Forge Security

Security Transparency

Security intake posture.

This summary gives researchers and customer security teams a stable view of Forge's public intake surface. It intentionally avoids private implementation details.

Primary report pathStructured security report form
Security contact[email protected]
PGP public keyPublished public key
Disclosure policyPublished responsible disclosure policy
Public advisoriesNo public advisories published.
Bug bountyForge does not currently operate a paid bug bounty program.
Report identifiersStructured reports receive a Forge Security Report Number for follow-up.
Public boundaryThis page covers public vulnerability intake only, not private customer environments or deployment-specific controls.