Privacy and retention
Forge stores workspace names, salted password hashes, hashed session/API tokens, compiler inputs and run artifacts on a temporary local CPU worker. Cloudflare serves the interface and proxies API requests over a Cloudflare Tunnel. The worker requires this computer to remain online; AWS migration is blocked by an expired interactive sign-in. Compiler inputs are not sent to an LLM.
Runs are private until their owner explicitly publishes them. Anyone with a published URL can download that report, including its input and intermediate code. Deleting the run revokes the URL. A recipient may already have saved a copy.
Submit only code you are authorized to process on this service. This engineering preview has no enterprise certification, SSO, contractual data residency guarantee or automated password recovery.
Guest runs expire after 24 hours. Registered workspaces retain runs until deletion, subject to the preview's storage limits. Session cookies and API tokens expire after 30 days. Authentication and job admission use rate-limit counters derived from the client address; the service hashes these addresses and does not record them in reports.
Compiler subprocesses receive a clean environment, filesystem restrictions and a network-denying syscall filter. Generated machine code is not executed. These controls reduce exposure; the service has not undergone an independent security audit.
Browser authentication uses a Secure, HttpOnly, SameSite session cookie. No advertising or analytics scripts are included. Passwords are hashed with PBKDF2-HMAC-SHA256, a random salt and 600,000 iterations.
Viewer connections and the tunnel use encrypted transport. The tunnel connects to a loopback-only local API using an independent secret header. This temporary deployment has no uptime guarantee. Use public or non-sensitive evaluation inputs in this preview.