset managers already run named control systems: case management, KYC and AML, credit decisioning, limit systems. Those are exactly the named sources the engine reads from. When an automated or agent-assisted call lands inside a critical function, the question from a supervisor is not what happened, it is why it was justified and who held authority.
Underwriting an AI-enabled process needs the model output, the ground truth it is measured against, and an agreed definition of a meaningful error. Ground truth is the hard one, and it gets harder with generative and agentic systems where no labelled answer exists, only ground rules the system is not supposed to break. Forge produces a signed, deterministic record of the rules a decision was evaluated against, at decision time, by a component the model does not control.
An agent produces a determination: a quote, a claim decision, a reserve, a denial. Forge takes the same evidence that agent was given and runs it against the rules you declared, deterministically, outside the model. Where the submitted evidence does not carry the conclusion, Forge names what is missing and signs that finding, and the record replays later for whoever asks, whether that is a counterparty, a market conduct examiner or a court. Forge does not judge whether an assumption was probabilistic, because that cannot be read off an output. It attests to what the evidence does and does not support. What the gap is worth is your number, not ours.
Forge Orbital is a US company and the Forge solution has been assessed as Awardable on the DoD CDAO Tradewinds Solutions Marketplace. The engine was built against high-consequence government requirements, including an evaluation by a national agency on a bounded cislunar space-domain-awareness use case. It runs in your environment or ours, selected by one configuration line.
Nothing in the engine is specific to finance or insurance. It reads evidence from named source systems, applies constraints you declare, and signs the result. Any sector where an automated decision has to be defended later is in scope, and several are already in conversation. We are sequencing rather than excluding, because a design-partner-stage company earns the right to breadth by proving depth first.
No engagement starts with a platform rollout. It starts with one surface you already have to defend: a model under governance, an agent workflow, or a class of decisions that gets challenged. From then on every action inside that surface gets the same deterministic treatment and the same signed record, not a sample and not a demo.
One surface, integrated against your own control systems, with an acceptance test agreed before we start. Real evaluations, signed records, and you verify them yourself offline.
The surfaces that matter, wired properly into the systems you already run. Scoped once against a fixed statement of work rather than billed by the hour, because the integration is the thing that has to survive an examiner. Integration is also where calibration starts: Forge learns from outcomes you attest to, never by training on your data, and no model is fitted to anything you hold. Held-out outcomes score the confidence number against what actually happened, and the map is applied after the action is chosen, so it can sharpen what a number means without ever changing a decision or the way it replays.
Priced against the workflows under record and the deployment shape, hosted or in your environment. Design partners keep preferred terms as coverage expands.
Enterprise only. There is no free tier and no sign-up flow, because every deployment reads from control systems that have to be scoped with a person in the room. Pricing is set against the workflows under record and the deployment shape, and we will give you a number on the first call rather than after four of them. The scoping question is always the same one: which of your existing control systems should we read from.
Any runtime that can call a tool or fire a hook can reach Forge. Without retention opt-in, no calibration row is written. Forge records the basis a customer supplies and signs it; it does not independently inspect, benchmark, validate, certify, or attest the customer's model, vendor, or data. Production deployment is a qualified managed integration, scoped per workflow, and enforcement mode applies only inside an exclusive protected boundary the customer defines. We publish what the signature proves and what it does not, we do not describe records as immutable, and we would rather tell you a limitation than have your engineers find it in an afternoon.
Three years as an executive in defense technology before founding Forge. Built the decision engine and leads the federal and commercial pursuits. BA, Wabash College.
Four years building federal go-to-market at a YC-backed, Series C technology company, most recently as a regional vice president serving US national-security and defense customers. Advises Forge on commercial strategy, enterprise positioning, and regulated-market go-to-market.
Nine years as an intelligence specialist at Naval Special Warfare Command, across geospatial and financial intelligence. Runs business development and partner sourcing, working the financial services and enterprise networks the design-partner motion depends on. MBA ’27, University of Notre Dame.
Download one bounded synthetic Forge proof, its separately stored test-key pin and an edited copy. The original verifies. The edited copy does not. After download, the check needs no Forge account, API credential or network connection.
The embedded public key must derive to the full key ID supplied separately from the proof.
The valid synthetic proof passes against that pin and the complete public payload remains bound to its signature.
The edited copy changes the signed basis. The same verifier fails closed instead of producing a reassuring answer.
mkdir forge-proof-check && cd forge-proof-check
curl --proto '=https' --fail --silent --show-error https://forgeorbital.com/verify/files/forge_verify_public_proof.py -O
curl --proto '=https' --fail --silent --show-error https://forgeorbital.com/verify/files/requirements-verifier.lock -O
curl --proto '=https' --fail --silent --show-error https://forgeorbital.com/verify/files/response.json -O
curl --proto '=https' --fail --silent --show-error https://forgeorbital.com/verify/files/tampered_response.json -O
curl --proto '=https' --fail --silent --show-error https://forgeorbital.com/verify/files/trust_root.json -O
python3.11 -m venv .venv
.venv/bin/python -m pip install --require-hashes --only-binary=:all: -r requirements-verifier.lock
KEY_ID=$(.venv/bin/python -c 'import json; print(json.load(open("trust_root.json"))["key_id"])')
.venv/bin/python forge_verify_public_proof.py response.json --expect-key-id "$KEY_ID"
! .venv/bin/python forge_verify_public_proof.py tampered_response.json --expect-key-id "$KEY_ID"
The delivered public proof has not changed since the pinned test identity signed it, and a changed field is rejected.
It does not certify source truth, policy correctness, outcome quality, compliance or execution authority. Those boundaries remain explicit.
We are working with a small number of design partners to put Forge against real workflows. First conversation is a scoping call, not a pitch.