Security
Security boundaries for sensitive incident work
IncidentForge security boundaries emphasize local processing, controlled access and auditable licensing operations.
Separate the incident record from licensing
The licensing service handles account, entitlement, activation and operational audit data. It does not need incident content, report content or AI prompts to perform its boundary functions.
Controlled operations
Signed activation responses, rate-limited portal boundaries and audit evidence support controlled operations. Private signing material remains outside the public website and client workflow.
Standards-aligned workflow
IncidentForge supports workflow boundaries aligned with NIST, CISA, ENISA, ISO 27035 and MITRE ATT&CK. Alignment is not certification or a legal compliance attestation.
