Skip to content

Use Cases

Real incidents. Real regulatory failures. How Forge defends against each one.

USE CASE 1

THE EJECTION SEAT

Suspected counterfeit semiconductors in an ejection seat that failed. DFARS source verification catches unauthorized suppliers before installation.

In June 2020, First Lieutenant David Schmitz ejected from his F-16 during a failed landing at Shaw Air Force Base. His ejection seat malfunctioned. He was killed on impact. He was 32.

The Air Force Research Laboratory examined the seat's digital recovery sequencer and found ten suspected counterfeit semiconductors inside it, including six transistors with no conformal coating, heavy gouging, and arcing scratch marks. The Air Force buried these findings in a classified section of its accident report. His widow learned about the suspected counterfeit parts only through a federal FOIA request.

The ejection seat had one job.

Ten suspected counterfeit semiconductors were found in the component that was supposed to save his life.

How Forge defends against this: DFARS authorized source verification flags unauthorized suppliers before parts are installed.

Forge screens every component on a bill of materials before the purchase order goes out. If a part is sourced from an unauthorized distributor, Forge flags it. If the component category falls under DFARS counterfeit avoidance requirements, Forge verifies the supplier against the authorized source chain and documents what it found. A BOM-level verification against DFARS 252.246-7007 would have flagged unauthorized sourcing before those parts were installed, before the seat was assembled, and before a pilot trusted it with his life.

Sources: Air Force Times · Military.com

USE CASE 2

THE HIDDEN SUBSIDIARY

A Huawei subsidiary manufacturing under its own brand. Corporate structure traversal traces ownership chains that name matching never will.

NDAA Section 889 prohibits federal agencies from procuring equipment containing components from Huawei, ZTE, Hikvision, Dahua, and Hytera, including their subsidiaries and affiliates. Huawei alone operates over 100 subsidiaries globally. HiSilicon, Huawei's semiconductor design arm, manufactures processors and imaging chips that appear in cameras, embedded systems, and industrial equipment under its own brand. A procurement officer reviewing a BOM sees "HiSilicon Technologies" and has no reason to know it is a Huawei affiliate unless they independently research the corporate ownership of every manufacturer on every bill of materials they process.

A single HiSilicon component in a defense system is a criminal violation of federal law. The contractor may not know. The procurement officer may not know. The part works. It passes electrical testing. It meets the specification. And it makes the entire program non-compliant from the moment it is installed.

How Forge defends against this: Corporate structure traversal traces every manufacturer to its ultimate parent entity, catching subsidiaries that name matching never will.

Forge resolves every manufacturer through a corporate ownership database sourced from regulatory filings, annual reports, and the BIS Entity List. "HiSilicon Technologies" is resolved to HiSilicon, traced to its parent entity Huawei Technologies, and matched against NDAA 889's covered entity list. The evidence chain shows every step: the name resolution, the corporate relationship, the specific statutory provision, and the verbatim text of the law. The procurement officer does not need to know that HiSilicon is a Huawei subsidiary. Forge knows.

Sources: Pub. L. 115-232, § 889 · BIS Entity List, 84 FR 22961

USE CASE 3

THE FIVE INTERMEDIARIES

A component passed through five middlemen between Shenzhen and a Navy helicopter. Authorized source verification flags the break in the chain.

The Senate Armed Services Committee investigation traced a single component's journey from a sidewalk in Shenzhen to a Navy SH-60B helicopter's FLIR and Hellfire missile targeting system. The part passed through five intermediaries spanning China, the United Kingdom, Canada, and the United States. Each intermediary repackaged the part, added a markup, and obscured its origin. By the time the component reached the helicopter, its provenance was untraceable through paperwork alone. Committee witnesses described visiting China and seeing public sidewalks covered with electronic components harvested from e-waste, and whole factories of 10,000 to 15,000 people set up for the purpose of counterfeiting. A single supplier, Hong Dark Electronic Trade of Shenzhen, supplied approximately 84,000 suspect counterfeit parts into the DoD supply chain.

Five intermediaries between a Shenzhen sidewalk and a Hellfire missile targeting system. Each one made the origin harder to trace. None of them were authorized distributors.

How Forge defends against this: Five intermediaries obscured the origin. Forge checks the supplier against the authorized source chain at the point of procurement, before the part enters a distribution network designed to make it untraceable.

Forge checks every supplier against DFARS 252.246-7008 authorized source requirements. An authorized supply chain runs from the original component manufacturer through authorized distributors to the contractor. When the chain includes an unverified broker, a surplus dealer, or an independent distributor who cannot demonstrate authorization from the OCM, Forge flags the gap and documents it. The evidence chain shows exactly where the authorized chain breaks. The procurement officer sees the risk at the first intermediary, before the part passes through four more and arrives at a helicopter that targets missiles.

Sources: Senate Armed Services Committee Report, May 2012

USE CASE 4

THE THIRTY-YEAR-OLD PLATFORM

Obsolete parts sourced from unverified brokers because the original manufacturer no longer exists. Forge flags the supplier gap before procurement.

The F-15 Eagle entered service in 1976. Dozens of the electronic components in its subsystems have not been manufactured for decades. When those components fail, contractors cannot order replacements from the original manufacturer because the original manufacturer no longer makes them. They are forced into the secondary market: surplus dealers, brokers, and independent distributors who acquire obsolete parts from decommissioned equipment, warehouse overstock, and sources that cannot always be verified. This is where counterfeits enter the supply chain. A component that has been out of production for fifteen years commands a premium, and that premium incentivizes forgery. The GAO confirmed that counterfeit microprocessors were sold to the Air Force for installation in F-15 flight control computers.

The older the platform, the deeper the problem. The parts are not available from authorized sources. The brokers cannot verify provenance. The counterfeits are physically indistinguishable without destructive testing. And the component goes into a flight control computer.

How Forge defends against this: When the original manufacturer no longer exists, Forge identifies the supplier gap, flags unverified broker sourcing, and documents the DFARS traceability requirement before a counterfeit reaches the flight line.

Forge verifies the supplier chain for every component against DFARS authorized source requirements. When a part is sourced from a broker rather than the original component manufacturer or an authorized distributor, Forge flags it and documents the gap. For obsolete components, Forge identifies which parts are no longer available from authorized sources and which authorized aftermarket manufacturers exist. The procurement officer sees the risk before signing the purchase order: this component has no authorized source, it was procured from an unverified broker, and DFARS 252.246-7008 requires documented traceability from the original manufacturer to the point of government acceptance. The evidence chain documents the supplier gap, the regulatory requirement, and the specific risk.

Sources: GAO Report GAO-10-389, March 2010

USE CASE 5

THE UNREPORTED MILLION

Over one million suspected counterfeit parts, most never reported. Cryptographically signed evidence chains make silence impossible.

A Senate Armed Services Committee investigation found over 1,800 cases involving more than one million suspected counterfeit electronic parts in the defense supply chain in a two-year period. More than 70% of the cases traced back to China. The Committee found that the vast majority of these cases were never reported to the Department of Defense or to criminal authorities. Companies discovered suspect parts, quietly replaced them, and told no one. No audit trail. No accountability. No way to know whether the same counterfeit parts were sold to other contractors, installed in other platforms, or deployed in other theaters.

The supply chain kept moving. The counterfeits kept circulating. Nobody was tracking them because nobody was required to prove they had checked.

How Forge defends against this: Cryptographically signed evidence chains create an immutable audit record that exists whether anyone asks for it or not.

Every compliance check Forge runs produces a cryptographically signed report documenting exactly what was verified, against which regulatory frameworks, with what results, on what date. The report exists whether anyone asks for it or not. If a component is flagged, the evidence chain traces to the rule, the statute, and the source. (Powered by Veracity-Engine) If a component is cleared, the evidence chain documents what was searched and what was not found. When DCMA requests compliance documentation two years after procurement, the report is there, it is signed, and it has not been modified since generation. Forge makes it impossible to claim the problem was never identified.

Sources: Senate Armed Services Committee Report, May 2012

USE CASE 6

THE PRINTER ON THE FACTORY FLOOR

A banned chip in a 3D printer on the factory floor is the same compliance violation as one in a weapon system. Forge screens both.

Compliance verification in defense procurement focuses on weapon systems. But every piece of equipment in a defense manufacturing facility has a bill of materials. The 3D printer that produces prototype brackets. The CNC machine that mills receiver housings. The inspection camera that photographs finished assemblies. Each of these machines contains processors, controllers, camera modules, and communications chips. If any of those chips were manufactured by a covered entity under NDAA Section 889, the facility is non-compliant. Not the weapon. The facility. The contractor's entire operation is exposed because a camera module inside a printer on the factory floor contains a HiSilicon image processor that nobody thought to check.

NDAA Section 889 does not distinguish between a chip in a missile and a chip in a printer. The prohibition is on procurement of equipment containing covered components. The equipment is the printer. The covered component is the chip inside it.

How Forge defends against this: NDAA Section 889 applies to every piece of equipment a contractor procures, not just weapon systems. Forge screens the printer, the CNC machine, and the inspection camera the same way it screens the missile.

Forge screens every bill of materials with the same rigor, from a weapon BOM to a printer BOM. The same entity resolution, the same corporate structure traversal, the same regime evaluation, and the same evidence chain apply to every bill of materials. Upload the BOM for the Stratasys printer. Run it against NDAA 889. If the camera module contains a HiSilicon processor, Forge traces the ownership chain to Huawei and flags it with the same statutory citation and the same evidentiary rigor as a flagged component in a missile guidance system. The tool catches compliance violations wherever they exist in the supply chain, not just where procurement officers think to look.

USE CASE 7

THE F-35 PRODUCTION HALT

Chinese-origin components halted the most expensive weapon program in history. Country-of-origin screening catches proscribed sources at BOM review.

F-35 Joint Strike Fighter production was halted after Chinese-origin components were discovered during manufacturing. The most expensive weapon program in history, stopped on the line, because components from a proscribed country made it through procurement, through receiving, through inspection, and into the assembly process before anyone identified the country of origin. The July 2025 GAO report found that DoD's primary procurement database provides "limited information about the countries of origin" of components and materials. Of over 99 materials identified by DoD as being in shortfall for FY2023, none were manufactured in the United States.

The F-35 program did not have a counterfeit problem. It had a visibility problem. The parts were real. They were just from the wrong country. And nobody knew until production stopped.

How Forge defends against this: Country-of-origin screening resolves every manufacturer's domicile and flags proscribed-source components at the BOM review stage, months before a part reaches the production line.

Forge screens every component's manufacturer against country-of-origin restrictions under ITAR § 126.1, EAR Country Group controls, and NDAA procurement prohibitions. When a manufacturer is domiciled in a proscribed country, the component is flagged with the specific regulatory provision that prohibits its procurement. When the manufacturer's country cannot be determined, Forge flags the component as unresolved and documents the gap. The procurement officer sees the country-of-origin risk at the BOM review stage, months before the part arrives at the factory, and years before a GAO audit discovers it on the production line.

Sources: GAO-25-107283, July 2025

USE CASE 8

THE MISSILE THAT WOULD HAVE MISSED

Suspect counterfeit parts in THAAD mission computers. The same screening protects the interceptor that protects the city.

Suspect counterfeit parts were found in THAAD mission computers. The Missile Defense Agency confirmed that the missile would likely have failed if the suspect parts had malfunctioned. THAAD is the Terminal High Altitude Area Defense system. It is the last line of defense against incoming ballistic missiles targeting military installations and population centers. The suspect counterfeit parts were in the mission computer: the component that calculates the intercept trajectory, commands the kill vehicle, and determines whether the warhead is destroyed in the upper atmosphere or reaches its target.

The ejection seat in Use Case 1 protects one pilot. THAAD protects a city. The counterfeit parts were in the component that decides whether the interceptor hits or misses.

How Forge defends against this: Forge applies the same DFARS authorized source verification to every component on every platform. The screening does not scale with the consequence of failure because it should never have to.

Forge applies the same verification to every component regardless of the platform it is installed in. A MOSFET in an ejection seat sequencer and a MOSFET in a THAAD mission computer are both verified against the same DFARS authorized source chain requirements, with the same evidence chain depth, and the same cryptographic signature on the compliance report. The tool does not know that one component protects a pilot and the other protects a city. It verifies both with the same rigor because the regulatory requirement does not distinguish between them.

Sources: Senate Armed Services Committee Report, May 2012

USE CASE 9

THE SOVEREIGN BUYER

Every country has different approved suppliers. Sovereign standards, allied-nation regulations, and contract flow-downs are all configurable as first-class regimes.

Thailand's military procures equipment from Russia, China, the United States, India, Israel, and domestic manufacturers. A Thai procurement officer verifying a bill of materials needs to check it against Thailand's own approved supplier list, which includes manufacturers from countries that would be prohibited under US regulations. No American compliance tool models this correctly because no American compliance tool was built to accommodate a regulatory framework where Russian and Chinese manufacturers are approved sources. The tool either flags everything from those countries (useless for a Thai buyer) or it only checks US regulations (useless for a Thai program).

Every country has its own procurement rules. Every allied nation has its own approved and restricted supplier lists. A compliance tool that only understands American law is a compliance tool that only works for Americans.

How Forge defends against this: Sovereign procurement standards, allied-nation regulations, contract flow-downs, and company-specific approved supplier lists are all configurable as first-class regimes enforced with the same evidentiary rigor as US federal law.

Forge treats the regulatory framework as an input, not an assumption. Upload a spreadsheet of approved suppliers. Map the columns. Assign each entity a status: approved, restricted, or banned. Forge enforces your country's rules as a first-class regime alongside the built-in US frameworks. Run a Thai procurement BOM against NDAA 889, OFAC SDN, and your own Thai approved supplier list simultaneously. The results show which components are flagged by US law, which are approved under Thai rules, and which are flagged by both or neither. Each determination carries its own independent evidence chain with its own source citations. One platform. Every regime. Any jurisdiction.

USE CASE 10

THE SUPPLY CHAIN AS A WEAPON

Compromised devices detonated across Lebanon. Compromised chips in military hardware are an attack surface. Forge verifies provenance before installation.

In September 2024, thousands of Hezbollah pagers and walkie-talkies detonated simultaneously across Lebanon. Israel had infiltrated the supply chain, modified the devices during manufacturing, and turned consumer electronics into weapons. The operation demonstrated at scale what defense analysts had theorized for decades: that supply chain compromise enables not just espionage, but mass physical destruction. A 2024 security report warned that supply chain attacks by nation-states could target edge AI hardware, yielding undetectable persistence across device lifecycles, with implications for autonomous systems where backdoors could alter decision-making algorithms in real time. In 2007, Syria's radar system failed to detect incoming Israeli aircraft during a strike on a nuclear facility. The failure has been attributed to a potential backdoor built into the radar's chips.

Supply chain compromise is a weapon. A compromised chip in a communication system, a navigation module, or a fire control computer is an attack surface controlled by whoever compromised it. The parts pass every test. The specs match. The equipment works. Until it doesn't, at exactly the moment someone else decides.

How Forge defends against this: Forge verifies the provenance, manufacturer, country of origin, and authorized supply chain of every component and produces cryptographic proof that the verification was done, before the part is installed.

Forge verifies every component's manufacturer, country of origin, corporate ownership chain, and supply chain provenance before the component is procured. When the threat is deliberately compromised parts, the provenance record is the first line of defense. A part from an unverified supplier sourced through an unauthorized distributor with a manufacturer whose corporate parent is domiciled in a proscribed country is flagged at every level, with evidence chains tracing each determination to its regulatory source. The signed compliance report documents exactly what was verified and what was not.

Sources: Senate Armed Services Committee Report, May 2012 · GAO-25-107283, July 2025

Scale and Operations

Verify at scale

e.g., 10,000+ components verified in seconds.

Bulk checks

Multiple BOMs checked against the same regimes in a single operation.

Organization-wide search

Search for any manufacturer across every BOM and compliance check in the organization.

Forge catches it before the purchase order goes out.

Forge uses a small number of cookies to keep you signed in and remember your interface preferences. Essential and security cookies are always on. Optional, non-essential analytics cookies stay off until you accept. Forge sets no third-party advertising cookies and does not sell your data. You can change your choice any time from Cookie Preferences. Privacy Policy