FORG is built around a compliance-first architecture — tamper-proof audit logs, k-anonymity guarantees, and zero payload logging by default. SOC 2, GDPR, and HIPAA controls are not retrofits; they are the foundation.
Enterprise-grade controls across the frameworks that matter most.
Covers Availability, Security, and Confidentiality trust service criteria. Third-party audit report available on request under NDA.
Data Processing Agreement (DPA) available. EU Workers option keeps all data inside European Economic Area infrastructure.
Available on Enterprise plans. Business Associate Agreement (BAA) provided. PHI handling restrictions enforced by policy engine.
Append-only, hash-chained audit log. Tamper-evident by construction — no trust required.
Payload logging is off by default. The adapter emits only metadata. What is — and is never — stored is structural, not configurable.
tsSession timestamp (UTC)modelModel identifiertokens_in / tokens_outToken countslatency_msEnd-to-end latencycost_usdComputed costuser_idOpaque hash — never emailproject_id / session_idScoped identifierserror_codeHTTP / provider errork-anonymity ≥ 5: Aggregate queries require at least 5 members in the bucket. Buckets with fewer members return HTTP 422. Individual data never surfaces upward.
Your data stays where you need it. No hidden cross-region transfers.
Cloudflare D1 + Supabase US (us-east-1). All processing and storage within US borders. Default for all plans.
Cloudflare EU Workers (Frankfurt). Supabase EU region. Stays within EEA. Required for GDPR-strict deployments. Available on Business+.
Bring your own cloud. Deploy the Rule Engine Worker and Supabase instance inside your VPC. Full data sovereignty. Contact Enterprise sales.
No role can view another individual's raw data. Access is scoped to the minimum required for each function.
Export your full audit history on demand. Supports CSV, JSON, and NDJSON. Pipe directly into Splunk, Datadog, or your own SIEM. Signed exports include a SHA-256 manifest for integrity verification.
SOC 2 report, GDPR DPA, and HIPAA BAA available for Business and Enterprise plans. Our security team can join your review call.
UpgradIQ, Inc. — legal entity for all compliance agreements.