# fremforge - full content > EU-sovereign Git hosting with CI/CD included. Hosted in Germany on T Cloud Public. Exportable. Generated from https://www.frem.sh/. Curated index: https://www.frem.sh/llms.txt Content © fremverk. Forgejo is GPL v3+, shipped unmodified. ================================================================================ # SSH host key fingerprints - frem.sh URL: https://www.frem.sh/ssh-fingerprints/ > Authoritative fingerprints for the Forgejo SSH host keys at frem.sh and ssh.frem.sh. Verify these on first connect to detect tampering. When your SSH client connects to `ssh.frem.sh:443` for the first time, it asks you to confirm the server's host key fingerprint. (Port 22 is not publicly exposed on the apex domain - `ssh.frem.sh:443` is the only published SSH endpoint.) **Verify the fingerprint matches one of the values below before accepting.** A fingerprint that does not appear here means you are looking at a man-in-the-middle, a stale cache, or a different server - do not trust it. ## Current fingerprints | Algorithm | SHA-256 fingerprint | Bit length | |---|---|---| | `ssh-rsa` | `SHA256:LNz5zoh9R2KZAhNGeFgKSeBMPEzbNBdd0wqwrwEkU3E` | 4096 | Currently only `ssh-rsa` is published. ED25519 + ECDSA host keys are not enabled at the Forgejo layer in this deployment; if your client requires them, force RSA via `ssh -o HostKeyAlgorithms=ssh-rsa,rsa-sha2-256,rsa-sha2-512`. ## What to do at the prompt When OpenSSH prints something like: ``` The authenticity of host 'ssh.frem.sh (...)' can't be established. RSA key fingerprint is SHA256:LNz5zoh9R2KZAhNGeFgKSeBMPEzbNBdd0wqwrwEkU3E. Are you sure you want to continue connecting (yes/no/[fingerprint])? ``` Compare the printed fingerprint to the row in the table above. If it matches, type `yes`; OpenSSH adds the key to your `~/.ssh/known_hosts` and never prompts again for that host. If it does **not** match, type `no` and reach out via `support@frem.sh` before trying again. ## Avoiding the prompt entirely You can pre-trust the host key by appending it to your `known_hosts` file: ```bash ssh-keyscan -t rsa -p 443 ssh.frem.sh >> ~/.ssh/known_hosts ``` Then verify the SHA-256 with: ```bash ssh-keygen -lf <(ssh-keyscan -t rsa -p 443 ssh.frem.sh 2>/dev/null) ``` The output should match the table above. ## When fingerprints rotate We rotate Forgejo host keys only when the underlying server cluster is rebuilt. When that happens we publish the new fingerprints here at least 24 hours before the cutover, archive the previous fingerprints for 90 days under [Previous fingerprints](#previous-fingerprints), and post a notice on [status.frem.sh](https://status.frem.sh). If your client warns "REMOTE HOST IDENTIFICATION HAS CHANGED" and the new fingerprint does **not** appear here, do **not** clear `known_hosts` - contact us first. ## Previous fingerprints None archived (this is the first publication of this page). ## Related - [Connecting to fremforge over SSH](https://docs.frem.sh/get-started/connecting/) - clone instructions, port-443 fallback, troubleshooting - [Status page](https://status.frem.sh) - current uptime + planned maintenance - [Trust page](/trust/) - sub-processors, audit posture, EU-only data residency --- *Last updated: 2026-05-06.* ================================================================================ # Legal documents URL: https://www.frem.sh/legal/ > fremforge legal bundle - Terms of Service, Privacy Notice, Data Processing Agreement, Acceptable Use Policy, Service Level Agreement, Cookie Policy, ROPA, DPIA, and the Controller-side incident-response runbook. The full set of fremforge legal and compliance documents. Each page below is rendered from a canonical markdown source kept in lockstep with the marketing site; if a rendered page ever disagrees with its source, the source governs. ## Customer-facing agreements - [Terms of Service](/legal/terms/) - the master agreement governing use of the fremforge product. - [Privacy Notice](/legal/privacy-product/) - categories of data processed, lawful bases, retention, GDPR rights. - [Data Processing Agreement](/legal/dpa/) - GDPR Art. 28 processor terms, sub-processor list, international-transfers posture, audit rights. - [Acceptable Use Policy](/legal/aup/) - lawful-use rules, prohibited content, DSA Art. 16 notice-and-action, enforcement actions. - [Service Level Agreement](/legal/sla/) - uptime targets, planned-maintenance windows, security-patch SLA, incident communication, service-credit calculation. - [Cookie Policy](/legal/cookie-policy/) - cookies, consent posture, analytics stance. ## fremverk-as-Controller documents - [Record of Processing Activities (ROPA)](/legal/ropa/) - the GDPR Art. 30 register for fremverk-as-Controller activities (HR, billing, audit-chain integrity, sub-processor selection). - [DPIA - Audit Monitoring](/legal/dpia-audit-monitoring/) - Data Protection Impact Assessment for the platform-wide audit-monitoring activities fremverk operates as Controller. - [Controller-side Incident Response](/legal/controller-incident-response/) - scope and availability of the runbook for breaches affecting fremverk-as-Controller activities (per DPA §8.5). The runbook itself is classified internal and is available to customers and auditors under NDA. ## Website notices The marketing website at `www.frem.sh` is governed by separate, narrower notices that cover only the marketing site (not the product): - [Website Terms](/terms/) - [Website Privacy Policy](/privacy/) Once self-serve signup opens, the product Terms and Privacy Notice above supersede these website notices for product users. ## Related - [Trust & compliance](/trust/) - overall security posture, sub-processors, and certifications. - [Security](/security/) - vulnerability disclosure and incident communication. - [Status](https://status.frem.sh/) - current uptime and maintenance windows. ================================================================================ # Partner programme URL: https://www.frem.sh/partners/ > Resell fremforge in the Nordics. Register deals, keep them protected, earn recurring margin on every customer you bring. *For consultancies and managed-service providers selling developer tooling in the Nordics.* ## Why partner with fremforge Your customers are being asked where their source code lives. fremforge is EU-sovereign Git hosting with CI included — every processing surface inside the EU, no US-parented sub-processors on any path, and export from day one. You bring the relationship. We run the platform. ## How it works **Register the deal.** Tell us which company you are working, as early as you can. Registration opens a **90-day protection window** on that customer. We email you 14 days and 3 days before it lapses, so it never expires quietly. **Win it, then create the customer yourself.** From your portal you provision their organisation, invite their administrator, and the customer is assigned to you the moment it exists — so margin counts from their first invoice rather than from whenever an operator got round to it. **Earn recurring margin.** Not a one-off referral fee. You earn on your customers' actual invoices, for as long as they stay, and the rate reflects how long the relationship has run. **Get paid on a monthly statement.** We build your statement on the 1st for the previous month and email you. You invoice us on your own document; we pay 30 days from receipt. Between statements your portal shows margin accruing in real time, so nothing is a surprise. ## If two partners claim the same customer We resolve it on **evidence of sales activity** — meetings, proposals, correspondence — never on who registered first, and never on who is larger. We also never tell either partner who the other is. A conflict is a conversation between you and us, not between you and a competitor. ## What you get - A partner portal in English, Danish, German, French, Dutch and Swedish - Deal registration with automatic protection tracking - Self-service customer provisioning - Monthly statements with a per-customer breakdown you can reconcile - A full REST API — everything in the portal is scriptable, so you can drive it from your own CRM or an assistant - A signed frame agreement, executed with a national eID ## Signing The frame agreement is signed electronically with your national eID. In Denmark and Sweden we use a **company-bound** credential — MitID Erhverv and Freja eID+ organisation — so the signature evidences authority to bind the company, not just who clicked. In Norway and Finland no company credential exists, so we record the signatory's title and rely on the authority warranty in the agreement. We will tell you which applies to you before anything is sent. You do not need to be the person registered to sign for the company. A sales director signing within their remit binds the company under ordinary agency rules; if your organisation restricts who holds the company credential, we have a documented path for that. ## Where we are looking for partners Denmark, Sweden, Norway and Finland today. If you sell developer tooling elsewhere in the EU, still get in touch — the platform is EU-wide and the programme follows demand. ## Apply Email **[partners@frem.sh](mailto:partners@frem.sh)** with your company, the countries you sell into, and the kind of customer you work with. We onboard partners by invitation and talk to every applicant. Commercial terms — margin rates, tiers and thresholds — are shared during that conversation and set out in the frame agreement. ================================================================================ # Pricing URL: https://www.frem.sh/pricing/ > One plan. Per seat. In EUR. Sovereignty not behind a paywall.

Pricing

One plan. Per seat. In EUR.

Every seat ships with sovereignty, supply-chain security, hosted runners, and full export rights. One price covers Actions minutes, security signing, dependency scans, and on-demand data export - all on EU infrastructure.

€30 / seat / month

Billed monthly. Cancel any time at end of paid month.

Billed in EUR. VAT reverse-charge for EU B2B with a valid VIES VAT number.

Read-only readers are free and unlimited. Only members who can push or administer count as a seat. How readers work →

At today's mid-market rates, €30 is roughly £26 / CHF 28 / kr 320 NOK / kr 224 DKK. Your effective cost in your local currency varies with FX on each invoice date. Customers outside the EUR zone are charged in EUR; their bank or card provider applies the conversion. Enterprise customers invoiced on payment terms can agree DKK invoicing instead.

30-day free trial on signup. Card authorisation at signup via Mollie hosted checkout (€0 - no funds taken; some banks may briefly pre-auth €0.01 and reverse it). Trial auto-converts to your monthly plan on day 30; cancel any time before then in Admin → Billing at no cost. We send a reminder 3 days before the auto-charge.

Trial caps: 1 seat, 10 repositories, 500 runner-minutes pooled across the full 30-day trial. The full 1,000 runner-minutes/seat monthly pool unlocks at first payment. Caps protect the platform during the trial window; legitimate evaluation fits comfortably - that's ~25-50 typical CI runs.

Annual term: €306/seat charged upfront for the year. If you cancel, access continues to your committed-until date and the year stands as paid. Auto-renews unless cancelled at least 30 days before term end. Full detail in the terms of service.

What's included

How €30 compares

Same per-seat tier, same supply chain controls - without the add-on tax.

GitHub Enterprise + Advanced Security 🇺🇸 hosted in the US

$70/seat/mo≈ €65/seat/mo · €780/seat/yr

$21 Enterprise + $49 Advanced Security (Code Security $30 + Secret Protection $19, per active committer). Team ($4) is not comparable - it lacks SAML SSO, audit logs, and IP allowlisting. Actions minutes metered separately. Dependabot consumes Actions minutes on top.

GitLab Ultimate 🇺🇸 hosted in the US

$99/seat/mo≈ €92/seat/mo · €1.100/seat/yr

SAST, DAST, dependency & container scanning, vulnerability management. CI minutes metered separately. Premium ($29) does not include the supply chain stack.

fremforge 🇪🇺 hosted in Germany

€30/seat/moflat · €360/seat/yr · €306 on annual commit

Supply chain stack included. 1.000 CI min/seat pooled. Hosted Renovate. Signed export. Zero US sub-processors.

USD prices are published list prices at the time of writing; EUR equivalents converted at ~1.08 USD/EUR for orientation only - your actual EUR equivalent depends on the spot rate when GitHub or GitLab bills your card. fremforge prices in EUR throughout, no FX exposure on renewal. Pricing reviewed annually.

frembench — add-on, per bench seat

A Linux machine you reach from the browser, for running a coding agent off your laptop. Requires a fremforge seat.

€39 / bench seat / month

200 hours of runtime included, pooled across bench seats. Prorated on change. VAT reverse-charge for EU B2B with a valid VIES VAT number.

At today's mid-market rates, €39 is roughly £34 / CHF 36 / kr 416 NOK / kr 291 DKK. Charged in EUR, like every other line on your invoice; your bank or card provider applies the conversion.

What's included

Payment & billing

Single currency, single price

EUR on every self-serve plan and every invoice. No localised pricing games, no FX surprise on renewal. Enterprise customers on invoice terms can be billed in DKK by agreement.

VAT reverse-charge

Available for EU B2B customers with a valid VIES VAT number. Verified at signup.

Payment methods

Card (Visa, Mastercard), SEPA direct debit, SEPA bank transfer, Google Pay, Apple Pay. Processed by Mollie (NL).

No minimum seat count. Public-sector or regulated buyers who require NET-30 invoice billing on a purchase order: email hello@frem.sh - we handle those cases individually. See trust for the full sub-processor list and the DPA for the contractual posture.

Start your 30-day free trial → See product
================================================================================ # Privacy policy URL: https://www.frem.sh/privacy/ > How fremverk handles personal data on www.frem.sh **Effective Date:** 2026-04-25 - **Version:** 1.1 *Last updated: 2026-07-01* ## Introduction fremforge is a product operated by **fremverk ApS** ("we", "us", or "our"). This Privacy Policy explains how we handle personal data on `www.frem.sh` (the fremforge marketing website). A separate [Product Privacy Notice](/legal/privacy-product/) covers the fremforge product itself - the hosted Git and CI/CD service on `frem.sh`. ## Data controller **fremverk ApS**\ CVR: 39150689\ VAT: DK39150689\ Ringager 4C, 2. tv, 2605 Brøndby, Denmark\ Email: [compliance@frem.sh](mailto:compliance@frem.sh) · [info@fremverk.com](mailto:info@fremverk.com) fremforge is a product brand of fremverk ApS; fremverk ApS is the legal and GDPR-responsible entity for all personal data processed in connection with the fremforge marketing website. ## What this website does not do We believe privacy claims should be verifiable, so we want to be explicit: - **No advertising or analytics cookies** - this website does not use cookies for analytics, advertising, or cross-site tracking - **No tracking pixels or fingerprinting** - there are no third-party tracking scripts - **No external font loading** - all fonts are self-hosted (no requests to Google, Adobe, or others) - **No auto-loaded third-party widgets or maps** - external services are contacted only if you choose to open an external link - **Limited browser-side preference storage only** - this site may use the browser's `localStorage` API to remember an appearance preference (light/dark) if you explicitly use the theme switcher; this is not used for analytics, advertising, or cross-site tracking - **Preferences are stored only after user action** - nothing is written to `localStorage` unless you toggle a preference yourself - **No consent banner for tracking** - because we do not use non-essential cookies or similar technologies for analytics, advertising, or third-party tracking You can verify this using your browser's developer tools (Network and Application tabs). If you choose to open an external link, that destination handles your request under its own policy. This site does not auto-load third-party widgets or embedded maps. Edge delivery and caching are covered separately in the Hosting section below; they are operational infrastructure rather than browser-side tracking. ## Hosting This website is hosted on **T Cloud Public** (Deutsche Telekom), an EU-sovereign cloud provider. The origin is a T Cloud Public OBS bucket in the `eu-de` region, with twin-core datacenters in Biere and Magdeburg, Germany. The public website is delivered through **Bunny CDN** in front of the origin, restricted to EU points of presence. To deliver, cache, and protect the site, T Cloud Public and Bunny process technical request data such as IP address, timestamp, requested URL, HTTP status code, and user agent in server or edge logs. We use this data solely for content delivery, security monitoring, abuse prevention, and troubleshooting. Operational access logs under our control are retained for a maximum of 30 days. The legal basis is legitimate interest (GDPR Art. 6(1)(f)) in maintaining the security, integrity, and availability of our website. ## Signing up This website does **not** collect personal data through any form - there is no waitlist or email-capture form on it. To create an account, you go to the product signup at [frem.sh/_app/signup](https://frem.sh/_app/signup), which includes a 30-day free trial. Any personal data you provide while signing up or using the product is governed by the **[product privacy policy](/legal/privacy-product/)**, not this website notice. This website itself only processes the technical request and log data described above, for content delivery and security. ## Analytics When we add analytics to this website, we will use a privacy-focused, EU-sovereign or self-hosted solution that does not use cookies or track individual visitors. Such tools work by aggregating page view counts, referrer information, and approximate geographic region (country level) without storing personal identifiers. If we deploy analytics on that basis, we do not expect a consent banner to be required for analytics because no non-essential cookies or comparable tracking identifiers would be used. This section will be updated when analytics are deployed. ## Information you provide directly If you contact us by email (for example at [hello@frem.sh](mailto:hello@frem.sh) or [security@frem.sh](mailto:security@frem.sh)), we may receive: - **Contact information**: name, email address - **Business information**: company name, job title, questions or context you share We use this information to respond to your inquiry and comply with legal obligations. ## Legal basis for processing Under GDPR, we process your data based on: - **Consent** (Art. 6(1)(a)): for any optional purpose you explicitly opt in to - **Contractual necessity and pre-contractual steps** (Art. 6(1)(b)): when responding to inquiries about future services - **Legal obligation** (Art. 6(1)(c)): when we need to retain records or comply with applicable law - **Legitimate interest** (Art. 6(1)(f)): for website delivery via T Cloud Public and Bunny, server and edge log processing, security monitoring, abuse prevention, and improving service reliability ## Data sharing We do not sell, trade, or rent your personal information. We may share data with: - **Lettermint B.V.** - Zwolle, Netherlands - outbound transactional email (system notifications and any reply we send you). EU-only operating entity (NL - no US parent). - **Heinlein Hosting GmbH (mailbox.org)** - Berlin, Germany - shared-mailbox hosting (correspondence sent by you to `support@`, `security@`, `compliance@`, `hello@`, `info@fremverk.com`). EU-only operating entity, no US parent. - **T Cloud Public (Deutsche Telekom AG)** - Biere/Magdeburg, Germany - primary hosting (all platform data). - **Bunny CDN d.o.o.** - EU PoPs only (HQ Slovenia) - edge delivery, WAF, DDoS for the marketing site. - **Legal authorities** when required by applicable law. This marketing website runs no signup form and uses **no third-party bot-mitigation processor**. Account signup in the product uses Altcha (self-hosted, MIT-licensed, HMAC-signed proof-of-work; runs in-process inside the api monolith) - no third-party widget, no external sub-processor. ## Data retention - **Server and edge logs**: maximum 30 days - **Private-beta signup email addresses**: until 90 days after onboarding completes or you withdraw, whichever comes first - **Direct email correspondence**: for the duration of our business relationship plus 5 years, or as required by Danish bookkeeping legislation ## Your rights Under GDPR, you have the right to: - **Access** your personal data (Art. 15) - **Rectify** inaccurate data (Art. 16) - **Erase** your data (Art. 17), subject to GDPR Art. 17(3) carve-outs - **specifically Art. 17(3)(b)**: where retention is required for compliance with a legal obligation under Union or Member-State law to which fremverk is subject. The principal carve-outs in practice are **Danish Bogføringsloven §10** (5-year retention of accounting records: invoice line items + tenancy identifiers required to reconcile invoices) and the audit-trail retention promised in DPA Annex A.7 (3-year WORM archive for security-relevant audit events). Erasure of these subsets is suspended for the statutory period; PII fields not required for the legal-obligation purpose are pseudonymised separately on request, per DPA §9. - **Restrict** processing (Art. 18) - **Data portability** - receive your data in a structured, machine-readable format (Art. 20) - **Object** to processing based on legitimate interests (Art. 21) - **Withdraw consent** at any time, without affecting the lawfulness of prior processing (Art. 7(3)) To exercise these rights, contact us at [compliance@frem.sh](mailto:compliance@frem.sh). We will respond within 30 days. ## Supervisory authority You have the right to lodge a complaint with the Danish Data Protection Agency: **Datatilsynet**\ Carl Jacobsens Vej 35, 2500 Valby, Denmark\ Website: [datatilsynet.dk](https://www.datatilsynet.dk)\ Email: [dt@datatilsynet.dk](mailto:dt@datatilsynet.dk) ## Data security We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (TLS), least-privilege access controls, and operational monitoring on the hosting platform. ## EU sovereignty / US extraterritorial law The fremforge marketing site and shared mailboxes run on a stack with **no US-parented processor in the path**: T Cloud Public (Deutsche Telekom, Germany), Bunny CDN (EU PoPs only), Lettermint B.V. (Zwolle, Netherlands), and Heinlein Hosting GmbH / mailbox.org (Berlin, Germany). Bot mitigation is server-side only; no third-party captcha vendor. **Zero US-parented sub-processors on any path.** The product (post-signup) follows the same posture in tighter detail. See the [product DPA](/legal/dpa/) for the full Article 28 processor terms and the [product privacy notice](/legal/privacy-product/) for the data-subject view. ## International transfers We keep website hosting within the European Economic Area (EEA). Email you send us routes to our shared mailboxes at Heinlein Hosting / mailbox.org (DE) - also EEA. If a service used for website operations involves a transfer outside the EEA, we will rely on an appropriate transfer mechanism under GDPR and update this policy accordingly. ## Changes to this policy We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page. A separate fremforge product privacy notice is published at **[/legal/privacy-product/](/legal/privacy-product/)** and supersedes this website notice for product users. The product notice covers repository and CI usage, log retention, billing data, sub-processor list, and data-subject request process in detail. ## Change log | Version | Date | Change | |---|---|---| | 1.0 | 2026-04-25 | Initial publication. | | 1.1 | 2026-07-01 | Go-live / GA: removed pre-launch framing. This policy now describes the live fremforge marketing website (`www.frem.sh`); the Product Privacy Notice at [/legal/privacy-product/](/legal/privacy-product/) is published and covers product users. No change to what data the marketing site processes. | ================================================================================ # Security URL: https://www.frem.sh/security/ > How to report a security issue, and what to expect. **Effective Date:** 2026-04-25 - **Version:** 1.0 *Last updated: 2026-04-25* ## Report a vulnerability Email **security@frem.sh**. Encrypted mail welcome; PGP key fingerprint published on the [trust page](/trust). We acknowledge reports within 48 business hours (see the safe-harbour clause below for the formal commitment). Critical issues in the fremforge surface are patched ahead of upstream Forgejo when required; upstream bugs are coordinated with the Forgejo security team under their disclosure policy. Published time-to-patch commitments by severity are on the [trust page](/trust#security-patching). ## Vulnerability disclosure Report vulnerabilities to [security@frem.sh](mailto:security@frem.sh). A machine-readable disclosure policy is published at [`frem.sh/.well-known/security.txt`](https://frem.sh/.well-known/security.txt) per RFC 9116, including scope, contact, preferred languages, and acknowledgement window. **Safe-harbour**: good-faith research within the published scope is covered by safe-harbour. fremverk will not pursue legal action against researchers who follow the disclosure policy. We commit to acknowledging vulnerability reports within 48 business hours and to coordinated disclosure on a mutually agreed timeline. PGP key fingerprint for `security@frem.sh` is published at [`frem.sh/trust#security-contact`](https://www.frem.sh/trust/#security-contact). ## Scope - `frem.sh` - Forgejo UI, Git protocol, API, package registry - `www.frem.sh`, `docs.frem.sh`, `status.frem.sh` - The `fremforge-prd` T Cloud Public tenant - Email / transactional surfaces sending from `@frem.sh` ## Out of scope - Third-party integrations you configure against fremforge (report to the vendor) - Findings that require a pre-authenticated, privileged user session to reproduce beyond what the user already has access to ## What we publish Security advisories are posted on the [trust page](/trust) and emailed to the security mailing list. Post-mortems for any incident that affected customer data or availability are published within 14 days. ## Change log | Version | Date | Change | |---|---|---| | 1.0 | 2026-04-25 | Initial publication. | ================================================================================ # Terms of service URL: https://www.frem.sh/terms/ > Terms and conditions for the fremforge marketing website **Effective Date:** 2026-04-25 - **Version:** 1.1 *Last updated: 2026-07-01* ## About us fremforge is a product brand of **fremverk ApS**. These Terms of Service ("Terms") are entered into between you and: **fremverk ApS**\ CVR: 39150689\ VAT: DK39150689\ Ringager 4C, 2. tv, 2605 Brøndby, Denmark\ Email: [hello@frem.sh](mailto:hello@frem.sh) · [info@fremverk.com](mailto:info@fremverk.com) A separate product Terms of Service is published at **[/legal/terms/](/legal/terms/)** and governs use of the fremforge Git hosting product itself. These website Terms cover only the marketing site and documentation surfaces at `www.frem.sh`, `frem.sh`, and `docs.frem.sh`. ## Agreement to terms By accessing or using this website, you agree to be bound by these Terms and our [Privacy Policy]({{< relref "privacy" >}}). If you do not agree, please do not use this website. ## About this site fremforge is live - **self-serve signup is open** at [frem.sh/_app/signup](https://frem.sh/_app/signup), including a 30-day free trial. This website exists to describe the product and its terms; creating an account, starting a trial, and subscribing all happen in the product itself. Browsing this website does **not**: - Create an account - Reserve a subscription or seat - Guarantee price, availability, or feature set - Constitute a contract for the supply of services Account creation, the free trial, pricing, and the product-specific terms are handled in the product; the fremforge product terms at [/legal/terms/](/legal/terms/) apply once you sign up. ## Use of website ### Permitted use You may use this website for lawful purposes related to learning about fremforge, signing up for the product, and contacting us. ### Prohibited use You may not: - Use this website in any way that violates applicable laws - Attempt to gain unauthorised access to our systems - Use automated tools to scrape or collect data from this website, or to submit forms or requests in bulk - Interfere with the proper functioning of this website ## Intellectual property All content on this website (including text, graphics, logos, and software) is the property of fremverk ApS or its content suppliers and is protected by intellectual property laws. You may not reproduce, distribute, or create derivative works from any content without our prior written consent. Forgejo, which fremforge runs as a modified build, is licensed under the GNU General Public License v3.0 or later and is © its respective copyright holders. References to Forgejo on this site do not imply endorsement by the Forgejo project. ## Disclaimer of warranties This website and its content are provided on an "as is" and "as available" basis. To the maximum extent permitted by applicable law, we disclaim all warranties, express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that this website will be uninterrupted, error-free, or free of harmful components. Statements about the future fremforge product (including pricing, feature scope, launch timing, and regional availability) are forward-looking and subject to change. Nothing on this website constitutes a binding offer, quote, or commitment to deliver the product on specific terms. ## Limitation of liability To the maximum extent permitted by Danish law: - We are not liable for any indirect, incidental, special, or consequential damages, including loss of profit, data, or business opportunity arising from use of this website - Our total aggregate liability for any claim related to this website or these Terms shall not exceed EUR 1,500 - We are not liable for any third-party services, platforms, or providers referenced on this website ## Indemnification You agree to indemnify and hold harmless fremverk ApS, its directors, and employees from any claims, damages, or expenses arising from your use of this website or violation of these Terms. ## Third-party links This website contains links to third-party sites, including `forgejo.org`, the fremverk corporate site, and others. We are not responsible for the content, accuracy, or practices of these external sites. Inclusion of a link does not imply endorsement. ## Force majeure Neither party shall be liable for any delay or failure to perform its obligations under these Terms where such delay or failure results from circumstances beyond the party's reasonable control, including but not limited to natural disasters, war, terrorism, pandemics, strikes, government actions, power failures, internet or telecommunications failures, or cyberattacks. ## Governing law and jurisdiction These Terms are governed by and construed in accordance with the laws of Denmark, without regard to its conflict-of-law principles. Any disputes arising under or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of Denmark. ## Dispute resolution Before initiating court proceedings, the parties agree to first attempt to resolve any dispute through good-faith mediation. If the dispute is not resolved within 60 days of the initial mediation request, either party may proceed to litigation in accordance with the governing law section above. ## Changes to terms We reserve the right to modify these Terms. Material changes will be posted on this page with an updated "Last updated" date. Changes take effect 30 days after posting. Your continued use of this website after the effective date constitutes acceptance of the modified Terms. ## Entire agreement These Terms, together with our [Privacy Policy]({{< relref "privacy" >}}), constitute the entire agreement between you and fremverk ApS regarding the use of the fremforge marketing website. Any prior or contemporaneous agreements, communications, or understandings relating to the subject matter hereof are superseded. ## Severability If any provision of these Terms is found to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable. ## Contact For questions about these Terms, contact: **fremverk ApS**\ Email: [hello@frem.sh](mailto:hello@frem.sh) · [info@fremverk.com](mailto:info@fremverk.com) ## Change log | Version | Date | Change | |---|---|---| | 1.0 | 2026-04-25 | Initial publication. | | 1.1 | 2026-07-01 | Go-live / GA: removed "pre-launch website" framing throughout; these Terms now cover the live fremforge marketing website. No change to liability, governing law, or any substantive term. | ================================================================================ # Trust URL: https://www.frem.sh/trust/ > Where fremforge runs, who processes data, and what we commit to. **Effective Date:** 2026-05-19 - **Version:** 1.5 *Last updated: 2026-07-01* ## Summary fremforge is EU-sovereign Git hosting built on upstream Forgejo and operated by fremverk ApS (Denmark). Every surface runs in the European Union. No customer data leaves EU jurisdiction. Every processing surface (repositories, CI, audit, billing, authentication, outbound email, inbound shared-mailbox correspondence) runs on entities with **no US parent**. **Zero US-parented sub-processors on any path.** See the product DPA §11.3 for the full posture. This page is the canonical reference for where your data lives, who processes it, what certifications apply, and how to reach us. ## Data controller fremverk ApS CVR: 39150689 Ringager 4C, 2. tv, 2605 Brøndby, Denmark Email: [compliance@frem.sh](mailto:compliance@frem.sh) · [info@fremverk.com](mailto:info@fremverk.com) ## Hosting and regions | Surface | Processor | Region | |---|---|---| | Forgejo UI, Git, API, package registry | T Cloud Public (Deutsche Telekom) | `eu-de` (Biere/Magdeburg, DE) | | Marketing, docs, status | Bunny CDN | EU PoPs only | | Outbound transactional email (system notifications, billing, magic-links) | Lettermint B.V. | Zwolle, Netherlands | | Inbound shared-mailbox correspondence (`support@`, `abuse@`, `security@`, `compliance@`, `hello@`, `ops@`, `enterprise@`, `info@fremverk.com`) | Heinlein Hosting GmbH (mailbox.org) | Berlin, Germany | | Payments | Mollie | Netherlands | | Billing engine | fremforge in-monolith engine (self-hosted by fremverk) | `eu-de` (T Cloud Public) | | Accounting integration (fremverk-side bookkeeping per Bogføringsloven §10; receives org legal name, billing-contact email, VAT number, invoice line items, Mollie payment-id. No repository content, no audit-log content, no PAN.) | Visma Dinero | Copenhagen, Denmark | ## Sub-processors The current sub-processor list is maintained here. Any change is announced 30 days in advance to the security mailing list and on this page. | Sub-processor | Purpose | Location | Certifications | |---|---|---|---| | Deutsche Telekom AG (T Cloud Public) | Core compute, storage, network | Biere/Magdeburg, DE | ISO 27001, 27017, 27018; BSI C5 Type 2; TISAX | | Bunny CDN d.o.o. | Edge delivery, TLS termination, DDoS mitigation, rate limiting (the Shield **WAF is not enabled** — see §Edge WAF below) | EU PoPs (HQ Slovenia) | ISO 27001 (2025), SOC 2 Type II (2023) | | Lettermint B.V. | Outbound transactional email | Zwolle, Netherlands | Vendor certifications pending evidence (NL - no US parent) | | Heinlein Hosting GmbH (mailbox.org) | Shared-mailbox hosting (`support@`, `abuse@`, `security@`, `compliance@`, `hello@`, `ops@`, `enterprise@`, `info@fremverk.com`) | Berlin, Germany | ISO 27001, BSI C5, BSI IT-Sicherheitskennzeichen (TR 03108) | | Mollie B.V. | Payment processing | Amsterdam, NL | PCI-DSS Level 1 | | Visma Dinero ApS | Accounting integration (fremverk-side bookkeeping per Bogføringsloven §10; receives org legal name, billing-contact email, VAT number, invoice line items, Mollie payment-id. No repository content, no audit-log content, no PAN.) | Copenhagen, DK | ISO 27001 (DK-issued, no US parent) | Bot mitigation does not involve a third-party processor. The product signup and login forms use self-hosted **Altcha** (MIT-licensed, HMAC-signed proof-of-work) running in-process inside the api monolith on the same T Cloud Public cluster; no third-party widget JS, no external sub-processor. Additional server-side controls (per-IP throttling, edge WAF) apply across the surface. ### Edge WAF - Bunny Shield posture (launch baseline) The Bunny CDN pullzones in front of `frem.sh` (Forgejo) and the api surface (`/_app/*`) run Bunny **Shield Basic** at launch, not Shield Advanced. Shield Basic provides volumetric DDoS mitigation, rate limiting, and IP/geo/bot signal filtering; the OWASP Core Rule Set (CRS) WAF available in Shield Advanced is *not* enabled on these two pullzones. The decision is intentional: Forgejo's URL patterns (Git protocol paths, pull-request diff routes, raw-blob fetches with hex-string identifiers, signed-URL query-strings) produced a high false-positive rate against the upstream CRS during pre-launch testing; an over-aggressive WAF that breaks legitimate Git operations or Forgejo UI flows would have shipped a worse customer outcome than the residual edge-layer risk. Mitigation lives in-app rather than at the edge: pre-receive secret-scanning, Altcha PoW on signup/login, per-IP and per-tenant rate limits in the Hono middleware, signed-token auth on every webhook receiver, and the audit-chain integrity hash. The static-site pullzones (www, docs, status, cli) run Shield Advanced with CRS enabled because their request shape is regular static-HTML traffic where CRS does not false-positive. The Forgejo/api Shield posture will be re-evaluated after 90 days of false-positive telemetry on a canary subset with Shield Advanced enabled. ### Hosted-runner isolation - ephemeral ECS VM, one per commit CI jobs you push to fremforge run on **T Cloud Public Elastic Cloud Server (ECS)**: each commit or pull request gets its own ephemeral virtual machine, provisioned fresh and destroyed once that commit's jobs finish. Two independent layers of isolation: - **Compute / kernel - a dedicated VM per commit.** Every commit's jobs run in an ECS virtual machine with its own Linux kernel, isolated by the hypervisor. **No two customers, and no two commits, ever share a kernel or a machine**, so kernel-side container-escape primitives (cgroup-escape, /proc bind-mount escape, eBPF, /sys exposure) have no cross-tenant boundary to cross: there is no shared kernel to escape into. The isolation unit is a whole VM, not a container - a stronger boundary than the shared-kernel container model that conventional Kubernetes (CCE included) uses for runner pods. The VM is reaped (deleted) once that commit's jobs complete, so nothing - build cache, cloned code, injected secrets - persists into another commit's jobs or into any other customer's. - **Within one commit, jobs may share the machine.** Successive jobs of the same workflow run (for example `build` then `deploy` over the same commit) may execute on the same VM, which is destroyed when they finish. That is deliberate: it is the same reviewed code in both jobs, and a fresh machine per job costs roughly 40 seconds of extra dispatch latency on every step of a pipeline. The consequence worth stating plainly is that a build step which executes third-party dependency code shares a machine with a later step of the same commit, so treat a pipeline as a single trust domain and scope any credential a deploy step needs to that pipeline. Cross-tenant and cross-commit isolation above is unaffected by this. - **Network - per-VM VPC Security Group.** Each runner VM sits behind its own VPC Security Group: no inbound access, VM-to-VM (intra-subnet) traffic denied, and egress restricted to the SSRF-guarded outbound runner-proxy, the Forgejo API, and DNS. Isolation is enforced at the VPC/hypervisor layer, not at an in-cluster `NetworkPolicy` layer that depends on a CNI agent behaving correctly. Combined with the forced outbound proxy and its SSRF deny-set, lateral movement from a runner VM to anything outside the customer's own job context is denied at both the VM and VPC layers. If T Cloud Public's isolation model for either layer changes in a direction that weakens the above (e.g. per-job VMs are replaced with shared-kernel containers, or the per-VM Security Group boundary is removed), this page is updated within 30 days of the change and any active Customer is notified per [DPA §14](/legal/dpa/#14-changes-to-this-dpa). ## Inherited certifications Through T Cloud Public: - ISO/IEC 27001 - information security management - ISO/IEC 27017 - cloud-specific security controls - ISO/IEC 27018 - protection of personal data in the cloud - BSI C5 Type 2 - German federal cloud-security baseline - TISAX - German automotive industry assurance - GDPR-compliant processing in EU data centres ## fremverk's own certification roadmap As of the Effective Date, fremverk does not hold standalone ISO 27001, SOC 2, or BSI C5 certifications. fremverk's security posture rests on (i) the inherited certifications of its sub-processors listed above, (ii) the technical and organisational measures in the DPA security annex, and (iii) fremverk's information security and security-testing programme described in the DPA security annex. fremverk has committed to: - Commencing **ISO 27001 Stage 1** audit within **18 months** of the Effective Date and achieving certification within **24 months**. - Commencing a **SOC 2 Type II readiness assessment** within **24 months**. Customers requiring direct certification before those milestones may contract under Enterprise-on-Demand with the certification-readiness milestones written into the Order Form. See DPA §12.1. ## Government access transparency As of the Effective Date, fremverk has received **zero** government-access requests for Customer Personal Data. The full report - including the partial-period statement covering pre-launch operations - is published at [`frem.sh/trust/transparency/`](/trust/transparency/). Subsequent reports cover full calendar years and publish in Q1 of the following year. Where fremverk receives a binding legal demand from a government authority, court, or law-enforcement agency, fremverk: - Reviews the request for legal validity, jurisdiction, and proportionality; - Challenges any request that is overbroad, lacks lawful basis, or conflicts with EU law (including GDPR Art. 48 for non-EU/EEA requests); - Notifies the affected Customer within 24 hours of receipt unless legally prohibited from doing so; - Provides the Customer with reasonable opportunity to seek a protective order or otherwise contest the request. See DPA §11A. ## DSA transparency report (Article 15) fremforge is a hosting service within the meaning of [Regulation (EU) 2022/2065](https://eur-lex.europa.eu/eli/reg/2022/2065/oj) (Digital Services Act). The annual Art. 15 report on notice-and-action volumes, member-state authority orders, own-initiative content moderation, and Art. 20 complaint outcomes is published at [`frem.sh/trust/dsa/`](/trust/dsa/) - separate from the government-access report above. The same URL carries the six-monthly average-monthly-EU-recipients figure required by Art. 24(2). ## Schrems II - international transfers **No international transfer of Customer Personal Data occurs on any processing path.** All processing (repository content, CI runs, audit logs, authentication metadata, billing records, payment-instrument data, outbound transactional email, and inbound shared-mailbox correspondence) takes place inside the EU/EEA at entities with no US parent. No Article 46 GDPR safeguard, SCC, or transfer impact assessment is required. ### Edge-PoP residency (Bunny CDN) Every Bunny pullzone in front of `frem.sh` is configured to serve from **EU PoPs only** - no US, AU, or Asia caching. This is enforced in OpenTofu on each pullzone resource via `routing { zones = ["EU"] }`. The pullzone configuration lives in the source tree at: - Forgejo pullzone: `fremforge/forgejo/.infrastructure/main.tf` - search `zones = ["EU"]` - API pullzone: `fremforge/monolith/.infrastructure/bunny.tf` - same line - Static-site pullzones (www, docs, status, cli) inherit the same `routing` block from the shared module at `fremverk/cloudplatform/modules/static-site/main.tf:103-112`. A `tofu plan` against any pullzone stack prints the active `routing.zones` value, so any drift away from `["EU"]` would surface as a plan diff. Auditable evidence will become directly browsable once the source tree is hosted on the customer-facing Forgejo instance (at `https://frem.sh/fremforge/...`); for now, the canonical audit-chain anchor and integrity-verifier documentation is published at [`docs.frem.sh/security/audit-chain/`](https://docs.frem.sh/security/audit-chain/). ## TLD note `frem.sh` is a Saint Helena (`.sh`) ccTLD administered by a UK-registered registry operator. This is a DNS-level fact only. No customer data, no control-plane state, and no backups leave T Cloud Public EU-DE. The sovereignty guarantees (processor identity, sub-processor list, data residency) are set out in the DPA and are unaffected by DNS hosting. **Zero CLOUD Act exposure on any processing path.** All Customer Personal Data is processed inside the EU/EEA by entities with no US parent. See DPA §11.3 for the full posture. > **Card-network footnote.** Mollie's PCI-DSS-attested card-processing chain involves Visa Europe Services Inc. (UK branch) and Mastercard Europe SA (Belgium) - EU operating entities whose ultimate parents (Visa Inc., Mastercard Inc.) are US-incorporated. The "no US-parented" claim applies to fremverk's own sub-processor stack at the operating-company level; the card networks are sub-sub-processors of Mollie under PCI-DSS network rules. Customers preferring zero US-parent exposure on the payment path may **pay by SEPA Direct Debit** (no card-network involvement). See [subprocessors - Card-network footnote](/trust/subprocessors/#card-network-footnote). ## Verify the audit chain yourself Every state-changing admin action on your org is recorded in a per-tenant SHA-256 hash chain, with the chain head WORM-anchored every two minutes to T Cloud Public OBS Object Lock storage (3-year retention, physically un-deletable within retention). You can walk the chain end-to-end without trusting fremverk's word for it. With the [fremforge CLI](https://docs.frem.sh/get-started/cli/): ```bash # Install (one-liner; see docs.frem.sh/get-started/cli/ for manual download + SHA-256 verify) curl -sSfL https://cli.frem.sh/cli/install.sh | sh export FREMFORGE_TOKEN='' fremforge audit-verify --human ``` Or with raw `curl` against the same endpoint the CLI calls: ```bash curl -sSf \ -H "Authorization: Bearer $FREMFORGE_TOKEN" \ https://frem.sh/_app/api/v1/orgs//audit/integrity \ | jq '{integrity_status, walked_rows, verified_count, last_verified_hash, worm_anchor}' ``` A healthy response reads `"integrity_status": "ok"` and includes a `worm_anchor` block whose `agrees_with_db_walk: true` confirms the in-database chain matches the OBS-anchored head. A break (`hash_mismatch` / `prev_hash_mismatch`) returns the offending row id and reason - designed to be auditor-readable. Full schema, exit codes, and the threat model in [docs.frem.sh - audit-chain integrity](https://docs.frem.sh/security/audit-chain/). ## Operator credential custody Bootstrap admin credentials (the domain-scoped T Cloud Public root AK/SK used only for first-time IAM, OBS bucket, and service-linked agency creation) are stored on the operator laptop with FileVault full-disk encryption and `chmod 600` file permissions, rotated quarterly, never transmitted via chat or screen-share, and revocable in under 10 minutes via the OTC console. Routine deploys use per-component scoped deployer keys, not the root credential. ## Security contact - Report vulnerabilities: [security@frem.sh](mailto:security@frem.sh) - Disclosure policy: [security](/security) - PGP key fingerprint: `DBA3 184D 0EFA E4C2 51ED EB46 53FA 57F8 698C 3488` ([public key](/.well-known/openpgp-key.asc) - RFC 4880 armored, RSA-4096, expires 2031-05-14). Use for encrypted vulnerability reports to `security@frem.sh`. The key is published only from `frem.sh/.well-known/`; we do not upload to public keyservers (avoids the third-party trust root). Mirror at [`/pgp.txt`](/pgp.txt) for convenience. ## Vulnerability disclosure A machine-readable disclosure policy is published at [`frem.sh/.well-known/security.txt`](https://frem.sh/.well-known/security.txt) per RFC 9116, including safe-harbour for good-faith research, scope, and reporting channel. Third-party penetration test reports, when commissioned, are made available to Customers under NDA on written request per DPA §12.1; Enterprise-on-Demand contracts may agree to a specific testing cadence in the Order Form. ## Incident disclosure Post-mortems for any incident affecting customer data or availability are published on this page within 14 days, per our [security policy](/security). ## Security patching fremforge commits to the following maximum time-to-patch for security vulnerabilities in the platform, measured from the upstream fixed release or advisory publication, whichever is later. | Severity (CVSS) | Maximum time to patch | |---|---| | Critical (≥ 9.0) | 48 hours | | High (7.0–8.9) | 72 hours | | Medium (4.0–6.9) | 7 days | | Low (< 4.0) | Next scheduled maintenance window | Out-of-band emergency releases are expected. The weekly maintenance window is a ceiling, not a floor. Security patches are never deferred to honour a tenant maintenance window; this is stated in the AUP and cited verbatim in the DPA security annex. ## Exit and data portability Everything is exportable - repositories, issues, pull requests, Actions logs, audit trail, SLSA attestations - via API as standard formats. There is no retention lock-in and no export fee. **Self-service tamper-evident export.** Any tenant admin can trigger a full bundle from the admin UI at any time. The bundle is delivered as a single zip with a **SHA-256 manifest** covering every file in the archive (`manifest.json` + `archive.tar.gz.sha256`) so the customer can confirm the contents haven't been tampered with after download. The bundle contains repo `git bundle` files, LFS manifests, Actions logs, audit slice, and SLSA attestations. GitHub and Azure DevOps do not offer an equivalent one-click self-service export; their portability paths require either Enterprise tier or support tickets. fremforge ships it on every plan, every customer, every day. *The manifest is signed with our SLSA builder key (DSSE envelope, `manifest.json.intoto.jsonl`); customers verify with the same trust root at `https://www.frem.sh/.well-known/slsa-trust-root.json` published for SLSA build attestations. No Sigstore dependency.* See `docs.frem.sh/data-export` for the bundle layout, verification recipes, and the API endpoints. Tenant offboarding timelines and procedures are spelled out in the DPA. ## Cookies and tracking fremforge sets only strictly-necessary cookies on authenticated product surfaces, and zero cookies on marketing, docs, status, and anonymous pages. No consent banner needed: not because we hid the question, but because we don't set cookies that would require consent. **Authenticated product surfaces** set four first-party cookies, all strictly-necessary under ePrivacy Directive Article 5(3): | Cookie | Purpose | Lifetime | |---|---|---| | `session` | Forgejo session state (authenticated login; cookie name on Forgejo 15+, previously `i_like_gitea`) | 7 days (persistent) | | `_csrf` | CSRF protection | Session | | `lang` | Language preference, user-triggered | Effectively permanent | | `fremforge_operator_session` (operator console) | Operator-console session | 30-min idle, 12h absolute cap | **Marketing, docs, and status** (`www.frem.sh`, `docs.frem.sh`, `status.frem.sh`) are Hugo-built static sites with no cookies, no analytics, no embeds, and no tracking of any kind. Verifiable in your browser's developer tools. **Third-party calls from the product UI are disabled by default**: no Gravatar, no federated avatars, no CDN-loaded fonts or scripts, no third-party analytics. Avatars are stored locally; fonts are served from the same origin as the forge. This is a deliberate product posture, not a compliance minimum. Full cookie inventory and data-subject rights are documented in the product [privacy policy](/privacy). ## Changes to this page Changes are versioned in Git and announced on the security mailing list. The date at the top of this page reflects the last meaningful content change. ## Change log | Version | Date | Change | |---|---|---| | 1.0 | 2026-04-25 | Initial publication. | | 1.1 | 2026-04-27 | Heinlein Hosting GmbH (mailbox.org, Berlin DE) added as Annex B sub-processor for inbound shared-mailbox correspondence (M365 → mailbox.org migration; removes the last US-jurisdiction processor from the Customer Personal Data path). | | 1.2 | 2026-05-06 | Visma Dinero ApS (Copenhagen DK) added as Annex B sub-processor for the fremverk-side bookkeeping integration (replaces the prior in-house ledger code path for invoicing/VAT/Bogføringsloven). | | 1.3 | 2026-05-08 | DPA §10.2 dual-channel sub-processor change-notification clarified; Bunny Shield posture documented inline (Shield Basic on Forgejo + api pullzones, Shield Advanced on static-site pullzones); CCI Kata + Yangtse v2 hosted-runner isolation paragraph added with explicit CCI v2 OBT-entitlement carve-out. | | 1.4 | 2026-05-14 | Brevo (FR) fully decommissioned as the outbound transactional-email sub-processor; Lettermint B.V. (Zwolle, NL - upstream OVHcloud SAS, FR + UpCloud Ltd, FI-incorporated, Amsterdam NL DC) is now the canonical Annex B row. Trust-page footer + AI-policy table updated. | | 1.5 | 2026-05-19 | Visma Dinero data-categories table corrected to enumerate the fields actually flowing through the bookkeeping integration (org legal name, billing-contact email, VAT, invoice line items, Mollie payment-id; no repo content, no audit-log content, no PAN); shared-mailbox enumeration expanded to all 8 canonical addresses; AUP §3.6+§4 concurrency limit aligned to "2 jobs/seat, max 100/org" (v1.1); DPA §8.5 24/7 monitoring qualified with cross-ref to SLA §9+§10 and EDPB Guidelines 9/2022 awareness-clock framing. | | 1.6 | 2026-07-01 | Hosted-runner isolation section rewritten to reflect the migration to **single-use T Cloud Public ECS VMs - one ephemeral VM per job, hypervisor-isolated, reaped after the job** (completed 2026-06-24). Replaces the prior "CCI Kata + Yangtse v2" description and removes the CCI-v2 OBT-entitlement waitlist carve-out (no longer applicable). This is a **stronger** isolation boundary (whole-VM vs shared-kernel container), same sub-processor (T Cloud Public, `eu-de`); mirrors DPA v1.16 Annex A.5. | | 1.7 | 2026-08-04 | **Hosted-runner isolation corrected: the VM boundary is per COMMIT, not per job.** This section had said "each job gets its own single-use virtual machine", "no two jobs ... ever share a kernel or a machine", and that nothing "persists into any subsequent job". Successive jobs of one workflow run over the same commit may in fact share the machine, which is destroyed when they finish — a deliberate trade (a fresh VM per job costs roughly 40s of extra dispatch latency on every pipeline step). **Cross-tenant and cross-commit isolation are unchanged**, and remain the properties this page commits to: no two customers and no two commits ever share a kernel or a machine. The intra-commit consequence is now stated explicitly rather than implied away — treat a pipeline as one trust domain. Treated as a **clarification** rather than a weakening notice: the §14 undertaking in this section is conditioned on *T Cloud Public's* isolation model changing ("e.g. per-job VMs are replaced with shared-kernel containers"), which has not happened — the VM boundary and the per-VM Security Group are exactly as described. Found 2026-08-04 during a deliberate sweep of the published documents against the running system; the same sweep corrected DPA Annex A.5, which had still described Cloud Container Instance pods and which the 1.6 row above wrongly claimed to mirror. | | 1.8 | 2026-08-05 | Two corrections on this page, both found by auditing it against the systems it describes. **(a) The `session` cookie lifetime read "Session".** It is a persistent **7 days** (`SESSION_LIFE_TIME = 604800`, aligned to the 7-day "Remember Me" window), set deliberately so single-sign-on arrivals survive a browser restart. Corrected in lockstep with cookie-policy 1.3 and privacy notice 1.14, which carry the full account — this page was the THIRD surface publishing the same wrong figure, and the gate that caught the other two had to be widened to see it. No consent implication: an authentication cookie is strictly necessary under ePrivacy Art. 5(3) whether session-scoped or persistent. **(b) The Bunny sub-processor row listed "WAF" as a role** while the Edge WAF section further down this same page states the Shield WAF is not enabled on the Forgejo and api pullzones. The row now describes what Bunny actually does for fremforge — edge delivery, TLS termination, DDoS mitigation and rate limiting — and points at that section. Nothing about Bunny's processing scope, location or certifications changes; the row described a capability rather than a deployed control. | | 1.9 | 2026-08-05 | Cookie table: the `lang` cookie read "1 year" and it is effectively permanent (`Max-Age=2147483647`, mirroring Forgejo's `LangCookieMaxAge` default). Corrected in lockstep with cookie-policy 1.4 and privacy notice 1.15. This is the second lifetime in this table corrected today — the `session` row was wrong in 1.8 — and both were caught only by reading the table against the code that sets the cookies. The strictly-necessary classification is unchanged: ePrivacy Recital 25 exempts user-action preference cookies regardless of duration, so no consent is required either way; what was wrong is the figure a reader checks. Both are now derived from code by the `cookie-lifetimes-match-the-code` claim, which also covers this page. | | 1.10 | 2026-08-05 | Cookie table: the fourth row read "fremforge middleware session | Per-org session binding | 8h rolling". It is `fremforge_operator_session`, the operator-console session, with a 30-minute idle timeout and a 12-hour absolute cap — the 8-hour fixed TTL was removed by audit P1-3. Stronger than published. Corrected in lockstep with cookie-policy 1.5 and privacy notice 1.16. That completes all four rows of this table, every one corrected today after being checked against the code. |