Skip to main content
Secure · Intelligence

Fleet-wide detections, k-anonymized.

Every org makes FORG smarter. Threat signatures aggregate behind a strict privacy floor (k≥25 orgs) so the whole network benefits — and nothing traces back to you.

forg intel --feed
$ forg intel --feed
signatures  1,284  network-sourced
k-floor     ≥25 orgs per signal
applied     on-device  no raw share
new / wk    +38  poisoning patterns
last sync   07:00 UTC  daily
On-deviceenforcement, no proxy
Metadata-onlycapture, no payloads
6control surfaces
Ed25519signed releases
14tools supported
8.5MBon-device agent
network effect, privately

Shared signal, zero exposure

k-anon gate (k≥25)

Signals only leave the privacy gate when at least 25 independent orgs share the same pattern. Never one org in clear.

Shared rule pool

New detections sync to your agent the moment the k-floor is satisfied — always current, never stale.

Daily aggregation

Patterns aggregate overnight so each morning your agent wakes up with the latest network-sourced signatures.

Privacy by design

No prompts. No code. Just patterns.

Intelligence sharing is metadata-only. Your prompts, your code, and your completions never leave the machine. Only the shape of a detection — timing, tool type, rule outcome — contributes to the pool.

The k≥25 floor means a pattern must appear across at least 25 independent organisations before it ships back to the network. One breach cannot become a signal.

Read the privacy model →

Network detections · total

illustrative · k≥25 when live
1,284active signatures · rolling out
Tool-poisoning847
Exfiltration312
SSRF patterns125

Borrow the network's hindsight

Join the privacy-preserving intelligence pool.

Start 14-day trial