Security Protocol

How we protect your studio's most valuable intellectual property at every layer of the ForgeNet stack.

Zero-Trust Architecture

AssetForge operates on a Zero-Trust basis. We assume the network is compromised. Every file is fragmented and encrypted with AES-256-GCM locally on your workstation using keys that never leave your control.

No Partial Decryption

Unlike S3 or Dropbox, ForgeNet nodes cannot "see" your filenames, directory structures, or file content. To the cloud, your data is merely a stream of randomized, cryptographically secured binary fragments.

Data Residency

By default, data is distributed across global edge nodes for speed. However, studios can specify **Data Residency Zones** to ensure metadata and fragments stay within specific legal jurisdictions (e.g., EU-only for GDPR compliance).

MFA & Hardware ID

Pairing a new device requires Multi-Factor Authentication (MFA) and is bound to the workstation's unique Hardware ID (HWID). This prevents session hijacking or unauthorized node cloning even if a Pairing Code is leaked.