Architecture

A reference document for security review

How the security model is built.

This reference gives IT, security, and procurement teams a row-level view of the planned architecture and the controls already implemented. Each control has a stable reference and a current status.

Four requests: the page, two fonts, one icon. The only script is a few hundred bytes that remembers whether you chose dark, and it fetches nothing. Check both in your own network tab.

Quote a row by its reference. C-04 means the same row next year as it does today. If a control changes, the reference stays and the row says what changed. A clause you pasted into a contract can't quietly come to mean something else.

1  /  On the pylon

Process close to the source

Process observations at the roadside.

The pylon processes sensor input near the road and creates structured observations. Any retained imagery is governed separately by defined purpose, access, and retention terms.

E-01What is up thereThe production sensor, power, and communication configuration will be set after field validation and site review.
E-02What the computer doesIt processes sensor input near the road and creates structured observations. Any retained imagery follows separate purpose, access, and retention terms.
E-03What leaves the poleStructured observations, coverage, health, and time references may leave the unit. Any transfer of imagery follows separately defined terms.
E-04The rolling bufferIf a site uses a rolling imagery buffer, its purpose, access, transfer, and retention window are set in the site terms. The public site does not state one universal duration.
E-05When the power diesA power loss stops observation. Coverage records mark the affected period so it is not treated as observed traffic.

2  /  The four clocks

Named here. How long each one runs is a contract term.

Each data type follows a named retention clock. Contract terms set the duration and the event that ends access or storage.

RefThe clockWhat it holdsWhat ends it
T-01The buffer on the poleThe raw recording, on one unitIt writes over itself. Nothing extends it and nothing shortens it.
T-02A live sessionNothing. It is a view, not a store.Closing the incident, or the ceiling, whichever comes first.
T-03Your history windowCounts, and the numbers worked out from themYour plan. The window moves forward with the calendar.
T-04The public logWho asked, what for, and what we handed overNothing. It is the record. Taking a line out of it would defeat the point of having it.

3  /  Who can see what

One place decides, so no screen can decide differently

Four questions, asked in one place.

Every screen and every action runs the same four questions, and they are never the same word. A row a customer can't have is drawn from the same table as a row they can. So a support view and a customer portal can't disagree about their own account.

I-01Does this kind of customer have it at allThe product type sets which functions can appear. A function outside that product is not shown.
I-02Did this organization buy itThe organization contract sets which purchased functions are available to its seats.
I-03Was this seat given itThe owner decides. Roles add up, and one person can hold several. An auditor seat can't also be an owner seat on the same organization.
I-04And if not, which one failedA refusal names whether the product, organization contract, seat role, legal rule, or measurement state caused it.

4  /  The control register

The rows a procurement officer will paste into a contract

A prototype is built and validation comes next. Some controls are implemented in the current software; others require a running service, an outside test, or an audit. Each row states which applies.

RefThe controlWhere we areWhat it actually means
C-01One customer can't read anotherIn placeEvery row carries its organization, and each query is narrowed to the signed-in seat's organization before it runs. Cross-organization lookup is not part of the customer interface.
C-02Access is a seat, not a personIn placeRoles and flags sit on the seat. The four questions in section 3 run in one place, on every screen and every action. A support view can't show a screen the customer doesn't have.
C-03An auditor can't audit themselvesIn placeThe auditor role cannot be combined with the owner role for the same organization. The application enforces that separation of duties.
C-04Two people to release anythingIn placeA release under legal process needs two Forge Core approvals and appears in the public log. One person cannot approve both steps.
C-05A reason travels with the sessionIn placeA live session opens against an incident and carries a purpose that limits what the session can reach.
C-06Access expires on its ownIn placeA session ends when the incident closes or reaches the ceiling in T-02.
C-07Encrypted in transit and at restIn placeThe build requires encrypted transport and encrypted storage volumes. Field validation and production review will verify the deployed configuration.
C-08No secret reaches a browserIn placeThe gate on the investor pages runs on the server and its password lives in AWS Secrets Manager. A gate written in browser script ships the password to the visitor along with the thing it was hiding.
C-09A second factor on every staff accountTrue, not writtenTrue today on the cloud accounts and the code host. There is no signed policy saying it must stay true, and that document is the thing an auditor asks for rather than the fact.
C-10A written incident planNot yetSection 7 is the planned response sequence. The plan has not been approved or rehearsed, so this control remains not yet in place.
C-11An outside testNot yetNo independent penetration test has been completed. This register is a company control statement rather than an external audit.
C-12A SOC 2 reportNot yetA SOC 2 report requires operating evidence over time. The compliance page lists the work that comes before this step.

5  /  Inside Forge Core

Two people, and what it takes for either of them to hand anything over

S-01Who "we" isTwo people. Andrew answers for every word on this site, and a reply to any address here reaches him.
S-02What we see without askingThe estate: which units are up, which are down, which corner has nothing on it. Not a customer's answers, and not their questions.
S-03Helping a customer with a screenThe support view uses the same access table as the customer portal, so it cannot show a function the customer account does not have.
S-04Reading a customer's own dataStaff must record a reason first, and the access appears in the customer's log.
S-05Handing anything outsideTwo approvals are required and the decision is published. See C-04. The same release process applies to every outside request.

6  /  What keeps this from becoming surveillance

Product rules and access boundaries

These rules define product and access behavior. Changes require the same review and release process as other controlled product changes.

X-01

Temporary track correspondence

A temporary object number can connect observations while the system maintains a continuous view. Road Sentinel does not read plates or recognize faces, and its structured record has no name or identity index. Separate imagery may still show a person or vehicle and follows its own terms.

X-02

No sharing between agencies

Each customer sees its own authorized incidents and records. The customer interface does not include a cross-organization lookup.

X-03

Access runs out on its own

Live access starts with an incident and ends when the incident closes or after four hours. That access ceiling is separate from data retention. Each session carries its purpose and is logged.

X-04

The reason limits what the session can be used for

The recorded incident purpose limits which functions and records the session can reach.

X-05

The usage log is open to anyone

The public log reports request purpose, outcome, and any refusal. It does not publish customer data or imagery.

7  /  If something goes wrong

On a clock, so that the first hour isn't spent deciding what to do

R-01The first hourPost a dated public notice stating what is known and what is still being checked.
R-02The same dayContain the affected function, including taking it offline when needed.
R-03Three working daysNotify affected customers and required authorities based on the incident and applicable law.
R-04Two weeksPublish what happened, what we got wrong, and what changed because of it. It goes in the public log with everything else.
R-05The honest partThis sequence has not been rehearsed. C-10 remains "not yet" until the plan is approved and tested.

Evidence status

No outside audit or penetration test has been completed. Section 4 identifies implemented controls and planned controls. Ask for written evidence for any row that matters to a contract.

Ask us for this in a packetWho processes what