Skip to content
NarrowForge

NF / Legal / GitHub

ForgeVault CRASecurity

Access model

ForgeVault CRA operates within GitHub and requests only the permissions its documented job requires: GitHub-native evidence for the EU Cyber Resilience Act. If a feature would need broader access, the feature is redesigned or dropped — not silently granted.

Data handling

Operational data is limited to what the product needs to function (see the product privacy policy). No sale of customer data, no advertising use, encrypted transport throughout.

Vulnerability handling

Report security issues affecting ForgeVault CRA via the support form (category Security) or the process on our security page. Reports are acknowledged and handled with coordinated disclosure.

What we don't claim

We do not claim SOC 2, ISO 27001 or similar certifications for ForgeVault CRA. If that changes, scope and dates will be stated here. [Placeholder — requires legal review.] confirm audit or assessment status with the team before launch.

Last updated: 2026-08-20.