
Security at Forolock
Your security platform should be secure too.
Forolock is built to inspect sensitive software and actions. We design the platform to minimise the amount of trust customers have to place in us.
We ask for as little access as possible, keep it for as short a time as possible, and record how it is used.
That means: less to trust, and less to lose.
Designed to need as little trust as possible.
A security platform sees sensitive things. These principles shape every part of how Forolock is built.
Least privilege
Forolock is designed to request only the access a feature needs, scoped to the repositories and resources you choose.
That means: No blanket access.
Access control
Access to customer data inside Forolock is designed to be limited by role and need, and granted only for a specific purpose.
In plain terms: Few people, clear reasons.
Auditability
Important actions, by people and by Forolock itself, are designed to be logged so they can be reviewed.
That means: Access leaves a record.

Built around least privilege
What Forolock can and cannot access.
You decide what to connect. Here is what Forolock may use, and what it does not need.
Only what you explicitly connect
- Yes: Source code you explicitly connect
- Yes: Application configuration
- Yes: Infrastructure metadata
- Yes: Runtime telemetry
- Yes: Agent actions
- Yes: Security-relevant logs
In plain terms: What it needs to find and stop risk.
Anything beyond the job
- No: Unrelated employee data
- No: Personal inbox access
- No: Unrestricted cloud access
- No: Permanent plaintext credentials
That means: Nothing it doesn’t need.
How customer data is handled.
Collection is limited to what is required to provide security functionality.
Data required for security functionality
- Yes: Code and configuration you connect
- Yes: Findings and attack evidence
- Yes: Policy decisions and their reasons
- Yes: Account and billing details
Unrelated business and personal data
- No: Customer records beyond what a finding needs
- No: Personal communications
- No: Data from systems you have not connected
That means: We see your software, not your business.
Protected in transit and at rest.
Forolock is designed so that customer data is encrypted in transit between your systems and ours, and encrypted at rest wherever it is stored.
Secrets and credentials are designed to be stored separately from other data, with tighter access.
In plain terms: Data stays protected the whole time.
Every customer stays isolated.
Forolock is designed so that one customer’s code, findings and credentials are never visible to another.
Tenant separation
Customer data is designed to be separated by tenant at every layer, from storage to search.
That means: Your data stays yours.
Contained testing
Exploit validation is designed to run in controlled, per-customer environments, with tests scoped to targets you approve.
Separate credentials
Each customer’s credentials are designed to be held and used independently, never shared between tenants.
Credentials should be temporary.
Forolock is designed around access that is narrow, short-lived and easy for you to revoke.
OAuth where possible
Connect through the provider’s own authorisation flow instead of pasting long-lived keys.
Scoped tokens
Tokens are designed to carry only the permissions a task needs, on only the resources you select.
Short-lived credentials
Access is designed to expire quickly and be renewed only when needed.
Least privilege
Read access by default; anything that changes your systems needs explicit permission.
Customer revocation
You can disconnect an integration or revoke access at any time, from your own provider.
Encrypted storage
Any credential Forolock must hold is designed to be encrypted and stored apart from other data.
Keep only what is needed.
Retention is designed to be configurable. Data needed to produce a finding is processed, the evidence is kept for the period you choose, and then it is deleted.
In plain terms: Data does not sit there forever.
Run on established infrastructure.
Forolock is designed to run on established cloud infrastructure, with production environments separated from development and testing.
Production access is designed to be limited to a small number of people, protected by strong authentication and logged.
In plain terms: Few doors, all of them watched.
Found something?
We welcome reports from security researchers and will work with you to fix issues quickly.
If you believe you have found a vulnerability in Forolock, please report it privately. Include enough detail for us to reproduce it, and give us reasonable time to fix it before sharing it publicly.
Please do not access, change or delete data that is not yours, or degrade the service while testing.
Report a vulnerability
We aim to acknowledge every report quickly and keep you updated until it is resolved.
- Report privately
- We acknowledge
- We investigate
- We fix
- We credit you
Security programme.
We publish facts, not badges. This section will list independent audits as they are completed.
Factual reporting
We will describe our security posture as it is today, and clearly mark anything that is planned.
Independent review
When audits such as SOC 2 or ISO 27001 are under way or complete, they will be listed here with their status.
Customer requests
Security questionnaires and data-processing terms are available on request.
Frequently Asked Questions
Does Forolock store my source code?
Forolock is designed to process the code you connect in order to produce findings, and to keep only what is needed as evidence for the retention period you choose.
Can I control what Forolock can access?
Yes. You choose which repositories, environments and agents to connect, and you can disconnect them or revoke access at any time.
Does Forolock need permanent credentials?
No. Forolock is designed around OAuth, scoped tokens and short-lived credentials rather than long-lived secrets.
Is exploit testing safe for my application?
Exploit validation is designed to be controlled and scoped to targets you approve, and to prove an issue exists without damaging data. You can choose which environments it runs against.
What certifications does Forolock hold?
We do not currently display any certifications. When independent audits are under way or complete, we will list them on this page with their status.
How do I report a vulnerability?
Email security@forolock.com with the details. We will acknowledge your report, keep you updated and credit you if you would like.