No Model In The Signed Path
No generative model sits in the signed path. The proof trail is not a generated explanation produced after the fact.
Trust and procurement
Forge is built for the moment a customer has to defend an AI-agent or automated action to security, legal, procurement, an auditor, an insurer, a board, or a regulator. The customer sends a bounded action, evidence, constraints, and a human-review boundary. Forge returns a proof trail the customer can store, review, and verify later.
No generative model sits in the signed path. The proof trail is not a generated explanation produced after the fact.
The result is made for the person who challenges the action later, not just for the system that made the original call.
The default is no retention. Outcome feedback supports calibration measurement only with a separate, explicit, contracted retention opt-in. Forge does not learn across customers or silently train on customer data.
The decision question, allowed action menu, evidence that mattered, rule or constraint that applied, uncertainty that remained, where human authority stayed, and verification material for later review.
The customer keeps the workflow, source systems, final authority, and system of record. Forge evaluates only the actions routed through the Forge integration point.
The default is no retention. The customer may tag what actually happened later, but tenant-local calibration state requires an authorized customer outcome plus a separate, explicit, contracted retention opt-in. Without that opt-in, no calibration row is written. With it, Forge compares its earlier confidence to those outcomes and reports whether that workflow is calibrated, over-confident, under-confident, or still too early to call. Decision, audit, and accountability-record retention is a separate control and follows the deployment and contract.
Synthetic or sanitized data is preferred for the first proof. Restricted or regulated data requires the right agreement, data boundary, security review, and deployment path before use.
Forge is a sidecar proof layer. It does not run the customer's agent, replace the customer's system of record, or take final authority away from the customer.
One bounded action, evidence summaries, constraints, allowed actions, and the human-review boundary.
Deterministic evaluation produces the action disposition, uncertainty, evidence path, and verification material.
The customer stores the returned proof trail in its own vault, GRC tool, case system, ticketing system, or data lake.
With an authorized outcome and an explicit contracted retention opt-in, Forge measures calibration for that tenant and workflow. The default is no retention and no calibration row.
| Product status | The enterprise integration candidate is built and tested. Production use still requires customer-specific security, deployment, acceptance, and operations qualification. |
|---|---|
| SOC 2 | Not certified. SOC 2 is not claimed. Treat formal attestation as a procurement milestone for a broader enterprise rollout. |
| Third-party security assessment | Not completed or scheduled. Independent application and cryptographic assessment scopes have been prepared; no report, certification, or completion date is claimed. |
| Cyber / E&O insurance | Not yet bound; being placed ahead of buyer paper. |
| FedRAMP / ATO | Not authorized. Do not route restricted government data through public commercial endpoints without the required authorization path. |
| CMMC | Not certified. CMMC is not claimed. |
| Legal packet | DPA, MSA, NDA, and integration order-form drafts are available for counsel review. |
| Security contact | security@forgeorbital.com |
After workflow fit, Forge provides a concise diligence package for security, legal, procurement, and engineering review. It answers the first round quickly, without exposing engine internals or customer data.
The public procurement map is available at forgeorbital.com/procurement. Security researchers can use the coordinated disclosure policy. Engineers can reproduce the public positive and negative verification cases at forgeorbital.com/verify.
The fastest way through a security review is a real workflow. Name one high-consequence decision, run it on synthetic or sanitized data, and verify the returned proof trail. The diligence package follows the same request.