Trust and procurement

What your procurement and security teams need.

Forge is live and tested, at design-partner stage. Start here for security answers, data handling, architecture and legal review. The status table below states what is certified, planned or not claimed. It is separate from the review of your own deployment.

Documents for each stage of review.

Public before fit Trust page, public API overview, onboarding path, vulnerability disclosure, privacy, terms, and this procurement map.
After workflow fit Vendor-security one-pager, no customer-data training statement, data-handling memo, and workflow-specific integration brief.
Security review CAIQ/SIG-style answer bank, non-sensitive architecture overview, deployment options, and current attestation status.
Counsel review NDA, DPA, MSA terms, and pilot order-form drafts are available as starting points for counsel. They are not executed terms.

The security posture is stated in plain English.

Data

No product training on customer data.

Forge does not learn across customers. The default is no retention: no calibration row is written. Tenant-local calibration measurement requires an authorized outcome plus a separate, explicit, contracted retention opt-in.

Proof

No generative model in the checked path.

The proof trail is deterministic and replayable. Extraction may happen before the checked path and must stay cited.

Review

Verification has a boundary.

Against an independently provisioned full signing-key ID, verification checks complete-record integrity and signer attribution. Replay separately checks reproducibility from the recorded basis. Neither certifies the customer's evidence or business judgment.

Architecture overview

Where Forge sits in your systems.

Here is what is certified and what is not.

SOC 2 Not certified. SOC 2 is not claimed. Readiness work is staged for the enterprise review path.
Third-party security assessment Planned. Not yet engaged; an independent security assessment is planned before production rollout.
Cyber insurance Not yet bound; being placed ahead of buyer paper.
CMMC, FedRAMP, ATO No CMMC status or certification, FedRAMP authorization, or ATO is claimed. CMMC Level 1 evidence work and Level 2 enclave planning are readiness work only, not a submitted SPRS score or certification.
Federal credential The Forge solution was assessed as Awardable on the U.S. Department of Defense CDAO Tradewinds Solutions Marketplace.

Company and registration details.

Legal entity Forge Orbital, Inc.
SAM.gov Active registration, renews 2027-06-30.
CAGE code 1ASL5
UEI FNMHTCGY8FK3
Business size General small business. No set-aside socioeconomic status is claimed.

Bring your review requirements.

Use these public pages for an initial review. Once we agree the scope, ask for the questionnaire answers, architecture overview and legal materials your team needs.