Skip to content

Security and trust

Forge separates source-control authority from repository access used during deployment. The separation limits what each actor can do and what each proof can establish.

Authority table

Capability Authority
Ordinary Git operations The operator's GitHub authority.
Repository access for deployment Forge App authorization, requested only when deployment requires it.
Derived deployment context Authorization and repository context.
Runtime behavior The committed manifest and app source.

Derived identity

Environment, tenant, account, installation, and app identity are not customer inputs. Forge derives them from authorization and repository context, and the CLI exposes no selector for them.

Source integrity

Forge deploys committed source. The default request uses the GitHub origin and committed HEAD. Automation may select only repository, ref, or commit.

Secret handling

Do not put credentials in the manifest, commit, proof packet, or support report. Redact secret-looking values before sharing logs.

Evidence boundary

A local proof establishes local behavior. A deployment result establishes the request outcome. Neither claim establishes hosted availability without accepted evidence.