Security and trust

Boundaries that are visible, testable, and difficult to bypass.

ControlForge is designed around a simple principle: the system should be able to show why it reached a conclusion and who authorized a consequential action.

Detections

Deterministic rules decide whether saved evidence becomes a finding. Model output is never the decision boundary.

AI assistance

Optional and advisory. It must use referenced evidence, pass schema validation, and remain subject to human review.

Endpoint response

High-impact action requires explicit authority, independent human approval, bounded execution, and audit evidence.

Tenant isolation

Owners may enter an explicitly selected network. Ordinary administrators remain scoped to their assigned network.

Endpoint privacy

The native app shows local status and safe support details—not organization cases, raw events, secrets, or analyst rationale.

Release integrity

Production mode rejects dirty source, the wrong host, missing exact tags, missing signatures, or incomplete notarization.

Current product boundary

A signed pilot is a status, not a production claim.

ControlForge currently has a signed and notarized staging package, tested multi-network authorization, passkey administration, endpoint enrollment, and deterministic investigation workflows.

It does not yet claim general availability, clean-Mac fleet acceptance, enterprise service levels, or autonomous remediation. Those claims stay closed until their evidence exists.

Release evidence

What a downloadable build must carry

Apple assuranceDeveloper ID signature, trusted timestamp, notarization ticket, Gatekeeper acceptance
Source assuranceVersion, channel, exact commit, tag, dirty state, supported architecture
Artifact assuranceImmutable filename, byte size, SHA-256, matching embedded and external manifests
Acceptance assuranceFresh install, first report, upgrade, rollback, and uninstall results kept separate from build tests