NF / Legal / GitHub
ForgeVault CRA — Security
Access model
ForgeVault CRA operates within GitHub and requests only the permissions its documented job requires: GitHub-native evidence for the EU Cyber Resilience Act. If a feature would need broader access, the feature is redesigned or dropped — not silently granted.
Data handling
Operational data is limited to what the product needs to function (see the product privacy policy). No sale of customer data, no advertising use, encrypted transport throughout.
Vulnerability handling
Report security issues affecting ForgeVault CRA via the support form (category Security) or the process on our security page. Reports are acknowledged and handled with coordinated disclosure.
What we don't claim
We do not claim SOC 2, ISO 27001 or similar certifications for ForgeVault CRA. If that changes, scope and dates will be stated here. [Placeholder — requires legal review.] confirm audit or assessment status with the team before launch.
Last updated: 2026-08-20.