Skip to main content
IncidentForge
  • Home
  • Product
  • Guide
  • Pricing
  • Downloads
  • Customer portal

Updated 14 September 2026

Security Statement

IncidentForge is designed to keep sensitive incident work under the customer’s deployment control.

Local-first data boundary

The desktop application stores and processes incident records, evidence and report content in the customer-controlled deployment. The licensing service does not need access to incident or report contents to perform account, entitlement or activation functions.

Protected signing boundary

Ed25519 signing keys remain in protected server-side secret storage. The service can issue signed license envelopes and signed offline-activation responses without exposing private signing material to the public website, desktop operator or customer portal.

Activation and air-gapped operation

Online and offline activation responses are verified through the existing signing contract. Business workstation enrollment and air-gapped workflows enforce the issued pooled entitlement and one-seat-per-active-workstation rule. An activation exchange does not require incident or report content transfer.

Authentication and sessions

The customer portal uses normalized account lookup with an account-enumeration-safe response, short-lived one-time access tokens hashed at rest, rotating opaque sessions, HttpOnly SameSite cookies and CSRF protection for state-changing actions.

Rate limiting and audit

Rate limiting is applied where configured at the deployment boundary. Security-relevant operations are transactional and recorded through the durable audit mechanism; the accepted service includes a hash-chained security audit record where that contract applies.

Secrets and release controls

Runtime secrets are stored outside immutable release trees in protected files. The project uses dependency and secret scanning, controlled release verification, and SHA-256 and Ed25519 signature metadata for published Linux artifacts. Windows artifacts are not published yet.

Reporting a security concern

Email support@incidentforge.net or call +380 75 110 1196 for a security question. Do not send incident evidence, passwords or activation secrets. No public bug-bounty program, 24/7 monitoring commitment or guaranteed response time is offered.

This statement does not claim absolute security, formal certification, penetration-test completion or guaranteed compliance.

© 2026 IncidentForge · Operated by Vladyslav Verkhusha.

FeaturesWorkflowGetting Started GuideAI Draft AssistantSecurityLicensingDocumentationInstallationOffline ActivationSupport and Sales
PrivacySecurity StatementTermsRefund and cancellationIntellectual Property