Forge Orbital

Trust and procurement

Your reviewer needs a status, not a disclaimer.

Forge has a built and tested enterprise integration candidate. This page gives vendor risk what it actually asks for: vendor-security answers, no product training on customer data, an IP-safe architecture overview, counsel-review legal templates, and a current status on SOC 2, penetration testing, cyber insurance, CMMC, FedRAMP, and ATO. Enough for diligence. Nothing that pretends to be more.

The procurement set is ready in layers.

Public before fit Trust page, public API overview, onboarding path, vulnerability disclosure, privacy, terms, and this procurement map.
After workflow fit Vendor-security one-pager, no customer-data training statement, data-handling memo, and workflow-specific integration brief.
Security review CAIQ/SIG-style answer bank, non-sensitive architecture overview, deployment options, and current attestation status.
Counsel review NDA, DPA, MSA terms, and integration order-form drafts are available as starting points for counsel. They are not executed terms.

The security posture is stated in plain English.

Data

No product training on customer data.

Forge does not learn across customers. The default is no retention: no calibration row is written. Tenant-local calibration measurement requires an authorized outcome plus a separate, explicit, contracted retention opt-in.

Proof

No generative model in the checked path.

The proof trail is deterministic and replayable. Extraction may happen before the checked path and must stay cited.

Review

Verification has a boundary.

Against an independently provisioned full signing-key ID, verification checks complete-record integrity and signer attribution. Replay separately checks reproducibility from the recorded basis. Neither certifies the customer's evidence or business judgment.

Architecture overview

Useful enough for review, not an IP leak.

Here is what is certified and what is not.

SOC 2 Not certified. SOC 2 is not claimed. Readiness work is staged for the enterprise review path.
Third-party security assessment Not completed or scheduled. Independent application and cryptographic assessment scopes are prepared; no report, certification, or completion date is claimed.
Cyber insurance Not yet bound; being placed ahead of buyer paper.
CMMC, FedRAMP, ATO No CMMC status or certification, FedRAMP authorization, or ATO is claimed. CMMC Level 1 evidence work and Level 2 enclave planning are readiness work only, not a submitted SPRS score or certification.
Federal credential The Forge solution was assessed as Awardable on the U.S. Department of Defense CDAO Tradewinds Solutions Marketplace.

Business and registration, ready to paste into a vendor record.

Legal entity Forge Orbital Inc.
SAM.gov Active registration, renews 2027-06-30.
CAGE code 1ASL5
UEI FNMHTCGY8FK3
Business size General small business. No set-aside socioeconomic status is claimed.

Give procurement the right artifact at the right time.

Before fit, the public pages should answer the shape of the review. After fit, Forge can hand over the questionnaire answers, architecture overview, and counsel-review materials for that buyer and workflow.