Trust Center

Security and compliance at AnyForge

How the platform protects your data, where each compliance programme stands today, and how to request security documentation for a vendor review.

Security overview

How the platform is built to protect your work

Data handling

Workspace data is stored in Firestore in the EU region behind deny-by-default database rules. Model calls run on the provider keys you bring (BYOK): the provider you connect is engaged under your own agreement with it, as the Data Processing Addendum describes.

Encryption

Traffic to the platform is served over HTTPS (TLS). Data is held in Google Cloud services, which encrypt data at rest by default. Provider keys and other customer credentials live in Google Cloud Secret Manager; the database stores a pointer, never the value.

Tenant isolation

Each workspace is isolated by authentication claims enforced in the database security rules. Repository access uses the acting operator’s own GitHub authorization, or your organization’s GitHub App installation for unattended work, never a shared company-wide token.

Access controls

Role-based access (owner, operator, editor, viewer) is enforced server-side, never in the browser. An organization can let its team sign in through its own SAML or OIDC identity provider, limited to email domains it has verified.

Audit trail

Governance events are SHA-256 hash-chained into an append-only ledger that application clients cannot write, so altering a past event breaks every hash after it. Each approval records who approved what, when, against which content.

Source-code escrow

For handover obligations, escrow deposits are produced with SHA-256 manifests and rebuild rehearsals and can be delivered to an escrow agent.

Vulnerability scanning

Every merge to the main branch runs an automated security scan covering static analysis, vulnerable dependencies, leaked secrets and cloud posture, and records a dated report.

Latest scan on 2026-10-07 did not complete

Compliance status

Where each programme stands

These statuses are maintained by the AnyForge team and change as each programme moves. A report or test is listed as issued or completed only once it exists, with its date.

  • SOC 2 Type I

    Not started

    An independent auditor’s report on the design of controls at a point in time.

  • SOC 2 Type II

    Not started

    An independent auditor’s report on how controls operated over an observation period.

  • ISO/IEC 27001

    Not started

    Certification of an information security management system by an accredited body.

  • GDPR Data Processing Addendum

    Available

    Read the DPA

    The data processing terms that govern personal data AnyForge processes for a customer.

  • Penetration test

    Not yet performed

    An external penetration test of the platform.

Sub-processors

Third parties that process customer data

The current sub-processor list is available on request from privacy@anyforge.ai.

Request documents

Request security documentation

Tell us who you are and what your review needs. A member of the AnyForge team reviews every request and shares documents by hand, under a non-disclosure agreement. Nothing is sent automatically.