What we actually do to keep your forge safe.
The concrete, current-state security facts behind the managed forge, stated plainly. This is the reference companion to the trust overview: who to contact, who touches your data, how backups and restore work, and the controls on each instance.
Everything below describes what is true today. Where something is planned rather than live, it says so. We do not advertise certifications we do not hold: Fjord makes no SOC 2, ISO 27001, or uptime-SLA claim. For the higher-level promises and how they map to each page, see the trust overview.
Reporting a security issue
Email [email protected] with a description of the issue, the steps to reproduce it, and the affected URL or instance. We acknowledge reports, investigate, and keep you updated through to a fix. Please give us a reasonable window to remediate before any public disclosure.
If a personal-data breach affects you, our Data Processing Addendum commits us to notify you without undue delay and within 72 hours of becoming aware. The full obligation is in the Data Processing Addendum.
Sub-processors and infrastructure providers
These are the vendors that may process Customer Data, and what each one does. We give at least 30 days' notice before adding a new one. This list mirrors the canonical roster in the Privacy Policy.
| Provider | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Chosen forge region; backup storage in Finland | hosting of managed Instances and CI Runner VMs in the customer-selected forge region, and encrypted backup storage. |
| Cloudflare, Inc. | US/EU | DNS, edge TLS, and bot mitigation. |
| Stripe, Inc. | US | payment processing. |
| Resend, Inc. | US | transactional email (account verification, password reset, billing receipts). |
| PostHog, Inc. | EU | product analytics for the Fjord Account platform. Uptime monitoring is operated in-house. |
| Functional Software, Inc. (dba Sentry) | EU | application error reporting and monitoring when error reporting is enabled for the Service. |
Data residency and regions
Fjord is operated from the United States. Choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) when you deploy. Your managed Instance and its CI Runner VMs are hosted by Hetzner in the region you choose. Backups are currently stored in EU (Helsinki, Finland) for every Instance, whichever region you choose; per-region backup storage is being rolled out. Service analytics and error reporting are processed in the EU. Where each category of data lives, backups included, is set out per category in the Data Residency Statement; how we handle personal data more broadly is in the Privacy Policy.
Region limitations to know at launch: Fjord is offered to US customers at launch; EU and Canada availability is planned.
Backups and restore
Backups are nightly and automatic on Team and Pro. Each archive is encrypted client-side (with restic) before it leaves your instance and shipped to a jailed Storage Box sub-account dedicated to that forge, kept on a rolling 90-day window. Operational and audit logs are retained for 90 days. How we run the platform day to day is on the operations page.
Restore is operator-run and follows a documented runbook we are still validating end to end; a self-service, point-in-time restore is not offered at launch. Two caveats worth stating plainly: because backups run nightly, the recovery point is the last nightly snapshot (up to 24 hours of data), and restore is operator-run, so we do not publish a contractual recovery-time SLA at launch. The backup and restore measures are on the record in the Data Processing Addendum.
Access controls and audit posture
These are the concrete measures behind each instance. Every one is on the record in full in the security annex (Annex A) of the Data Processing Addendum.
- Single-tenant isolation: every managed Instance and CI Runner runs on its own dedicated VM, isolated from every other customer.
- Per-Instance secrets are derived from a durable root key held only in the control plane and fetched over TLS at first boot, never placed in cloud-init user-data.
- A per-project firewall restricts inbound access, with SSH limited to the control-plane CIDR; CI runners expose no inbound services.
- Operator access to sensitive administrative endpoints requires MFA, and we do not access repository or CI contents except to provide, secure, and support the Service.
- A tamper-evident audit ledger records administrative actions (token issuance, configuration changes, bootstrap consume).
Policies
The agreements that put the above on the record. Each legal policy was last updated July 30, 2026.
