Private by default, and yours to leave.
Everything we commit to on security, privacy, and data ownership, gathered in one place. Each card summarizes a promise and links to the page that spells it out in full.
We never train AI on your code
Your repositories and CI jobs are never used to train or improve machine-learning models, and we do not read their contents except to provide, secure, and support the Service. There is no shared corpus to train on.
Read the commitment →Single-tenant by design
Every managed instance and CI runner runs on its own dedicated VM, isolated from every other customer. Per-instance secrets are derived from a durable root key that never touches our servers’ user-data channel.
How isolation works →You own your data, and your exit
Export everything any time in Forgejo’s own format: no proprietary lock-in. If a plan lapses, your backups are retained so leaving never means losing your history overnight.
Export and migration →Regions and data residency
Fjord is operated from the United States. Choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) when you deploy. Your managed instance and dedicated CI runner VMs stay in the region you choose. Backups are currently stored in EU (Helsinki, Finland) for every Instance, whichever region you choose; per-region backup storage is being rolled out. Service analytics and error reporting are processed in the EU.
Where data is stored →Sub-processors (6), disclosed
We name every vendor that may touch Customer Data and what each one does, and we give at least 30 days’ notice before adding a new one. The current roster is 6 vendors.
See the roster →Backups and retention
Nightly, automatic, encrypted before they leave your instance and retained on a rolling 90-day window. Restore is operator-run and follows a documented runbook we are still validating end to end. Operational and audit logs are kept for 90 days.
How we run it →SSO with your identity provider
Connect your OIDC provider (Okta, Azure AD, Google, Auth0, Keycloak) on Team and Pro so your team signs in with your IdP. Wire it up at create time or later.
Set up SSO →Audit trails
We keep a tamper-evident audit ledger of administrative actions, and record audit events (sign-in, configuration changes, token issuance) on your account so changes are accountable.
Security measures →The security measures, specifically
The promises above come down to concrete mechanisms. These are taken straight from the security annex of our Data Processing Addendum, where every measure is on the record in full.
Per-instance secret derivation
Per-instance secrets are derived from a durable root key held only in the control plane; secrets are fetched by the instance over TLS at first boot and never embedded in user-data.
Tamper-evident audit ledger
A tamper-evident audit ledger records administrative events (token issuance, configuration changes, bootstrap consume).
Network controls
A per-project Hetzner firewall restricts inbound access; SSH limited to Fjord's control-plane CIDR; CI runners expose no inbound services.
Encryption at rest
Backups encrypted with per-instance keys via restic.
Backups
Nightly Forgejo dumps shipped to a jailed Storage Box sub-account per instance.
The legal backing, in writing
These promises are not just marketing copy: the Privacy Policy, Data Processing Addendum, and Terms put them on the record, including retention windows, the sub-processor list, and the security measures behind each instance. Questions go to [email protected].
We don't advertise certifications we don't hold. Fjord makes no SOC 2, ISO, or uptime-SLA claim; what you see here is what we actually do, with a link to the source for each item.
