API keys, database credentials, model tokens, and infrastructure secrets never belong in browser code or customer forms.
Trust is a boundary.
Not a promise.
Forge designs around tenant boundaries, server-side secrets, approved sources and human review. These are design and internal operating controls; each customer deployment requires its own security and acceptance review.
Discovery begins with metadata and configuration. Consequential actions require explicit scope and human approval.
Sources, timestamps, confidence, contradictions, and provenance remain distinguishable from model-generated conclusions.
Customer evidence, connector runs, generated artifacts, and operational state are bound to an authenticated tenant context.
Self-hosted inference is designed to stay behind the selected customer or Forge-controlled private boundary.
Forge can explain and plan high-impact work without turning recommendations into uncontrolled execution.
