Your BOM is either compliant or it isn't.
Prove it.
Upload a bill of material. Forge screens every component against NDAA §889, the OFAC SDN list, ITAR, EAR, and any regime you configure, and produces a signed, source-traced evidence chain you can put in a compliance file and defend under audit.
A single sanctioned component in your supply chain is a criminal violation, a contract termination, and a debarment proceeding
A relabeled chip from a prohibited subsidiary enters your supply chain through a third-tier distributor. Your compliance team doesn't catch it because they're checking manufacturers by hand against spreadsheets that were current last quarter. The contracting officer finds it during a DCMA audit.
ITAR violations carry criminal penalties up to $1M per violation and 20 years imprisonment. False Claims Act exposure attaches to every certification you signed. Debarment removes your company from government contracting entirely. Individual criminal liability follows the compliance officer who signed off on the BOM.
Forge catches it before the purchase order goes out.
Automated compliance verification with evidence you can defend under audit
Every verdict traces from the component on your BOM to the statute that governs it
Each step is recorded as a node you can expand, read, and cite in an audit. A subsidiary whose parent is sanctioned is exactly the case manual review misses.
An interactive compliance check you work in, and a signed compliance report you file.
The check surfaces every determination grouped by component. Non-compliant parts show the decisive fact immediately: which regime, which rule, which entity in the ownership chain triggered it. Clean components document what was searched and what was not found. Every entity name, every regime, every rule, and every statutory citation in the evidence chain is a live link to its source. Expand, drill down, navigate, and record dispositions without leaving the results page.
The report is the document you defend under audit. The verdict summary table shows every component with a per-regime verdict on one page. The executive risk narrative names every non-compliant component, cites the specific statute, and states the regulatory consequence. The scope disclosure documents exactly which regimes were evaluated and which were not, so a compliant determination is never mistaken for an absolute clearance.
One platform for every regime or contractual requirement your program touches
Forty regimes ship with the engine, spanning sixteen jurisdictions and five multilateral development banks — the United States, the European Union, the United Kingdom, the United Nations, the full Five Eyes, wider Europe from Bern to Ankara, and the Indo-Pacific from Tokyo to New Delhi. Screening runs against live designation feeds, and every determination cites verbatim text from the canonical government publication. For anything not on that list, hand Forge the regulation's own PDF or a spreadsheet of designated parties: it extracts the rules, proposes the entity list for your review, and screens against the result with identical rigor.
United States
NDAA §889 and §5949. OFAC SDN. US Consolidated Screening List. BIS EAR Entity List and EAR country controls. ITAR / USML. DFARS counterfeit avoidance. DoD §1260H Chinese military companies. DoD Blue UAS approved list. UFLPA Entity List. FCC Covered List. CBP forced-labor orders. BIS military-intelligence end-user list. CAATSA §231 specified persons. Entity resolution traces corporate ownership, so a permitted subsidiary of a proscribed parent is caught.
European Union
Dual-Use Regulation (EU) 2021/821, screened against Annex I categories. Consolidated Financial Sanctions List, including designated individuals as well as entities. The Russia military end-user list — all 921 entities of Annex IV, Regulation 833/2014. Common Military List, ML1 through ML22.
United Kingdom & United Nations
UK Sanctions List, published live by the FCDO — the single source for every UK designation, trade-sanctions targets as well as asset freezes. UK Strategic Export Control Lists. UN Security Council Consolidated List. All carry the full designated-person rosters, not entity names alone.
Five Eyes — Australia, Canada, New Zealand
Australia's DFAT Consolidated List and Defence and Strategic Goods List. Canada's Export Control List and SEMA autonomous sanctions. New Zealand's Russia Sanctions Register and Strategic Goods List. With the US and UK above: Five Eyes, covered end to end.
Switzerland, Norway & Türkiye
SECO Consolidated Sanctions — sixty-five programmes in one state-published live feed — with the Goods Control Ordinance annexes. Norway's Sanctions Act measures, applying the EU list by reference and cited to Norwegian law. Türkiye's MASAK asset-freeze designations under Law 6415 — domestic and foreign-request lists that appear on no UN roster.
Indo-Pacific — Japan, Taiwan, India, Thailand
Japan's MOF asset-freeze list and METI End User List. Taiwan's Strategic High-Tech Commodities Entity List, regenerated daily. India's SCOMET dual-use categories. Thailand's AMLO Designated Persons List and Foreign Business Act List Two.
Wassenaar Arrangement
Multilateral export controls. Map components to Wassenaar munitions and dual-use categories. Author custom rules for national implementation variations.
Anything not on this list
World Bank ineligible-firms list with ADB, AfDB, EBRD, and IDB cross-debarments, in one daily feed. Prime contractors impose supplier restrictions beyond statutory requirements. Contract flow-downs, prohibited-supplier lists, sovereign procurement rules, and customer-specific frameworks are authored as custom regimes and screened with the same evidentiary rigor as the built-ins. Every BOM revision is re-screened automatically.
An ITAR expert on every bill of material
§ 126.1 proscribed destination screening
Flags defense articles sourced from prohibited countries with evidence tracing to the specific regulatory provision.
USML category identification
Maps components across all 21 Munitions List categories and catches items requiring classification review before procurement, not during audit.
Corporate structure traversal
Traces manufacturer ownership through subsidiaries and affiliates to the ultimate parent entity, because a permitted subsidiary of a proscribed parent is not compliant.
Specification-level honesty
When a component's category triggers a potential ITAR classification, Forge flags it for formal commodity jurisdiction analysis and tells the user exactly why, citing the USML criteria that apply.
A deterministic compliance engine that proves its own citations, written in Rust, with AI to research what the database doesn't already know
Rust because a compliance verdict must be deterministic and reproducible.
Forge is a compiled Rust compliance engine. The rule evaluation is deterministic — Rust is chosen because although it is more demanding of the software developer (Blecher Group), it produces output that is fundamentally more reliable. Rust compiles to native machine code with zero runtime overhead, enforces memory safety without a garbage collector, and catches errors at compile time that other languages discover in production. The same BOM checked against the same regime version produces the same result every time. The type system enforces evidence chain production at compile time — a function that evaluates a rule cannot compile unless it returns the evidence nodes that document its reasoning.
Agent-driven statutory/regulatory verification and entity research where deterministic lookup cannot reach.
AI enters the pipeline at exactly two points. When a manufacturer name cannot be resolved deterministically through e.g., exact match, alias lookup, or phonetic encoding, an agent researches the entity, finds its corporate parent, and sources the relationship to a verifiable filing. When a cited authority cannot be found in the local database, an agent discovers candidate URLs on primary government sources, fetches them, and grounds the citation. In both cases, the agent's work is verified before it enters the system. The evidence chain documents what the agent found and where it found it. The determination is the engine's. The research is the agent's.
Veracity-Engine can discover and verify any legal authority from any jurisdiction on demand. The first user who triggers a lookup for an obscure Thai procurement regulation or a Wassenaar category definition pays the one-second network cost. Every user after that — across every organization — gets the verified authority instantly. The database doesn't need to know about a statute before someone asks. It learns on first contact and serves every contact after.
Powered by Veracity-Engine
Every citation is checked word for word against its source.
The Sovereign Library is a cross-tenant authority cache built on the citation verification methodology developed for Veracity-Engine. When the engine cites a statute, the cited excerpt must appear as a verbatim substring of a page actually fetched from the canonical government source. A model-authored or hallucinated URL or quote cannot survive the grounding and evaluation. A citation that passes grounding is stored as a verified, trust-tiered authority and reused across every subsequent check that references the same provision. The first lookup pays the network cost. Every lookup after it is instantaneous.
The source viewer shows a green ✓ Verified badge on every grounded authority, the verbatim excerpt with the relevant passage highlighted, and a direct link to the government publication. The user can read the statute themselves. The tool proves it cited correctly.
Signed and tamper-evident.
A report generated today can be independently verified two years from now without contacting Forge or Blecher Group. The Ed25519 digital signature proves the document has not been modified since generation. The hash chain computes a cryptographic fingerprint of every element in the report — each verdict, each evidence node, each source citation, each disposition — and combines them into a single root hash embedded in the signed certificate, so that altering any single element invalidates the entire chain. The hash chain covers the evidence tree, the source citations, and every disposition recorded against the findings.
Priced to your program
Enterprise
Organization-wide compliance infrastructure for primes and large suppliers managing verification across multiple programs, divisions, and security classifications.
The platform:
- Unlimited BOM uploads (CSV / Excel)
- Built-in regimes: NDAA §889, OFAC SDN, ITAR, EAR
- Full source-traced evidence chains
- Signed PDF / XLSX reports with Ed25519 certificate
- Author custom regimes (form, spreadsheet, or PDF)
- Bulk checks and BOM revision comparison
- Agent-assisted entity and ownership research
Enterprise deployment:
Your BOMs, your supply chain, your data. Forge never trains on your uploads, never shares data across organizations, and no one at Blecher Group can see your bills of material.
- On-premise deployment. A single deployable binary that runs inside your network. Your BOMs never leave your infrastructure. Air-gapped environments supported. No external API calls required for core screening. Agent-assisted resolution available when connected.
- API access for ERP integration. REST API for automated BOM ingestion from SAP, Oracle, or any procurement system. Trigger compliance checks programmatically. Pull results and evidence chains into your existing workflows.
- Program-scoped access control. Assign users to specific programs. A program manager sees only their program's BOMs, checks, and reports. Division-level administrators manage their teams. Organizational administrators see everything. Role-based access matches your existing program security structure.
- Continuous re-evaluation. When a regime updates, every historical BOM checked against that regime is automatically re-evaluated. If a previously compliant component is now flagged because a manufacturer was added to the SDN list yesterday, Forge notifies the affected program manager immediately.
- Dedicated regime curation. Blecher Group curates custom regimes specific to your contract requirements, program-specific flow-downs, or country-specific procurement rules. Delivered as managed, versioned regime packages maintained on your update schedule.
- SSO and SAML integration. Connect Forge to your existing identity provider. No separate credentials. No separate user management.
- Organization data export, audit controls, and retention policies.
- Volume and seat pricing. Dedicated onboarding and support.
Put your next BOM through Forge.
Create an account, upload a bill of material, and get a signed, evidence-traced compliance report you can defend.
Your BOMs are never retained beyond your account, never shared across organizations, and never used for training.