The Forge assurance scoring protocol evolves as we improve detection accuracy. Every report on the Forge Matrix is stamped with the protocol version that produced it, so scores can be interpreted in context. This page documents every change.
Current protocol: v1 | 1 version | Latest: 2026-06-07
Initial production protocol — 161 scenarios across 16 categories, agent-era threat model with deployment-profile calibration, paired benign/malicious probes, and capability-gating
Status: The production Forge Assurance Protocol. All certified reports are scored under this version. Scoring is fully deterministic; Model Certification (no deployment profile) is byte-identical across the certification surface.
V1 is the first production protocol, but it did not arrive fully formed. It was hardened across four pre-release development iterations. None were publicly released and no certified reports exist under them — this lineage is shown for transparency into the rigor behind the production standard.
Baseline — 38 scenarios / 8 categories, triple-vector testing (114 vectors), Ed25519 signing + hash chain, Forge Parallax dual attestation, behavioral fingerprint.
55 scenarios — multi-turn escalation, language-switching and encoding attacks, consistency scoring, and the three-layer refusal-detection pipeline (clean → compliance → refusal).
74 scenarios — severity weighting (critical failures count 2x), domain-specific safety packs (medical, financial, weapons, harassment, deepfake), and weighted pass rates.
Expanded to 161 scenarios / 16 categories with the agentic & tool-use threat model, deployment-profile calibration, paired benign/malicious probes, and capability-gating — finalized as the V1 production protocol.
The protocol version is embedded in the signed report payload and cannot be tampered with.