Changelog
v2.7.0March 28, 2025

Business plan, SCIM, and data residency

Enterprise-ready features for larger teams. Business plan with unlimited users, automated SCIM provisioning, EU data residency, and GDPR DPA.


New

Business plan launched

The FORG Business plan is now available at $299/month. Includes: unlimited users, SCIM 2.0 provisioning, EU or US data residency selection, Data Processing Agreement (DPA), FORG Atlas access, 1-year signal retention, and priority support with 4-hour SLA. Contact hello@forg.pro for annual pricing.

New

SCIM 2.0 support for Okta, Azure AD, Google Workspace

Business+ plans can now automate user provisioning and deprovisioning via SCIM 2.0. Supported IdPs: Okta, Azure Active Directory, Google Workspace, and any generic SCIM 2.0 compatible provider. SCIM handles user create, update, deactivate, and group-to-FORG-team mapping. Setup documentation is available at forg.pro/docs/scim.

New

EU data residency option (Business+)

Business+ customers can now elect EU data residency. When enabled, all signal data is processed in Cloudflare EU-region Workers (Amsterdam, Frankfurt, London) and stored in Supabase EU (eu-central-1, Frankfurt). No signal data crosses to US infrastructure. License and identity data (D1) remains US-resident by design and is not subject to residency selection. Contact your account manager to migrate an existing account to EU residency.

New

DPA available for all Business+ customers

A GDPR-compliant Data Processing Agreement is now available for all Business+ customers. The DPA covers: data controller/processor roles, processing scope and purpose, security obligations, sub-processor disclosure (Cloudflare, Supabase), data subject rights procedures, and breach notification timelines. Request a signed DPA at forg.pro/legal/dpa or through your account manager.

Improved

SAML SSO now supports JIT (just-in-time) provisioning

Previously, SAML SSO required users to be pre-created in FORG before they could log in. v2.7.0 adds JIT provisioning: when a user authenticates via SAML for the first time, a FORG account is automatically created with the role specified in the SAML assertion (or the default role configured in SSO settings). Existing SAML configurations are unaffected — JIT provisioning must be explicitly enabled in Organization Settings → Authentication.