Security starts with a system buyers can inspect.
Forge Core publishes the architecture, access controls, release process, incident plan, sub-processors, compliance path, and current gaps. Formal audits and outside testing will follow a running product.
| What a buyer asks about | Where we are | The detail |
|---|---|---|
| SOC 2 | Not completed | No auditor has been hired and no date has been set. The status will change when that work begins. |
| Outside penetration test | Not completed | No independent penetration test has been completed. |
| ISO 27001 | Not planned first | The current compliance plan starts with the requirements most relevant to state and local buyers. |
| GovRAMP | Planned path | This is the planned security assurance path for state and local buyers. No assessor has been hired. |
| Structured movement schema | Documented | The schema contains place, time, movement, coverage, and source fields without a name or identity index. Imagery is governed separately. |
| Two people for every release | Implemented | The release workflow requires two Forge Core approvers and records the decision. |
| Plate reading | Not a product function | Road Sentinel does not read plate numbers or create a plate index. |
| Face recognition | Not a product function | Road Sentinel does not recognize faces or create a face gallery or watch list. |
- Security architecture. Review edge processing, access decisions, release controls, incident response, and current control status.
- Compliance path. See the standards and legal reviews that apply, their current state, and the planned order of work.
- Reporting a flaw. See the test scope, safe harbor, response timing, and what makes a useful report.
- Service providers. See each current provider, where it operates, and what information it may receive.