Private by default, and yours to leave.

Everything we commit to on security, privacy, and data ownership, gathered in one place. Each card summarizes a promise and links to the page that spells it out in full.

We never train AI on your code

Your repositories and CI jobs are never used to train or improve machine-learning models, and we do not read their contents except to provide, secure, and support the Service. There is no shared corpus to train on.

Read the commitment →

Single-tenant by design

Every managed instance and CI runner runs on its own dedicated VM, isolated from every other customer. Per-instance secrets are derived from a durable root key that never touches our servers’ user-data channel.

How isolation works →

You own your data, and your exit

Export everything any time in Forgejo’s own format: no proprietary lock-in. If a plan lapses, your backups are retained so leaving never means losing your history overnight.

Export and migration →

Regions and data residency

Fjord is operated from the United States. Choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) when you deploy. Your managed instance and dedicated CI runner VMs stay in the region you choose. Backups are currently stored in EU (Helsinki, Finland) for every Instance, whichever region you choose; per-region backup storage is being rolled out. Service analytics and error reporting are processed in the EU.

Where data is stored →

Sub-processors (6), disclosed

We name every vendor that may touch Customer Data and what each one does, and we give at least 30 days’ notice before adding a new one. The current roster is 6 vendors.

See the roster →

Backups and retention

Nightly, automatic, encrypted before they leave your instance and retained on a rolling 90-day window. Restore is operator-run and follows a documented runbook we are still validating end to end. Operational and audit logs are kept for 90 days.

How we run it →

SSO with your identity provider

Connect your OIDC provider (Okta, Azure AD, Google, Auth0, Keycloak) on Team and Pro so your team signs in with your IdP. Wire it up at create time or later.

Set up SSO →

Audit trails

We keep a tamper-evident audit ledger of administrative actions, and record audit events (sign-in, configuration changes, token issuance) on your account so changes are accountable.

Security measures →

The security measures, specifically

The promises above come down to concrete mechanisms. These are taken straight from the security annex of our Data Processing Addendum, where every measure is on the record in full.

Per-instance secret derivation

Per-instance secrets are derived from a durable root key held only in the control plane; secrets are fetched by the instance over TLS at first boot and never embedded in user-data.

Tamper-evident audit ledger

A tamper-evident audit ledger records administrative events (token issuance, configuration changes, bootstrap consume).

Network controls

A per-project Hetzner firewall restricts inbound access; SSH limited to Fjord's control-plane CIDR; CI runners expose no inbound services.

Encryption at rest

Backups encrypted with per-instance keys via restic.

Backups

Nightly Forgejo dumps shipped to a jailed Storage Box sub-account per instance.

Full detail in the DPA (Annex A) →

The legal backing, in writing

These promises are not just marketing copy: the Privacy Policy, Data Processing Addendum, and Terms put them on the record, including retention windows, the sub-processor list, and the security measures behind each instance. Questions go to [email protected].

We don't advertise certifications we don't hold. Fjord makes no SOC 2, ISO, or uptime-SLA claim; what you see here is what we actually do, with a link to the source for each item.