SSO with SAML & OIDC
Bring your identity provider; sign-in stays where your directory is.
SSO, SCIM, path-level access control, audit, and key ownership — the controls a regulated org needs, on git storage you already own.
Connect SAML or OIDC, provision through SCIM, and deprovision the moment someone leaves.
Bring your identity provider; sign-in stays where your directory is.
Users and groups sync from your IdP — joiners, movers, and leavers included.
Phishing-resistant sign-in and one-time codes for every account.
Most forges stop at the repository boundary. GitForge scopes roles and visibility to refs and paths, so one shared repo can serve teams with different clearances.
Sensitive actions recorded with actor, target, and timestamp.
Restrict tenant access to the networks you approve.
Personal access tokens are stored as SHA-256 hashes, never plaintext.
Data ownership here is architectural, not a contract clause: objects live in your storage, snapshots wrap under your KMS key, and revoking that key is a real off switch.
Git objects live in the bucket you connect — residency follows your provider and region choice.
Wrap tenant snapshots under your own KMS key, with on-demand rotation.
Revoke your key and the wrapped data becomes unreadable — leaving is enforceable, not contractual.
History already sits in your account; no export request, no migration project.
Multi-tenant with the workspace as an enforced security boundary, stateless servers, an audit trail on sensitive actions, and residency that follows your bucket choice. Ask us the hard questions — the architecture is the answer.
We'll map your identity, access, and residency needs onto GitForge — no deck, just answers.