Security
What the design makes impossible.
Some of this is in place today. The rest is a commitment for first deployment. Every line says which, and there is no third word.
- Place and time keying
- Today
- We file every record under a place and a time. We never file it under a thing that moved. No index lets anyone follow one vehicle across a city. We never built one. So there is no such index to subpoena, leak or misuse.
- Provenance at creation
- Today
- Every record says where it came from. That is its provenance. It names the pylon, the firmware version and the model version. It says how sure the pylon was, and when that pylon was last calibrated. All five are there from the start. Nothing is filled in later. A provenance field written later is a guess with a timestamp on it.
- Object number retirement
- Today
- An object is a thing that moved. Its number is retired when it leaves coverage. We never issue that number again. The product has no plate recognition. It has no face recognition. So there is no face database, no watchlist and no way to look a vehicle up.
We would rather show you the hole than fill it. No one has checked an encryption claim on this page against a running system. So anything we published here would be a sentence from memory.
It ships when we have checked all six
- Transport and the minimum version
- The pylon uplink that carries records out, as its own boundary
- The algorithm and everything it covers, backups and logs named
- Which service holds the keys
- How a stored file is encrypted, and what protects its key
- What a key rotation actually re-encrypts
A page that says AES-256 and stops is the most common half-truth in this genre. We would rather be visibly incomplete than quietly imprecise.
- Row-level isolation
- Commitment
- Every row in the database carries the id of the organization that owns it. The database itself keeps them apart. That is row-level security, not the app code alone.
- Separate file storage per organization
- Commitment
- Each organization's files sit in a storage path of their own. Reaching one takes a signed link that works once and then expires.
- Tracking at the edge
- Commitment
- Tracking happens on the pylon. What leaves it is the derived record: what moved, where, how fast, in what order. Its provenance comes with it.
- No inbound data path
- Commitment
- There is no remote session to steal. Nobody can ask a pylon about a person.
Firmware, clock sync and settings reach a pylon somehow. Until we have traced all three, we claim no data comes in, not that nothing does.
- No standing production access
- Commitment
- Keeping the pylons running must not require looking at the data. So we watch telemetry: health numbers, never the records. Opening a customer's data takes a break-glass request. That request is an exception we log. That exception expires on its own. The exception appears in that customer's own access log, not only in ours.
- Two-person release
- Today
- Two named Forge Core people must both approve any release of data. Neither can act alone.
Fig 02
How a release is approved
- 01
A request arrives
Court order, warrant, subpoena, or just a purchase.
- 02
Both approvers read it
Neither can act alone.
- 03
Both approve, or nothing is released
2 of 2
In an emergency, the release can go first. The second approval still has to come, inside 24 hours.
- 04
It publishes to the log
Requester, type, what was asked for, outcome.
- 04a
Under a gag order
Published as a count, never as a censored row. The full row publishes when the order lifts.
- 04a
The query nobody can write is the one an attacker cannot argue with. It is a missing feature, not a policy.
- Account takeover
- Commitment
- We make every agency use single sign-on. An officer who leaves with a live account is the classic breach. SCIM closes an account here when the agency closes it in their own staff directory. An account that can export needs multi-factor authentication. Accounts lock out. We limit how fast requests can arrive. We check passwords against a breached-password list we hold ourselves.
- Pretextual requests
- Today
- There is nowhere to type a person. No name field, no plate field, no face upload, no watchlist, no standing alert. Every question is a query: a shape on a map and a window of time. Both carry hard limits. Every query must state its purpose. We record it, and it binds the query. The software enforces that, not a policy. That is why it holds under pressure.
- Export abuse
- Commitment
- Every organization has an export quota. We alert on unusual export rates. We fingerprint exported imagery per buyer, so a leaked file names its buyer. We sign download links. They work once and expire. The organization's own admin sees the export log, not only us.
- Insider risk
- Commitment
- We approve any rise in a person's access. We log it. The rise expires on a clock. We review access every quarter. The internal console is a separate app. It has its own sign-in and its own permission checks.
- Procurement fraud
- Today
- Bank details are where fraud happens in government sales. We verify any change to ours on a separate channel. We publish the only bank details we use. We send them at contract signing.
We tell a customer within 72 hours of confirming a security incident that touches their data. We tell them sooner where the law requires it. The notice says what happened, what data it touched, what we did, and what we recommend.
We publish that commitment and not a target for how fast we respond. We have never had a security incident. If we do, we disclose it here.
We publish no uptime number either. We have three weeks of history behind us. A figure with three weeks behind it is a guess wearing a decimal point. A status page ships at first deployment.
- Zone redundancy and tested restores
- Commitment
- We run in more than one availability zone. We back up at a fixed interval. We test restores on a schedule. We do not assume them.
- Buffered uplink loss
- Commitment
- When a pylon loses its uplink, it keeps tracking. It holds what it measured. What it sends later carries the same provenance as the rest.
Three requests: the page, one font, one icon. Nothing from anyone else's server. The page runs one small script, written into the page itself, which reads whether you picked the light or the dark theme. No cookies. Nothing else runs. You can check all of that in your browser's own network tab in about ten seconds. We built it this way so you can check it that cheaply.
Nothing here hides, folds away, or waits for a hover or a click. So a print and a PDF are this same document.