Security & compliance

Built to be audited, including by you.

A platform that audits your controls must survive scrutiny of its own. RiskForge's security guarantees hold because of how the system is built, not because a policy document promises them.

Architecture is the first control.

riskforge / audit-trailTIMEENTRYCHAINED HASH09:41:12finding recorded · RF-02318f31…22aa09:42:01verdict · hold, four-eyes releasec77d…52f009:44:03released · m.vogel1a6e…bd9309:44:03evidence appended · PKG-2026-Q277b0…410cappend-only · each entry chained to the lastSEALED

Independent by design

RiskForge watches your systems without depending on them. The monitored system cannot alter, blind or switch off its monitor.

Per-customer isolation

A dedicated environment and your own encryption keys. No shared databases, no shared compute.

EU residency, enforced

Written into our infrastructure code, so a non-EU deployment is technically impossible, not merely forbidden.

Encryption everywhere

In transit and at rest, with managed key rotation.

Least privilege

Each part of RiskForge holds only the access it needs, and none of it can write into your ERP uninvited.

Fail-safe interception

If RiskForge is unreachable, you choose per process whether transactions pass or wait. Your operations are never hostage to ours.

GDPR by design.

Minimised and purpose-bound

Data minimisation from the ground up, with purpose limited to controls monitoring.

Role-scoped access

Each viewer sees only what their function requires. Retention rules apply per data class.

Works-council ready

Clear documentation of what is monitored and what is not, plus full records of processing.

EU AI Act: high-risk, and built for it.

Human in the loop

No transaction is finally rejected without a human decision. Oversight is architecture, not policy.

Confidence bands

Holds follow calibrated confidence bands, so uncertainty is communicated honestly and acting on findings is safe.

Every decision logged

Inputs and model version recorded for each automated decision; technical documentation maintained continuously.

ForgeIQ stays grounded

It cites what it reads from your data, and it says so when it cannot answer.

Our own change management.

We hold ourselves to the standard we audit: every change is version-controlled, peer-reviewed, tested and deployed through a pipeline, with no manual changes to production. Your auditors may inspect our development lifecycle documentation on request.

Own your controls.

See RiskForge on your own processes.

In the demo we walk through what is already built and running on SAP and the connected live systems, and what we can set up for your business. No slides, just the product and a plan.

Request a demo