Security

Architecture, controls, compliance, and disclosure

Security starts with a system buyers can inspect.

Forge Core publishes the architecture, access controls, release process, incident plan, sub-processors, compliance path, and current gaps. Formal audits and outside testing will follow a running product.

01

Where we stand

Current controls and the work ahead

What a buyer asks aboutWhere we areThe detail
SOC 2Not completedNo auditor has been hired and no date has been set. The status will change when that work begins.
Outside penetration testNot completedNo independent penetration test has been completed.
ISO 27001Not planned firstThe current compliance plan starts with the requirements most relevant to state and local buyers.
GovRAMPPlanned pathThis is the planned security assurance path for state and local buyers. No assessor has been hired.
Structured movement schemaDocumentedThe schema contains place, time, movement, coverage, and source fields without a name or identity index. Imagery is governed separately.
Two people for every releaseImplementedThe release workflow requires two Forge Core approvers and records the decision.
Plate readingNot a product functionRoad Sentinel does not read plate numbers or create a plate index.
Face recognitionNot a product functionRoad Sentinel does not recognize faces or create a face gallery or watch list.

In this section

Architecture, control status, compliance, providers, and vulnerability reporting.

  • Security architecture. Review edge processing, access decisions, release controls, incident response, and current control status.
  • Compliance path. See the standards and legal reviews that apply, their current state, and the planned order of work.
  • Reporting a flaw. See the test scope, safe harbor, response timing, and what makes a useful report.
  • Service providers. See each current provider, where it operates, and what information it may receive.