Trust Center
Security and compliance at AnyForge
How the platform protects your data, where each compliance programme stands today, and how to request security documentation for a vendor review.
Security overview
How the platform is built to protect your work
Data handling
Workspace data is stored in Firestore in the EU region behind deny-by-default database rules. Model calls run on the provider keys you bring (BYOK): the provider you connect is engaged under your own agreement with it, as the Data Processing Addendum describes.
Encryption
Traffic to the platform is served over HTTPS (TLS). Data is held in Google Cloud services, which encrypt data at rest by default. Provider keys and other customer credentials live in Google Cloud Secret Manager; the database stores a pointer, never the value.
Tenant isolation
Each workspace is isolated by authentication claims enforced in the database security rules. Repository access uses the acting operator’s own GitHub authorization, or your organization’s GitHub App installation for unattended work, never a shared company-wide token.
Access controls
Role-based access (owner, operator, editor, viewer) is enforced server-side, never in the browser. An organization can let its team sign in through its own SAML or OIDC identity provider, limited to email domains it has verified.
Audit trail
Governance events are SHA-256 hash-chained into an append-only ledger that application clients cannot write, so altering a past event breaks every hash after it. Each approval records who approved what, when, against which content.
Source-code escrow
For handover obligations, escrow deposits are produced with SHA-256 manifests and rebuild rehearsals and can be delivered to an escrow agent.
Vulnerability scanning
Every merge to the main branch runs an automated security scan covering static analysis, vulnerable dependencies, leaked secrets and cloud posture, and records a dated report.
Latest scan on 2026-10-07 did not complete
Compliance status
Where each programme stands
These statuses are maintained by the AnyForge team and change as each programme moves. A report or test is listed as issued or completed only once it exists, with its date.
SOC 2 Type I
Not started
An independent auditor’s report on the design of controls at a point in time.
SOC 2 Type II
Not started
An independent auditor’s report on how controls operated over an observation period.
ISO/IEC 27001
Not started
Certification of an information security management system by an accredited body.
GDPR Data Processing Addendum
Available
The data processing terms that govern personal data AnyForge processes for a customer.
Penetration test
Not yet performed
An external penetration test of the platform.
Sub-processors
Third parties that process customer data
The current sub-processor list is available on request from privacy@anyforge.ai.
Request documents
Request security documentation
Tell us who you are and what your review needs. A member of the AnyForge team reviews every request and shares documents by hand, under a non-disclosure agreement. Nothing is sent automatically.