What Forge reads, stores, and never stores

The deep read fetches your source files to analyze them. What it keeps is a different, much smaller thing — and the difference is the entire trust question, so this page states it without the reassuring vagueness these pages usually have.

What Forge reads

  • A connected repository: the file tree, commit history, pull requests and reviews, and — on the deep read — the contents of eligible source files, through a GitHub App grant that is read-only and scoped to the repositories the installer selected. Merge and review webhooks keep the review-tax read current.
  • A public scan: public repositories only, tree and metadata, through a shared token. A private repository is refused rather than read. The ownership scan of a repository nobody connected stores nothing at all.
  • A repository read on your own machine: the CLI (npx @ambera/forge map) walks the git-tracked files on your computer, reads the manifests and the imports, and prints what the repository carries. It sends nothing and carries no telemetry. Signed in and with --submit, it hands one of your products a manifest of that reading and nothing else: the capabilities the manifests evidence, the dependency names behind them, the paths of the files importing them (capped, never their contents), counts, and the commit id. Forge stores that where the connected repository’s reading would be — one per product, replaced by the next — and writes no description and moves no card from it.

What a stored reading contains

File contents are fetched, analyzed in memory, and discarded. What a reading keeps is the report: counts over a stated sample, example paths, line numbers, and — for some finding types — a single normalized line as located evidence, length-capped, and withheld entirely whenever the line matches a credential pattern. No file, no function, no diff is ever stored. The repository’s HEAD commit id is kept so an unchanged repository can reuse its own reading instead of being re-fetched.

The cross-repository benchmark is fed by an anonymous row per reading — sizes, per-detector counts, primary language. No organization id, no repository name, no paths. Public front-door scans contribute nothing to it.

Where credentials live

A repository connected through the GitHub App stores no repository credential at all — access tokens are minted per request and expire within the hour. Connections that predate the App hold an OAuth token encrypted at rest (AES-GCM), and reconnecting through the App deletes that token and revokes it at GitHub. A Google Search Console connection holds a read-only OAuth token for the site’s own search figures; disconnecting it removes the token.

What leaves Forge

  • Nothing is written to your repository. Forge opens no branch, no commit and no pull request. With the pull request check switched on it posts a check result, and that is the whole of what it writes.
  • Brief links you create: a link publishes one Signal brief as it was written — the product’s name and the market entries with their sources, nothing from a repository. Links are revocable from the brief’s own page.
  • What a model is sent: your product’s description, the market entries a cycle read, and counts and names from a repository reading — never source-file contents. No model produces a number anywhere in Forge.

Disconnecting, and deleting

Disconnecting a repository removes the webhook and the stored credential. Its readings stay by default — the audit’s value is its memory, and a reconnect picks the history back up — and the disconnect dialog offers deleting them instead, permanently. Rescue purchase receipts are billing records and stay either way.

An account can be deleted from its own settings: the account deactivates immediately, signs out everywhere, and a nightly job purges its data after a 30-day grace window — along with any workspace where it was the only member. Workspaces with other members name a new owner or write to hello@ambera.app for org-wide deletion, which is handled on request as the privacy policy states.