Security review packet.

The short version for the person deciding whether Fjord can hold company source code. This page summarizes the current operating facts and links to the policy or technical page behind each one.

Last updated July 30, 2026. This is a summary, not a separate agreement. The Terms, Privacy Policy, and Data Processing Addendum are the controlling documents.

Legal operator

Raster & State LLC, operating the Fjord managed Forgejo service.

Service shape

Dedicated, single-tenant upstream Forgejo instances, with optional dedicated CI runner VMs on Team and Pro.

Customer data ownership

Customers retain ownership of repository, issue, pull request, CI, and account content. Fjord receives only the limited license needed to provide, secure, support, and back up the service.

AI training

Fjord does not use repository or CI content to train or improve machine-learning models. The commitment is written into the Terms.

Regions

Customers choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) for managed instances and dedicated CI runner VMs. Backups are currently stored in EU (Helsinki, Finland) for every Instance, whichever region you choose; per-region backup storage is being rolled out.

Backups

Team and Pro receive nightly encrypted backups with 90-day rolling retention. Starter has no managed snapshot backups.

Restore model

Restore is operator-run from a documented runbook. Point-in-time restore, warm standby, contractual RTO, and contractual uptime SLA are not offered at launch.

Access controls

Administrative endpoints require MFA, inbound access is firewalled, SSH is limited to Fjord control-plane CIDR, and administrative actions are recorded in a tamper-evident ledger.

Sub-processors

6 vendors are disclosed publicly, with at least 30 days' notice before adding a new sub-processor.

Certifications

Fjord does not publish SOC 2, ISO 27001, ISAE 3402, or similar audit reports today.

Security contact

[email protected]

Documents to attach to a review