Vercel
CurrentPurpose: Application hosting and deployment metadata
Current usage: ForgeLayer uses Vercel-oriented deployment metadata and hosting configuration.
Data exposure: Application requests and rendered content may traverse the hosting environment.
Limitation: Region, contractual terms, retention, SLA, and certifications are not asserted by this repository.
Supabase
Foundation OnlyPurpose: Intended workspace identity and persistence provider
Current usage: Client/server adapters and workspace schema/RLS definitions exist; local Auth, RLS, tenant isolation, and durability validation passed.
Data exposure: The Trust Center does not query Supabase. Production workspace authentication and persistence flags remain disabled.
Limitation: Local migration/RLS validation is not production validation; production backup, retention, deletion, recovery, and monitoring remain unvalidated.
OpenAI
Not ConfiguredPurpose: Optional report generation provider
Current usage: An optional server report-provider code path exists. Deterministic Trust, Task, AgentOS, and PromptForge product models do not require it.
Data exposure: Supplied prompt/diff text could be sent only when that separate provider path is configured and invoked.
Limitation: Runtime enablement, region, retention, contractual controls, and model settings are not exposed or verified here.
Codex
Foundation OnlyPurpose: Workspace AI provider connection preview
Current usage: The workspace records a deterministic Codex product relationship using the Part 131 provider registry and adapter definition.
Data exposure: No OpenAI account identity, credential, provider output, repository access, health observation, dispatch, or execution exists.
Limitation: Production use requires authenticated workspace identity, secure secret storage, verified provider ownership, reviewed adapter controls, and sandboxed transport.
Claude Code
Foundation OnlyPurpose: Workspace AI provider connection preview
Current usage: Claude Code is a first-class deterministic workspace provider product with registry-owned modeled capabilities.
Data exposure: No Anthropic account identity, credential, provider output, repository access, health observation, dispatch, or execution exists.
Limitation: Production use requires provider-specific authentication, ownership and permission validation, adapter security review, containment, cancellation, and durable auditing.
Cursor
Foundation OnlyPurpose: Workspace AI coding environment connection preview
Current usage: Cursor is recorded as an AI coding environment with future IDE-extension or local-bridge semantics.
Data exposure: ForgeLayer cannot access or remotely control a Cursor desktop session and has no identity, credential, health, output, dispatch, or execution state.
Limitation: A future integration requires explicit workspace identity, reviewed local bridge or extension boundaries, isolation, redaction, and user-controlled authorization.
GitHub
DisabledPurpose: Webhook, repository policy, and read-only repository connection foundation
Current usage: GitHub App helpers and a server-only Repository Connection v1 adapter define Metadata: Read and Contents: Read access for identity, default-branch head, and bounded tree metadata.
Data exposure: Current workspace connections and source-content fetches are disabled. Installation tokens are intended to remain short-lived, server-only, unlogged, and non-persistent.
Limitation: Production requires trusted workspace identity, validated RLS persistence, installation ownership, revocation, audit events, and task-scoped authorization; posting and writes remain separate disabled boundaries.