Forge is AGPL licensed.
That means the source is auditable. You can read what it does. Your security team can read what it does.
Anyone offering Forge as a hosted service must open-source their modifications, or buy a commercial licence. The code cannot be taken and made proprietary.
Self-hosters are protected. The commons are protected.





