Detections
Deterministic rules decide whether saved evidence becomes a finding. Model output is never the decision boundary.
Security and trust
ControlForge is designed around a simple principle: the system should be able to show why it reached a conclusion and who authorized a consequential action.
Deterministic rules decide whether saved evidence becomes a finding. Model output is never the decision boundary.
Optional and advisory. It must use referenced evidence, pass schema validation, and remain subject to human review.
High-impact action requires explicit authority, independent human approval, bounded execution, and audit evidence.
Owners may enter an explicitly selected network. Ordinary administrators remain scoped to their assigned network.
The native app shows local status and safe support details—not organization cases, raw events, secrets, or analyst rationale.
Production mode rejects dirty source, the wrong host, missing exact tags, missing signatures, or incomplete notarization.
Current product boundary
ControlForge currently has a signed and notarized staging package, tested multi-network authorization, passkey administration, endpoint enrollment, and deterministic investigation workflows.
It does not yet claim general availability, clean-Mac fleet acceptance, enterprise service levels, or autonomous remediation. Those claims stay closed until their evidence exists.
Release evidence