Security review packet.
The short version for the person deciding whether Fjord can hold company source code. This page summarizes the current operating facts and links to the policy or technical page behind each one.
Last updated July 30, 2026. This is a summary, not a separate agreement. The Terms, Privacy Policy, and Data Processing Addendum are the controlling documents.
Legal operator
Raster & State LLC, operating the Fjord managed Forgejo service.
Service shape
Dedicated, single-tenant upstream Forgejo instances, with optional dedicated CI runner VMs on Team and Pro.
Customer data ownership
Customers retain ownership of repository, issue, pull request, CI, and account content. Fjord receives only the limited license needed to provide, secure, support, and back up the service.
AI training
Fjord does not use repository or CI content to train or improve machine-learning models. The commitment is written into the Terms.
Regions
Customers choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) for managed instances and dedicated CI runner VMs. Backups are currently stored in EU (Helsinki, Finland) for every Instance, whichever region you choose; per-region backup storage is being rolled out.
Backups
Team and Pro receive nightly encrypted backups with 90-day rolling retention. Starter has no managed snapshot backups.
Restore model
Restore is operator-run from a documented runbook. Point-in-time restore, warm standby, contractual RTO, and contractual uptime SLA are not offered at launch.
Access controls
Administrative endpoints require MFA, inbound access is firewalled, SSH is limited to Fjord control-plane CIDR, and administrative actions are recorded in a tamper-evident ledger.
Sub-processors
6 vendors are disclosed publicly, with at least 30 days' notice before adding a new sub-processor.
Certifications
Fjord does not publish SOC 2, ISO 27001, ISAE 3402, or similar audit reports today.
