Security

What the design makes impossible.

Some of this is in place today. The rest is a commitment for first deployment. Every line says which, and there is no third word.

01 / Data protection

There is no person column

Place and time keying
Today
We file every record under a place and a time. We never file it under a thing that moved. No index lets anyone follow one vehicle across a city. We never built one. So there is no such index to subpoena, leak or misuse.
Provenance at creation
Today
Every record says where it came from. That is its provenance. It names the pylon, the firmware version and the model version. It says how sure the pylon was, and when that pylon was last calibrated. All five are there from the start. Nothing is filled in later. A provenance field written later is a guess with a timestamp on it.
Object number retirement
Today
An object is a thing that moved. Its number is retired when it leaves coverage. We never issue that number again. The product has no plate recognition. It has no face recognition. So there is no face database, no watchlist and no way to look a vehicle up.

02 / Encryption

This section is empty

We would rather show you the hole than fill it. No one has checked an encryption claim on this page against a running system. So anything we published here would be a sentence from memory.

It ships when we have checked all six

  1. Transport and the minimum version
  2. The pylon uplink that carries records out, as its own boundary
  3. The algorithm and everything it covers, backups and logs named
  4. Which service holds the keys
  5. How a stored file is encrypted, and what protects its key
  6. What a key rotation actually re-encrypts

A page that says AES-256 and stops is the most common half-truth in this genre. We would rather be visibly incomplete than quietly imprecise.

03 / Isolation

One organization cannot reach another

Row-level isolation
Commitment
Every row in the database carries the id of the organization that owns it. The database itself keeps them apart. That is row-level security, not the app code alone.
Separate file storage per organization
Commitment
Each organization's files sit in a storage path of their own. Reaching one takes a signed link that works once and then expires.

04 / The edge

What runs on a pylon and what leaves it

Tracking at the edge
Commitment
Tracking happens on the pylon. What leaves it is the derived record: what moved, where, how fast, in what order. Its provenance comes with it.
No inbound data path
Commitment
There is no remote session to steal. Nobody can ask a pylon about a person.

Firmware, clock sync and settings reach a pylon somehow. Until we have traced all three, we claim no data comes in, not that nothing does.

05 / Internal access

Neither of us can act alone

No standing production access
Commitment
Keeping the pylons running must not require looking at the data. So we watch telemetry: health numbers, never the records. Opening a customer's data takes a break-glass request. That request is an exception we log. That exception expires on its own. The exception appears in that customer's own access log, not only in ours.
Two-person release
Today
Two named Forge Core people must both approve any release of data. Neither can act alone.

Fig 02

How a release is approved

  1. 01

    A request arrives

    Court order, warrant, subpoena, or just a purchase.

  2. 02

    Both approvers read it

    Neither can act alone.

  3. 03

    Both approve, or nothing is released

    2 of 2

    In an emergency, the release can go first. The second approval still has to come, inside 24 hours.

  4. 04

    It publishes to the log

    Requester, type, what was asked for, outcome.

    • 04a

      Under a gag order

      Published as a count, never as a censored row. The full row publishes when the order lifts.

Two named people. Neither can act alone. We publish every outcome, granted or refused.

06 / Abuse of the platform

Five attacks, and what stops each

The query nobody can write is the one an attacker cannot argue with. It is a missing feature, not a policy.

Account takeover
Commitment
We make every agency use single sign-on. An officer who leaves with a live account is the classic breach. SCIM closes an account here when the agency closes it in their own staff directory. An account that can export needs multi-factor authentication. Accounts lock out. We limit how fast requests can arrive. We check passwords against a breached-password list we hold ourselves.
Pretextual requests
Today
There is nowhere to type a person. No name field, no plate field, no face upload, no watchlist, no standing alert. Every question is a query: a shape on a map and a window of time. Both carry hard limits. Every query must state its purpose. We record it, and it binds the query. The software enforces that, not a policy. That is why it holds under pressure.
Export abuse
Commitment
Every organization has an export quota. We alert on unusual export rates. We fingerprint exported imagery per buyer, so a leaked file names its buyer. We sign download links. They work once and expire. The organization's own admin sees the export log, not only us.
Insider risk
Commitment
We approve any rise in a person's access. We log it. The rise expires on a clock. We review access every quarter. The internal console is a separate app. It has its own sign-in and its own permission checks.
Procurement fraud
Today
Bank details are where fraud happens in government sales. We verify any change to ours on a separate channel. We publish the only bank details we use. We send them at contract signing.

07 / Incidents and reliability

What we commit to, and what we will not guess

We tell a customer within 72 hours of confirming a security incident that touches their data. We tell them sooner where the law requires it. The notice says what happened, what data it touched, what we did, and what we recommend.

We publish that commitment and not a target for how fast we respond. We have never had a security incident. If we do, we disclose it here.

We publish no uptime number either. We have three weeks of history behind us. A figure with three weeks behind it is a guess wearing a decimal point. A status page ships at first deployment.

Zone redundancy and tested restores
Commitment
We run in more than one availability zone. We back up at a fixed interval. We test restores on a schedule. We do not assume them.
Buffered uplink loss
Commitment
When a pylon loses its uplink, it keeps tracking. It holds what it measured. What it sends later carries the same provenance as the rest.

08 / This document

You can check this page yourself

Three requests: the page, one font, one icon. Nothing from anyone else's server. The page runs one small script, written into the page itself, which reads whether you picked the light or the dark theme. No cookies. Nothing else runs. You can check all of that in your browser's own network tab in about ten seconds. We built it this way so you can check it that cheaply.

Nothing here hides, folds away, or waits for a hover or a click. So a print and a PDF are this same document.

Ask for the documentCompliance posture