Trust Center
Security at BridgeForge
A plain-language overview of repository-supported controls and the responsibilities that remain during Public Beta.
Account boundaries
Protected product routes require a server-recognized session. Development bypass behavior is restricted and does not grant paid production access.
Billing boundaries
Entitlements are evaluated server-side, checkout prices are allowlisted, and webhook requests require signature and size validation. Database migration verification remains a release blocker.
Secrets and providers
Provider secrets are intended for server-only use and are not shown in health responses. Never send credentials through support or product text fields.
Current limitations
BridgeForge does not claim SOC 2, FedRAMP, HIPAA, DoD approval, or other unverified certification. Database RLS and hosted configuration validation remain deferred.
Report a concern
Use the support contact for responsible security reports. Include reproducible details but no live credentials or unnecessary personal data.
BridgeForge OS · Public Beta

