Forge Orbital

Trust and procurement

The proof has to hold when someone outside the workflow checks it.

Forge is built for the moment a customer has to defend an AI-agent or automated action to security, legal, procurement, an auditor, an insurer, a board, or a regulator. The customer sends a bounded action, evidence, constraints, and a human-review boundary. Forge returns a proof trail the customer can store, review, and verify later.

No Model In The Signed Path

No generative model sits in the signed path. The proof trail is not a generated explanation produced after the fact.

Outside Review Built In

The result is made for the person who challenges the action later, not just for the system that made the original call.

No Product Training On Customer Data

The default is no retention. Outcome feedback supports calibration measurement only with a separate, explicit, contracted retention opt-in. Forge does not learn across customers or silently train on customer data.

What The Proof Trail Contains

The decision question, allowed action menu, evidence that mattered, rule or constraint that applied, uncertainty that remained, where human authority stayed, and verification material for later review.

What The Customer Keeps

The customer keeps the workflow, source systems, final authority, and system of record. Forge evaluates only the actions routed through the Forge integration point.

Calibration Without Silent Training

The default is no retention. The customer may tag what actually happened later, but tenant-local calibration state requires an authorized customer outcome plus a separate, explicit, contracted retention opt-in. Without that opt-in, no calibration row is written. With it, Forge compares its earlier confidence to those outcomes and reports whether that workflow is calibrated, over-confident, under-confident, or still too early to call. Decision, audit, and accountability-record retention is a separate control and follows the deployment and contract.

Data Boundary

Synthetic or sanitized data is preferred for the first proof. Restricted or regulated data requires the right agreement, data boundary, security review, and deployment path before use.

How Forge Fits

Forge is a sidecar proof layer. It does not run the customer's agent, replace the customer's system of record, or take final authority away from the customer.

Input

One bounded action, evidence summaries, constraints, allowed actions, and the human-review boundary.

Forge Evaluation

Deterministic evaluation produces the action disposition, uncertainty, evidence path, and verification material.

Customer Storage

The customer stores the returned proof trail in its own vault, GRC tool, case system, ticketing system, or data lake.

Outcome Measurement

With an authorized outcome and an explicit contracted retention opt-in, Forge measures calibration for that tenant and workflow. The default is no retention and no calibration row.

Forge Orbital procurement posture (current as of July 2026)
Product statusThe enterprise integration candidate is built and tested. Production use still requires customer-specific security, deployment, acceptance, and operations qualification.
SOC 2Not certified. SOC 2 is not claimed. Treat formal attestation as a procurement milestone for a broader enterprise rollout.
Third-party security assessmentNot completed or scheduled. Independent application and cryptographic assessment scopes have been prepared; no report, certification, or completion date is claimed.
Cyber / E&O insuranceNot yet bound; being placed ahead of buyer paper.
FedRAMP / ATONot authorized. Do not route restricted government data through public commercial endpoints without the required authorization path.
CMMCNot certified. CMMC is not claimed.
Legal packetDPA, MSA, NDA, and integration order-form drafts are available for counsel review.
Security contactsecurity@forgeorbital.com

Enterprise Diligence Materials

After workflow fit, Forge provides a concise diligence package for security, legal, procurement, and engineering review. It answers the first round quickly, without exposing engine internals or customer data.

The public procurement map is available at forgeorbital.com/procurement. Security researchers can use the coordinated disclosure policy. Engineers can reproduce the public positive and negative verification cases at forgeorbital.com/verify.

Available Before Sensitive Data

  • Vendor-security one-pager.
  • No customer-data training statement.
  • Public API overview.
  • Public security intake and disclosure policy.

Available For Diligence

  • Questionnaire-style answer bank.
  • Non-sensitive architecture overview.
  • DPA, MSA, NDA, and integration order-form drafts for counsel.
  • SOC 2, pentest, and cyber insurance status statement.

Bring one decision and check the proof yourself.

The fastest way through a security review is a real workflow. Name one high-consequence decision, run it on synthetic or sanitized data, and verify the returned proof trail. The diligence package follows the same request.