FORGEBY Name your market

Trust and security

Read at the source. Sent by a human.

Every company in the library comes from an official public business register, read at the source. No social network is scraped and nothing is LinkedIn-derived. No person appears on a public page. Rune drafts, and a person sends.

EU-resident by design Public registers at the source No social scraping Never LinkedIn-derived Suppression registers honoured Person data behind sign-in A human sends

Last reviewed 1 August 2026

01 · Where the companies come from

Official public business registers, read at the source.

Every company in the library comes from the public business register of its own market, read by us under that register's own terms, rather than bought as somebody else's copy.

Category oneOfficial public business registersThe public register in each market we work. What we take is company fact: the legal entity, its registration number, its sector, its size band and its registered address.
Category twoWhat a company publishes itselfThe cloud posture is measured from the outside, from what a company already publishes to the open internet. Nothing from behind a login, nothing from a person's profile.
Category threeWhat you bringYour own records, inside your own workspace. We do not train on them and we do not resell them, and you can export or erase them whenever you want.

Full provenance is available on request. Every attribute we hold traces to one of those three categories and to the named source behind it. A DPO who has to verify that should not have to take a web page's word for it, so we give the register-level detail in writing, under the data processing agreement, rather than publishing our sourcing map for everyone. Ask at privacy@forj.se and you get it.

Public business registers · read at the source · under each register's own terms · aggregate bands only on public pages · provenance per attribute on request

02 · The hard rules

Four things we do not do.

We do not scrape social networks. Nothing in the library is LinkedIn-derived. We will not buy a list from anyone who cannot name where it actually came from, because buying a scrape does not launder it.
We do not show people in public. Public pages carry counts and bands. Never a name, never an email, never a phone number, never a title. A public read shows a role, never a named individual.
We do not send anything automatically. Rune drafts. A person reads it, decides, and sends it from their own inbox in their own name. There is no mass send and no autopilot.
We do not file anything into AWS by ourselves. Rune prepares the paperwork. A human at the partner reviews it and submits it in AWS Partner Central. Nothing reaches AWS without that person.

03 · The lawful channel

The market decides the channel.

Marketing law is not the same in every country we work. We respect the lawful contact channel in every market, and the product applies it for you, rather than running one campaign shape everywhere and hoping.

Suppression

Suppression is honoured before a draft exists.

Where a market publishes an objection or advertising-protection register, it is applied at the source, not at the end. A company or a person on one of those registers is screened out before anything is written, not filtered out after.

Applied, not taught

The rule reaches the person, not the policy shelf.

Every record carries the lawful way in for its market before anything is drafted, so the person about to make contact does not have to look it up or decide it under time pressure. We apply the rule in the product. We do not publish the rule set.

Legitimate interest

Documented, and balanced.

Business contact data of a person in a professional role is processed on documented legitimate interest, balanced and written down, for business to business contact only. We process what the role needs and nothing beyond it.

Objection

Where the data came from, and how to say no.

Where business contact details were obtained from somewhere other than the person, the source categories and the route to object are set out in the privacy policy, with the article-level basis. An objection stops the processing.

04 · The sign-in line

Person data lives behind sign-in. Always.

There is one line on this product and it does not move. Before sign-in you get counts. After sign-in, inside a partner's own isolated workspace, you get the work.

Public, no account
  • How many companies are in a market
  • How the cloud posture splits, as bands
  • How many decision roles sit on a company, as a count
  • Which funded door an account shape tends to open
Behind sign-in, inside your workspace
  • The account-level read
  • Named roles and business contact details
  • Drafts, approvals and the send from your own inbox
  • Your own records, isolated from every other partner's

Workspaces are separated by row-level security in the database itself, not by application code that could be talked around. An unauthenticated caller holds no database privileges at all: the public surface reaches a small number of read-only aggregate endpoints and nothing else. No partner can see another partner's records.

05 · Rune

Rune drafts. A human sends.

Rune is openly an AI and says so on every surface he appears on. He is fast and he is useful, and he is never the last decision.

A person approves every sendRune writes. He does not contact anyone on his own, in any channel, ever.
Every run is loggedWhat he read, what he wrote and what he did is visible to the partner it was done for.
Every workspace has a spend capEnforced in code, not in a policy document.
His output is checked against its sourceWhat he cannot stand behind is flagged rather than asserted.

06 · Where it lives

EU-resident by design.

Your workspace, your records and the library sit at rest in the EU, in Stockholm. Reasoning runs in the EU by default, on Amazon Bedrock in the same region. Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256. Secrets stay server-side and are never handed to a browser.

One honest caveat, because it is true and you would find it anyway: a small set of tasks that need live web search run outside the EU under Standard Contractual Clauses, because that capability is not available in the EU region we use. No customer records are stored there. Every processor we use is named and versioned in the data processing agreement and sub-processor list, and that list is the authoritative one.

Meeting capture and transcription, when a partner chooses to use it, run with EU providers on EU soil, and both the platform and the meeting layer refuse to start without consent recorded.

07 · Objection and erasure

The route, in plain words.

If you want out, one email does it.

Write to the address below and say what you want: access to what we hold, a correction, an objection to the processing, or erasure. We answer within one month, as the law requires, and sooner in practice.

An erasure is a suppression as well as a delete. The record is removed and the identifier is held on a suppression list so the next load of the register does not quietly bring it back. That is the only reason anything survives an erasure, and it exists to keep the erasure honest.

For a security issue, write to the second address and give us reasonable time to fix it before any public disclosure. We will tell you what we found and when it was closed.

08 · What we do not claim

We are GDPR-aligned. We are not ISO certified.

Forj is a Swedish company and builds to GDPR: documented lawful basis, data-subject rights honoured, a versioned sub-processor list, a data processing agreement offered to every customer, and as little collected and kept as the work allows.

ISO 27001 is on the roadmap and we are not certified today. We do not claim certifications we have not earned, and this page will change on the day that changes rather than before it.

The fastest way to judge any of this is to look at what is actually in your market. Ten seconds, no typing, no account, no person data.

Name your market

This page describes our posture in good faith and is written for information. It is not a contract. The binding terms are in your agreement and in the data processing agreement.