Forged
Start building
Resources

Security

Forged handles source code, product plans, and business context. Security is built into how we authenticate users, access repositories, execute code, and operate our infrastructure.

Sandboxed code execution

AI-driven implementation runs inside gVisor-sandboxed containers on isolated worker nodes, separate from Forged's core application services. Generated code, tests, and commands execute inside those environments rather than directly within the application control plane.

Scoped repository access

When you connect a repository, Forged authenticates through a GitHub App rather than a personal access token. Access is limited to repositories you explicitly authorize and can be revoked through GitHub. Each job receives a short-lived, task-scoped credential that our proxy validates before allowing repository access.

Customer data and AI providers

Private source code, repositories, prompts, plans, and other Customer Content are used only to provide, operate, secure, maintain, support, and improve Forged. We do not use Customer Content to train or fine-tune AI models, whether general-purpose models or Forged's own models, except in the form of Aggregated Data.

When a feature requires an external AI provider, Forged sends only the information needed to perform the requested work, subject to the provider settings and contractual protections we have configured.

Authentication and access control

Account authentication is handled by Clerk, a dedicated identity provider, rather than a credential system we build and store ourselves. Within an organization, administrators control who has access to which projects.

Internal access

Access to production systems and Customer Content is limited to authorized personnel who need it to operate, secure, or support the Service, investigate suspected abuse or a security incident, diagnose errors, comply with law, or establish, exercise, or defend legal claims. Administrative access is controlled and restricted to that same set of personnel.

Infrastructure and secrets

Forged runs on Google Cloud. Deployments authenticate using keyless workload identity federation rather than long-lived service-account keys, and secrets such as API keys and credentials are managed through an external secret store rather than checked into configuration.

Encryption

Data is encrypted in transit via TLS between your browser, our services, and connected third-party providers. Data stored in our databases and cloud storage is encrypted at rest, consistent with Google Cloud's standard managed-service defaults.

Certifications

Forged is not currently SOC 2 certified. We are continuing to formalize our security program as the product and customer base grow. If your organization has specific security or compliance requirements, please let us know.

Questions or a security review?

If you need more detail for a security questionnaire or vendor review, contact us at security@tryforged.ai.