Security

Security boundaries for sensitive incident work

IncidentForge security boundaries emphasize local processing, controlled access and auditable licensing operations.

Separate the incident record from licensing

The licensing service handles account, entitlement, activation and operational audit data. It does not need incident content, report content or AI prompts to perform its boundary functions.

Controlled operations

Signed activation responses, rate-limited portal boundaries and audit evidence support controlled operations. Private signing material remains outside the public website and client workflow.

Standards-aligned workflow

IncidentForge supports workflow boundaries aligned with NIST, CISA, ENISA, ISO 27035 and MITRE ATT&CK. Alignment is not certification or a legal compliance attestation.