Trust and procurement

Evidence an outside reviewer can check.

Your security team, auditor or regulator may need to understand an AI action long after it happened. You supply the proposed action, evidence, rules and approval requirements. Forge returns a proof trail you can store, review and independently verify.

No Model In The Signed Path

No generative model sits in the signed path. The proof trail is not a generated explanation produced after the fact.

Outside Review Built In

The result is made for the person who challenges the action later, not just for the system that made the original call.

No Product Training On Customer Data

The default is no retention. Outcome feedback supports calibration measurement only with a separate, explicit, contracted retention opt-in. Forge does not learn across customers or silently train on customer data.

What The Proof Trail Contains

The decision question, allowed action menu, evidence that mattered, rule or constraint that applied, uncertainty that remained, where human authority stayed, and verification material for later review.

What The Customer Keeps

The customer keeps the workflow, source systems, final authority, and system of record. Forge evaluates only the actions routed through the Forge integration point.

Calibration Without Silent Training

The default is no retention. The customer may tag what actually happened later, but tenant-local calibration state requires an authorized customer outcome plus a separate, explicit, contracted retention opt-in. Without that opt-in, no calibration row is written. With it, Forge compares its earlier confidence to those outcomes and reports whether that workflow is calibrated, over-confident, under-confident, or still too early to call. Decision, audit, and accountability-record retention is a separate control and follows the deployment and contract.

Data Boundary

Synthetic or sanitized data is preferred for the first proof. Restricted or regulated data requires the right agreement, data boundary, security review, and deployment path before use.

How Forge Fits

Forge is a sidecar proof layer. It does not run the customer's agent, replace the customer's system of record, or take final authority away from the customer.

Input

One bounded action, evidence summaries, constraints, allowed actions, and the human-review boundary.

Forge Evaluation

Deterministic evaluation produces the action disposition, uncertainty, evidence path, and verification material.

Customer Storage

The customer stores the returned proof trail in its own vault, GRC tool, case system, ticketing system, or data lake.

Outcome Measurement

With an authorized outcome and an explicit contracted retention opt-in, Forge measures calibration for that tenant and workflow. The default is no retention and no calibration row.

Forge Orbital procurement posture (current as of July 2026)
Product statusLive, tested, enterprise-grade, and enterprise-ready. Design-partner stage.
SOC 2Not certified. SOC 2 is not claimed. Treat formal attestation as a procurement milestone for a broader enterprise rollout.
Third-party security assessmentPlanned. Not yet engaged; an independent security assessment is planned before production rollout.
Cyber / E&O insuranceNot yet bound; being placed ahead of buyer paper.
FedRAMP / ATONot authorized. Do not route restricted government data through public commercial endpoints without the required authorization path.
CMMCNot certified. CMMC is not claimed.
Legal packetDPA, MSA, NDA, and pilot order-form drafts are available for counsel review.
Security contactsecurity@forgeorbital.com

Enterprise Diligence Materials

After workflow fit, Forge provides a concise diligence package for security, legal, procurement, and engineering review. It answers the first round quickly, without exposing engine internals or customer data.

The public procurement map is available at forgeorbital.com/procurement. Security researchers can use the coordinated disclosure policy.

Available Before Sensitive Data

  • Vendor-security one-pager.
  • No customer-data training statement.
  • Public API overview.
  • Public security intake and disclosure policy.

Available For Diligence

  • Questionnaire-style answer bank.
  • Non-sensitive architecture overview.
  • DPA, MSA, NDA, and pilot order-form drafts for counsel.
  • SOC 2, pentest, and cyber insurance status statement.

Bring one decision and check the proof yourself.

The fastest way through a security review is a real workflow. Name one high-consequence decision, run it on synthetic or sanitized data, and verify the returned proof trail. The diligence package follows the same request.