ForgeHelm › Product

Seven modules. One platform.

From compliance checks that run automatically every day to safely modernizing legacy systems, it all happens in one place — and source code stays inside your network throughout.

What the CISO, the CTO, and the dev team each see

👔

CTO / CIO

Compliance status across every project at a glance: risk heat maps, trends, and what to tackle first

🔐

CISO

Framework coverage matrix, audit log export, supply chain inventory (SBOM)

⚙️

IT / DevSecOps Teams

Hook into your scanning pipeline, automated code transformation (codemod), database health analysis

Seven Modules, One Platform

From compliance reports to legacy modernization, everything happens in one place — and source code stays in your network.

01
📋

Compliance Reports

Takes the results of mapping your code against 31 frameworks and turns them into reports an auditor can read: which controls have code-level evidence, which don't, and where to start. Exports to PDF, Excel, CSV, or Word, in six languages.

  • PDF, Excel, CSV, Word export
  • Reports in six languages
  • Three risk assessment methods: ISO 31000, NIST RMF, ISO 27005
  • Framework coverage matrix; every finding points to a file and line number
02
📦

SBOM

Which packages each project uses, under what licenses, with which known vulnerabilities — all in one list. Exports in both CycloneDX and SPDX, so you can hand auditors and customers whichever format they ask for.

  • CycloneDX and SPDX formats
  • Dependencies mapped to known vulnerabilities
  • License tracking
  • Supply chain risk at a glance
03
📊

Governance Dashboard

Click from the whole organization down to the one subsystem with the problem. Compliance coverage, trend charts, and risk heat maps — you won't get lost even with a hundred subsystems.

  • Drill down: organization → main system → subsystem
  • Compliance coverage trends
  • Risk heat maps
  • Side-by-side project comparison
04
🎯

Risk Questionnaire

A maturity questionnaire across five dimensions: system handover, requirements traceability, change prediction, acceptance criteria and communication cost. The scores come from what your team answers, not from scanning code — it covers the side a scan cannot see. Shown as a radar chart with improvement suggestions and a downloadable PDF report.

  • Five dimensions (M1 system handover through M5 communication cost), scored from your answers
  • Radar chart view
  • Improvement recommendations (AI- or rule-generated)
  • Downloadable PDF report
05
🤖

AI Assistant

Answers questions from your own governance data: what this finding means, how much it matters, and what to fix first. Replies stream in as they're written, and it can run fully offline.

  • Answers grounded in your governance data
  • Streaming, real-time replies
  • Fully offline with your own model
  • Works with external models or your own local model
06
🔄

Tech Stack Migration

Convert code from an old framework to a current one automatically (for example .NET Framework to .NET 9), compare compliance state before and after, and keep every phase's output downloadable in the document centre. Automated conversion is currently .NET-focused; other languages get the assessment and the before-and-after comparison.

  • Automated code conversion (codemods, currently .NET-focused)
  • Before/after compliance comparison
  • Each stage's output kept in the Document Center
  • Assessment report for legacy modernization
07
🗄️

Data Quality

Finds unused database objects, duplicate tables, inconsistent naming, and whatever is slowing performance — a starting point for paying down technical debt.

  • Database object health scoring
  • Redundancy and duplication detection
  • Naming consistency check
  • Performance bottleneck identification
One axis measured, four estimated, three from your survey

Eight-Axis Risk Fingerprint

Eight dimensions on one radar chart — and you can see at a glance which axes are measured and which aren't.

Security posture is measured by the analysis engine (Agent). Documentation coverage, test coverage, dependency risk and technical debt are currently system defaults — marked (est.) on the chart, and never treated as risk findings. Onboarding, change impact and shared understanding come from the risk questionnaire you fill in. As analyzer coverage grows, an axis switches from estimate to measured automatically. This chart is the executive overview; the conclusions for the 31 frameworks do not come from it — they are produced by each framework's analyzer comparing the code rule by rule, with every finding pointing at a file and line.

  • Security posture (measured)
  • Documentation completeness (est.)
  • Test coverage (est.)
  • Dependency risk (est.)
  • Technical debt (est.)
  • Onboarding (survey)
  • Change impact (survey)
  • Consensus gap (survey)

Work out the cost up front, and still see the usage

Price is seats times the monthly rate — it has nothing to do with how many analyses you run or how many reports you generate. Put your headcount into the formula and you have your budget, with no surprise line item at month end.

Your plan

Which plan you are on, what it includes, and when it expires.

Usage over the last 30 days

Analyses run and AI questions asked. Administrators can see it, so you know when you are getting close to your plan limit.

Hitting the limit pauses, it does not bill

At the limit the platform stops and tells you the date it resets — there is no extra charge. AI questions that never got an answer do not count against the quota.

Audit record

Who did what, and when. Queryable via API or downloadable as CSV for finance or compliance review — on all three plans.

Enterprise

Bring Your Own Model (BYOL) for the AI Assistant — Enterprise

The AI assistant can run on your own GPU servers, connected to Ollama, vLLM, or any model server that speaks the OpenAI API. Source code and questions both stay inside your network.

See the Deployment Architecture →

What it reads, and what it produces

The three questions we get asked most, answered here.

Languages and sources supported

C#, VB.NET and ASP.NET WebForms get deep analysis down to the syntax tree, plus the compliance and security rules. A further 62 technology families (Java, PHP, Python, COBOL, PowerBuilder, Delphi, VB6 and more) get syntactic parsing and call-relationship inventory, but not those rules. The source can be a Git URL or a ZIP upload.

See the full list →

20 architecture diagrams, nine roles

Class diagrams, call graphs, dependency graphs, data-flow diagrams, sequence diagrams, deployment diagrams and more — 20 types generated straight from the code. Filter by role; this is where to start on a system you don't know.

How to use it on a legacy system →

Use your own report layout

Upload your organisation's own Word template (with bookmarks or content controls), map the controls to report fields, and exports use your layout instead of the built-in one. Uploading and mapping is limited to the administrator, compliance officer and executive roles.

Fields mapped to the self-assessment questionnaire stay empty until the questionnaire is completed.

Who is quietly calling an AI service

The CTO thinks there are two or three places using AI; a scan usually finds more. Every analysis also looks for unregistered AI calls in code and configuration, and for AI keys written into files.

AI SDK usage

Code that imports the OpenAI, Anthropic or Gemini SDKs, or frameworks such as LangChain. Packages from mainland Chinese vendors are listed separately, so they are easy to check against procurement rules. AI code that has been commented out gets its own low-priority note: it is not running, but someone tried it.

Hard-coded API keys

Key formats from about twenty AI services, including OpenAI, Anthropic, Google and Hugging Face. Anyone who can open the file has the key. Keys in the results keep only their prefix and last four characters, so the report itself does not become a second leak.

Unmanaged outbound calls

URLs pointing at OpenAI, Anthropic, Google, Azure OpenAI, AWS Bedrock and similar services, as well as self-hosted inference servers such as Ollama. If traffic can leave, so can data; a self-hosted model keeps data at home, but it is still AI nobody is managing.

The scope of this check, stated plainly

Every programming language the product supports is in scope, from C#, Java, Python, JavaScript and Go to COBOL and Delphi, plus configuration files, dependency manifests and Jupyter notebooks; documentation is checked only for leaked keys. It works by rule matching, not deep static analysis, so expect false positives: a hit is a list of things to go and look at, not a verdict. It cannot see keys already deleted from Git history, keys that exist only in CI or server environment variables, or AI services staff use directly in the browser.

This check is not one of the 31 compliance frameworks and does not appear in the compliance report; it runs separately, and the seven AI governance frameworks take its list as their input. The file and line for each hit can only be exported on the analysis engine's side (off by default) and are never sent to the management platform.

Security Design

🔏

Data Masking

Only file names, line numbers, and summary counts leave the Agent; code fragments and paths are masked or replaced with placeholders before they go out.

🛡️

Role-Based Access Control

Layered by role — view, configure, export, admin — each with its own boundary, enforcing least privilege. Sign-in is username and password with session controls; SSO/SAML is on the roadmap.

🏢

Multi-Tenant Isolation

Full logical isolation between tenants. Every customer runs the same codebase — no per-customer forks — so security patches land for everyone at once.

📜

Hash-Chained Audit Log

Every sign-in, policy change, report generation, and data export is recorded: who, when, what, and the result. Entries are hash-chained, so any altered record is detectable, and the log is queryable via API.

Try it in your own environment