FORGE by Threat Foundry

Evidence-grounded reasoning for security operations.

Forge helps analysts investigate, classify, design, validate, and tune from current tenant-authorized evidence. It proposes and explains. Deterministic services verify. Authorized humans decide.

Authorized evidenceTenant, user, permission, source, policy, and currentness are checked throughout the run.
Closed toolsForge uses a finite registry of bounded product tools instead of arbitrary execution.
Human authorityRecommendations and prepared drafts do not become approvals, deployments, or response actions.

One reasoning layer

Bring the analysis to the workspace where the decision already lives.

Forge extends existing Threat Foundry workflows instead of creating a separate chat destination. The current source, deterministic state, retrieved evidence, limitations, recommendation, and required review stay together.

IQ

Ask in context

Ask a bounded workspace question and review a concise Forge Plan before the final recommendation.

EV

Inspect the evidence

See authorized sources and citations, observed facts, deterministic findings, model inferences, and missing evidence as distinct classes.

TL

Follow the timeline

Review planning, tool use, retrieval state, cancellation, supersession, and recommendation history without exposing hidden reasoning.

DG

Degrade truthfully

Exact structured workflows remain usable when semantic retrieval or the selected model is unavailable; a fallback is never mislabeled as Forge output.

Investigation + triage

Explain what is known, what is inferred, and what still blocks a decision.

Forge can analyze a current case or triage finding, summarize readiness, surface evidence gaps and unresolved questions, relate bounded authorized evidence, and recommend the next reviewable step.

  • Case and triage source state reloaded before a current-evidence action
  • Deterministic severity, status, disposition, ownership, relationships, and lifecycle remain authoritative
  • At most five bounded case-task drafts can be proposed for exact human confirmation
  • No case closure, finding disposition, incident confirmation, containment, response, or external ticket creation

Detection + validation

Move from a coverage question to a reviewable draft—without confusing draft state with proof.

Forge supports coverage analysis, detection design, detection-chain design, validation planning, and validation-evidence analysis inside Detection Studio. Read-only tools retrieve bounded definitions, candidates, coverage, validation, assurance, health, and stored outcomes.

  • Observed facts and deterministic validation outcomes stay separate from Forge inferences
  • Apply-as-Draft requires fresh evidence, current permissions, citations, rationale, and deterministic checks
  • A draft is not approved, active, deployed, validated, or proof of coverage
  • Forge cannot launch validation, set an outcome, mutate a provider, approve, activate, deploy, or perform response

Candidate classification + tuning

Prepare bounded improvement work while independent review stays mandatory.

Forge can classify current tuning candidates, analyze drift and related evidence, prepare a review-ready proposal, optionally prepare an unapproved draft candidate, and identify exact retest work when every deterministic eligibility check passes.

  • Evidence sufficiency, freshness, confidence, materiality, protected state, positive and negative controls, cooldowns, and permissions are checked
  • Unknown materiality, stale evidence, unsupported tuning, protected detections, or deterministic fallback block automatic preparation
  • Prepared proposals remain review-ready and prepared candidates remain unapproved drafts
  • Independent acceptance, candidate review, retest, approval, and customer-controlled deployment remain separate decisions

A closed execution model

The model does not get a general-purpose operating system.

Forge uses server-owned capability definitions, strict input and output schemas, bounded turns, time, evidence, and tool calls, plus current authority checks at every boundary.

CT

Closed tools

No arbitrary shell, code, SQL, file system, browser, URL, credential, provider-administration, approval, deployment, or response tool.

AU

Reauthorization

Tenant, user, permission, workspace, source, policy, retrieved citations, deadlines, cancellation, and feature state are rechecked before persistence or action.

PR

Bound proposals

Tool names, versions, arguments, result size, invocation count, and action class are selected and constrained by server policy.

HS

Safe history

Plans, tool states, evidence references, decisions, feedback, and lifecycle events remain reviewable without storing secrets, raw credentials, vectors, or hidden reasoning.

Forge trust statement

Forge proposes and explains from authorized evidence. Deterministic services verify. Authorized humans decide. If authority, source, policy, evidence, or route changes, the affected work stops or becomes stale instead of silently continuing.

Forge Managed Operations

Give service operators useful guidance without centralizing customer evidence.

An authorized Control Center operator can request one bounded Forge analysis purpose for an eligible work item. Model contact and evidence retrieval stay inside the customer tenant. Control Center receives only an evidence-free projection of state, recommendation, sufficiency, limitations, and currentness.

  • Authoritative operational priority, assignment, SLA, escalation, and source lifecycle stay unchanged
  • Short-lived read-only tenant handoff can open the current analysis for review
  • No cross-tenant retrieval, automated assignment, priority change, escalation, proposal acceptance, approval, provider write-back, or response
  • Managed work continues normally if the model is unavailable or rate limited
Explore Control Center for MSSP/MSPs

“Useful automation prepares the next accountable decision. It does not quietly take it.”

Threat Foundry operating principle

Customer-selected AI

Forge follows the active BYOAI route.

The tenant selects the provider, model roles, and reviewed evidence boundary. Supported workflows bind that choice through review and execution. There is no silent provider fallback or partial verdict when the selected route or complete evidence handoff is unavailable.

Review BYOAI controls

Start with the workflow

Put Forge inside a workflow your team already owns.

Bring one investigation, triage, detection, validation, tuning, or managed-operations workflow. We will map the authorized evidence, deterministic controls, review points, and first useful outcome.