Solutions
You’re not buying a dashboard. You’re hiring a team.
ForgeWatch is a monitoring platform wrapped in an engagement. We stand up the scan, read the findings ourselves, chase down what looks wrong, and sit beside you when someone starts asking what your AI tools can see.
How we work
Software finds it. Someone still has to explain it.
Tooling that hands you a list of findings has moved the work, not done it. Every ForgeWatch engagement puts a person between the scan and your inbox.
Assessment
We read your environment. We don't just scan it.
Every engagement opens with a complete read-only inventory — every app, every scope, every account, and the date each grant was first authorized. Then a person goes through it line by line and writes up what actually matters for a business like yours.
Active investigation
When something looks wrong, we chase it.
A grant that shouldn't be there raises questions a dashboard can't answer: who approved it, when, what it can reach today, and whether anything else in your tenant looks the same. We run that down and come back with a finding — not an alert for you to triage.
High-touch relationship
You get a person, not a portal.
Direct access to the people doing the work. Governance briefings written for your board, a standing policy review, and prep sessions before an examiner, an auditor, or an insurer starts asking questions.
The engagement
What a year with us looks like.
Week one
Authorization and baseline
One read-only admin authorization — no agents, nothing on anyone's laptop. Your first inventory lands within days, including apps authorized years ago and grants still held by people who have already left.
Every month
Exposure report
What changed since last month: new grants, widened permissions, revoked access, and anything newly classified as AI. Written to be forwarded to your board, not decoded by your IT person.
When something changes
WatchWe reach out
Drift doesn't wait for the report. A new grant reaching sensitive data gets investigated when we see it, and you hear from us with the context already gathered.
Every quarter
AdvisoryGovernance briefing
A board-ready read on your AI exposure, how your policy is holding up against what people are actually connecting, and what we'd change before the next review.
Before an exam
AdvisoryWe prepare with you
Walk in with timestamped evidence mapped to your framework — and someone who can answer the questions behind it, in the room or on the call.
Deliverables
Everything we do ends in something you can hand to someone.
A regulator, an insurer, a board, or the employee who connected the app. Nothing stops at a screen only you will look at.
Exposure Assessment
The day-one picture: every app, account and scope, each finding graded and explained in language an owner can act on.
Monthly Exposure Report
What moved and why it matters, timestamped and mapped to the frameworks you answer to.
Disposition packet
For every finding that needs action: the exact steps to authorize or remove it, a plain-English explanation for the admin, a non-accusatory note for the employee, and a sanctioned alternative where one exists.
Analyst concerns memo
The things a scan cannot see. Where we believe exposure sits outside your governed accounts — personal logins, tools bought on a card — we put it in writing rather than let a clean report imply it isn't there.
Where we work
Regulated businesses, mostly small ones.
The obligation is different in each. What we go looking for changes with it.
Healthcare & clinics
HIPAAAI scribes, transcription and note-taking tools holding mailbox or drive access — the shortest path from a convenience app to PHI. We check what each one can actually reach, and whether your agreements cover it.
Accounting & CPA firms
SOC 2Tax and bookkeeping assistants sitting on client financial records, plus seasonal staff whose access outlives the season. We look hard at grants that survived the last busy season.
Legal & law firms
ISO 27001Drafting and summarizing tools connected to matter files or firm email, where a confidentiality obligation runs straight into a vendor's training terms. We map what each tool can read.
Title, real estate & finance
PCI-DSSNon-public information and wire instructions moving through email and document tools. We flag anything with mailbox access — especially apps authorized by someone who has since moved on.
Every engagement maps to HIPAA, SOC 2, PCI-DSS and ISO 27001 — the tag above is only where the pressure usually starts.
For MSPs & partners
Run the whole engagement for the clients you serve.
Manage every client tenant from one console with strict per-client isolation, and resell the entire engagement — assessments, reports, disposition packets and briefings — under your own brand. We stay behind the curtain, or join the client call as your specialist. Your call.
- Cross-tenant operator console
- Deny-by-default isolation between clients
- White-labeled reports and packets
- Priced per client tenant, on volume
Start with an assessment.
One read-only authorization, a complete picture of what AI can reach inside your business, and a person to walk you through every line of it.