Solutions

You’re not buying a dashboard. You’re hiring a team.

ForgeWatch is a monitoring platform wrapped in an engagement. We stand up the scan, read the findings ourselves, chase down what looks wrong, and sit beside you when someone starts asking what your AI tools can see.

How we work

Software finds it. Someone still has to explain it.

Tooling that hands you a list of findings has moved the work, not done it. Every ForgeWatch engagement puts a person between the scan and your inbox.

01

Assessment

We read your environment. We don't just scan it.

Every engagement opens with a complete read-only inventory — every app, every scope, every account, and the date each grant was first authorized. Then a person goes through it line by line and writes up what actually matters for a business like yours.

02

Active investigation

When something looks wrong, we chase it.

A grant that shouldn't be there raises questions a dashboard can't answer: who approved it, when, what it can reach today, and whether anything else in your tenant looks the same. We run that down and come back with a finding — not an alert for you to triage.

03

High-touch relationship

You get a person, not a portal.

Direct access to the people doing the work. Governance briefings written for your board, a standing policy review, and prep sessions before an examiner, an auditor, or an insurer starts asking questions.

The engagement

What a year with us looks like.

  1. Week one

    Authorization and baseline

    One read-only admin authorization — no agents, nothing on anyone's laptop. Your first inventory lands within days, including apps authorized years ago and grants still held by people who have already left.

  2. Every month

    Exposure report

    What changed since last month: new grants, widened permissions, revoked access, and anything newly classified as AI. Written to be forwarded to your board, not decoded by your IT person.

  3. When something changes

    Watch

    We reach out

    Drift doesn't wait for the report. A new grant reaching sensitive data gets investigated when we see it, and you hear from us with the context already gathered.

  4. Every quarter

    Advisory

    Governance briefing

    A board-ready read on your AI exposure, how your policy is holding up against what people are actually connecting, and what we'd change before the next review.

  5. Before an exam

    Advisory

    We prepare with you

    Walk in with timestamped evidence mapped to your framework — and someone who can answer the questions behind it, in the room or on the call.

Deliverables

Everything we do ends in something you can hand to someone.

A regulator, an insurer, a board, or the employee who connected the app. Nothing stops at a screen only you will look at.

Exposure Assessment

The day-one picture: every app, account and scope, each finding graded and explained in language an owner can act on.

Monthly Exposure Report

What moved and why it matters, timestamped and mapped to the frameworks you answer to.

Disposition packet

For every finding that needs action: the exact steps to authorize or remove it, a plain-English explanation for the admin, a non-accusatory note for the employee, and a sanctioned alternative where one exists.

Analyst concerns memo

The things a scan cannot see. Where we believe exposure sits outside your governed accounts — personal logins, tools bought on a card — we put it in writing rather than let a clean report imply it isn't there.

Where we work

Regulated businesses, mostly small ones.

The obligation is different in each. What we go looking for changes with it.

Healthcare & clinics

HIPAA

AI scribes, transcription and note-taking tools holding mailbox or drive access — the shortest path from a convenience app to PHI. We check what each one can actually reach, and whether your agreements cover it.

Accounting & CPA firms

SOC 2

Tax and bookkeeping assistants sitting on client financial records, plus seasonal staff whose access outlives the season. We look hard at grants that survived the last busy season.

Legal & law firms

ISO 27001

Drafting and summarizing tools connected to matter files or firm email, where a confidentiality obligation runs straight into a vendor's training terms. We map what each tool can read.

Title, real estate & finance

PCI-DSS

Non-public information and wire instructions moving through email and document tools. We flag anything with mailbox access — especially apps authorized by someone who has since moved on.

Every engagement maps to HIPAA, SOC 2, PCI-DSS and ISO 27001 — the tag above is only where the pressure usually starts.

For MSPs & partners

Run the whole engagement for the clients you serve.

Manage every client tenant from one console with strict per-client isolation, and resell the entire engagement — assessments, reports, disposition packets and briefings — under your own brand. We stay behind the curtain, or join the client call as your specialist. Your call.

  • Cross-tenant operator console
  • Deny-by-default isolation between clients
  • White-labeled reports and packets
  • Priced per client tenant, on volume
Talk to us

Start with an assessment.

One read-only authorization, a complete picture of what AI can reach inside your business, and a person to walk you through every line of it.