Skip to content

Your BOM is either compliant or it isn't.
Prove it.

Upload a bill of material. Forge screens every component against NDAA §889, the OFAC SDN list, ITAR, EAR, and any regime you configure, and produces a signed, source-traced evidence chain you can put in a compliance file and defend under audit.

See it in action

A single listed or prohibited component in your supply chain is a contract termination, a False Claims Act theory, and a debarment case

A relabeled chip from a prohibited subsidiary enters your supply chain through a third-tier distributor. Your compliance team doesn't catch it because they're checking manufacturers by hand against spreadsheets that were current last quarter. The contracting officer finds it during a DCMA audit.

ITAR violations can carry criminal penalties up to $1M per violation and 20 years imprisonment. False Claims Act exposure can attach to every certification you signed. Debarment removes your company from government contracting entirely. And the compliance officer who signed the certification is the first person the government interviews.

Forge catches it before the purchase order goes out.

Nexperia · 74HC595 · Non-CompliantWatching Forge trace the verdict…
  • InputComponent: Nexperia 74HC595 (line 24)

    manufacturer="Nexperia" part="74HC595" category=Microcontroller qty=1 country=- cage=-

  • Entity ResolutionEntity resolution: "Nexperia"2 steps

    Declared supplier "Nexperia" resolved to entity nexperia.

    NLLEI: 724500IMA6Z12H3ZHA17
    • InputDeclared entity "Nexperia"

      cage=- duns=- lei=-

    • Entity ResolutionExact match -> nexperia

      Operation 1 (deterministic exact): declared name normalized to "nexperia", which exactly matches alias "Nexperia" of entity nexperia.

  • Parent LookupCorporate parent chain for nexperia3 steps

    Resolved parent chain (canonical): [Nexperia B.V. -> Wingtech Technology Co., Ltd.]

    Appears on 3 lists
    • Parent LookupCorporate parent-chain traversal from nexperia

      Operation 4: walking recorded parent relationships to the chain root.

    • Parent Lookupnexperia -> wingtech (majority_owned)

      Nexperia B.V. is a majority_owned of wingtech.

    • Parent Lookupwingtech is chain root

      No parent relationship recorded; this entity is the ultimate parent.

  • Regime EvaluationRegime evaluation: BIS EAR Entity List (15 CFR Part 744, Supplement No. 4)2 steps

    BIS EAR Entity List (15 CFR Part 744, Supplement No. 4): NON-COMPLIANT — matched prohibition rule(s): ear_entity_list-r2

    BIS EAR Entity List
    • Regime EvaluationRule ear_entity_list-r1 [RequiresLicense]2 steps

      Condition did not match

      Rule ear_entity_list-r1Covered-entity list
      • Regime Evaluationentity.on_list [entity_set:ear_entity_list]

        entity "Nexperia B.V." is not on list "ear_entity_list"; result = false

      • Source VerificationVerifiedSource verification for rule ear_entity_list-r11 step

        Excerpt cited at 15 CFR § 744.16; see 84 FR 22961 (May 21, 2019) and 84 FR 54002 (Oct. 9, 2019) against source 74ddca7c-ea59-51f8-b70d-58d0d46c05ce → verified

        • Source VerificationVerifiedVerbatim match (exact)

          Excerpt is an exact substring of the source text: "In addition to the license requirements for items specified on the CCL, you may not, without a license from BIS, export,…".

    • Regime EvaluationProhibitedRule ear_entity_list-r2 [Restricted]2 steps

      Condition MATCHED → Restricted

      Rule ear_entity_list-r2Covered-entity list
      • Regime Evaluationentity.parent_chain CONTAINS_ANY [entity_set:ear_entity_list]

        parent_chain member "Wingtech Technology Co., Ltd." is in entity_set "ear_entity_list" (3332 members); result = true

      • Source VerificationVerifiedSource verification for rule ear_entity_list-r21 step

        Excerpt cited at 15 CFR § 744.16 (parent/affiliate scope; see 84 FR 22961 non-U.S. affiliate additions) against source 74ddca7c-ea59-51f8-b70d-58d0d46c05ce → verified

        • Source VerificationVerifiedVerbatim match (exact)

          Excerpt is an exact substring of the source text: "The Entity List (supplement no. 4 to this part) identifies persons or addresses of persons reasonably believed to be inv…".

A component on line 24 of a bill of materials — Nexperia, part 74HC595 — is ruled Non-Compliant, on an ownership edge rather than on the supplier itself. Nexperia B.V. is a Dutch company that is clean on its own record: the first rule tested whether it appears on the BIS Entity List and did not match. The second rule tested its corporate parent chain, and did match — Nexperia's majority owner is Wingtech Technology Co., Ltd., which is on the Entity List. The determination rests entirely on that majority-ownership relationship, cited to 15 CFR § 744.16 and quoted verbatim from the regulation.

Powered by Veracity-Engine

Automated compliance verification with evidence you can defend under audit

Add rule · ITAR / USML (22 CFR Parts 121, 126)Watching Forge author a rule…
Jurisdiction
US
Issuing authority
US Dept. of State, DDTC
Version
v2
Effective date
22 Jul 1993
Unlisted-entity default
restricted
Covered entities
1,486

Rule type

Flag components from selected countries, optionally narrowed to categories.

Countries

Origin is the BOM-declared country, or the resolved manufacturer's nationality.

Nothing selected yet.

Add a predefined country group

Add a country by ISO code

Narrow to categories (optional)

Leave empty to flag components from these countries regardless of category.

Nothing selected yet.

Defense / USML-relevant

Electronics / EAR-relevant

General

When this matches, flag the component as

Source citation (optional)

Excerpt (optional)

Live preview

Select at least one country or country group.

result_type = banned

Rules3

  • 22 CFR § 126.1(d)(1)
    banned

    A component whose category may constitute a USML defense article (an imaging/thermal or other sensor, an optical or laser article, an RF/radar/electronic-warfare article, or a cryptographic article), sourced from or originating in a country on the 22 CFR § 126.1(d)(1) policy-of-denial list (Belarus, Burma, China, Cuba, Iran, North Korea, Syria, Venezuela), is flagged as banned: it is the policy of the United States (§ 126.1(a)) to deny licenses for defense articles destined for or originating in these countries. This screening operates at the component category level.

    component.category IN [sensor, optical, rf, crypto] AND entity.country IN [BY, MM, CN, CU, IR, KP, SY, VE]

    “For defense articles and defense services, the following countries have a policy of denial: Belarus, Burma, China, Cuba, Iran, North Korea, Syria, Venezuela.”

    #0 · itar_usml-r1

  • 22 CFR § 126.1(d)(2)
    restricted

    A component whose category may constitute a USML defense article, sourced from or originating in a country listed in 22 CFR § 126.1(d)(2), is flagged as restricted: a policy of denial applies to defense articles for these countries as specified in the associated (program- or embargo-specific) paragraphs of § 126.1, and each transaction requires case-by-case review against those paragraphs rather than automatic approval.

    component.category IN [sensor, optical, rf, crypto] AND entity.country IN [AF, CF, CY, CD, ER, ET, HT, IQ, LB, LY, NI, RU, SO, SS, SD, ZW]

    “For defense articles and defense services, a policy of denial applies as specified in the associated paragraphs in the following table: Afghanistan, Central African Republic, Cyprus, Democratic Republic of the Congo, Eritrea, Ethiopia, Haiti, Iraq, Lebanon, Libya, Nicaragua, Russia, Somalia, South Sudan, Sudan, Zimbabwe.”

    #1 · itar_usml-r2

  • 22 CFR § 121.1
    warning

    This component's category may constitute a defense article under the United States Munitions List (for example, USML Category XI Military Electronics, or Category XII Fire Control, Laser, Imaging, and Guidance Equipment) and is flagged for ITAR classification review regardless of destination. This screening operates at the component category level.

    component.category IN [sensor, optical, rf, crypto]

    “Category XI—Military Electronics. Category XII—Fire Control, Laser, Imaging, and Guidance Equipment.”

    #2 · itar_usml-r3

Rule added

The rule is now part of this regime.

Authoring a compliance rule for a new jurisdiction without writing code. A pointer operates the builder: it moves between the four rule tabs, types a manufacturer, combines conditions with AND, OR and NOT, searches the category taxonomy, applies the ITAR §126.1(d) country group in a single click, adds and removes an individual country code, changes the result severity, and enters a pinpoint citation with its excerpt. Three things rewrite themselves at every keystroke: a plain-language sentence stating what the rule does, the compiled condition expression, and a conflict warning that appears only when an overlapping rule carries a different severity.

Powered by Veracity-Engine

Every verdict traces from the component on your BOM to the statute that governs it

Each step is recorded as a node you can expand, read, and cite in an audit. A subsidiary whose parent is sanctioned is exactly the case manual review misses.

Component
HiSilicon Hi3559AV100
A processor on your bill of material.
Resolved entity
HiSilicon Technologies Co., Ltd.
The raw manufacturer text is matched to a known entity, aliases included.
Corporate parent
Huawei Technologies Co., Ltd.
Ownership is traced from the subsidiary to its ultimate parent.
Statute
NDAA §889
The parent is a covered entity under the rule, cited to primary text.
Verdict
Non-Compliant
The determination, with the full chain above attached as evidence.
Non-Compliant · NDAA §889 · line 48What does this rest on?
Link 1 / 6The verdictwhat you were handed
Non-Compliant
HiSilicon Technologies · Hi3559AV100

NDAA FY2019 Section 889 - Covered Telecommunications and Video Surveillance Equipment Prohibition

  • Regime EvaluationRegime evaluation: NDAA FY2019 Section 889 - Covered Telecommunications and Video Surveillance Equipment Prohibition

    NDAA FY2019 Section 889 - Covered Telecommunications and Video Surveillance Equipment Prohibition: NON-COMPLIANT — matched prohibition rule(s): ndaa_889-r1

    NDAA §889

Same component, all four regimes evaluated

  • BIS EAR

    matched prohibition rule(s): ear_entity_list-r2

  • NDAA §889

    matched prohibition rule(s): ndaa_889-r1

  • OFAC SDN
  • CSL

Contaminated Reference BOM · 3 non-compliant of 50 · entity db seed-6496f6244bac9c2f · cert 8ed74ba0dbebdfaf…

The same determination read backwards, from conclusion to source. It starts at the Non-Compliant verdict, then shows the rule that fired — ndaa_889-r1, quoting § 889(a)(1)(A) verbatim and marked Verified, Tier 1. Then the covered-entity membership behind it: Huawei is one of the five entities in the NDAA §889 set. Then the corporate-parent edge that a manual review misses, HiSilicon to Huawei, sourced to 84 FR 22961. Then the entity resolution that normalised the declared supplier string. And finally the row it all came from: line 48, HiSilicon Technologies, part Hi3559AV100.

Powered by Veracity-Engine

An interactive compliance check you work in, and a signed compliance report you file.

The check surfaces every determination grouped by component. Non-compliant parts show the decisive fact immediately: which regime, which rule, which entity in the ownership chain triggered it. Clean components document what was searched and what was not found. Every entity name, every regime, every rule, and every statutory citation in the evidence chain is a live link to its source. Expand, drill down, navigate, and record dispositions without leaving the results page.

The report is the document you defend under audit. The verdict summary table shows every component with a per-regime verdict on one page. The executive risk narrative names every non-compliant component, cites the specific statute, and states the regulatory consequence. The scope disclosure documents exactly which regimes were evaluated and which were not, so a compliant determination is never mistaken for an absolute clearance.

Certificate of record check ab84ab77independent verification…

Verifying certificate integrity…

Recomputing the hash from the payload, then checking the detached signature.

Hash matchessignature
1 · Recompute SHA-256 over certificate_jsonpass
certificate_hash (as issued)

214b35bc42edc576a2b988dceab96e02cba969416bc13b67d32af094675fb816

recomputed from the payload below

214b35bc42edc576a2b988dceab96e02cba969416bc13b67d32af094675fb816

identical — all 50 components, the dispositions and the pinned versions are inside these bytes

2 · Verify Ed25519 signature over the 32-byte digestrunning…
signature (base64, detached)

fduiQKJPP02LGQxH3a6BUV8JKci/9M//lzo7FxblSF4gD4XUudBdfog3GuvmPo3MaAdXGmqx9h2ONVOVyyowAA==

public_key (base64, embedded in the certificate)

OWOO6xj5Wuf4KcF+vsF9kIcDOXEhWrW0QD/9SpaDj+0=

the signature covers the digest, not the JSON — so the check is: recompute, then verify against the embedded key

3 · Versions pinned at check timereproducible
entity_db_version

seed-9ed1e786aab9180e

regime_versions
  • 50cb4283-60f5-4c13-bcef-dfeef510fa76v1
  • 129f27bf-a2bd-43ac-afb6-64a658381a86v1
  • 9bb7fc7d-e342-4567-bf89-af2109f6d88dv1
  • 958ca89c-ac62-4d1b-b95e-448b9fc4aae0v1

the determinations are reproducible from the pinned regime and entity-database versions — a third party can re-run the check against exactly these

certificate_json — the signed payloadas issued

canonical field order = what the hash binds to · 3 of 50 components shown · click a dotted value to tamper

{
"schema": "forge.certificate.v3",
"check_id": "ab84ab77-0c6a-4872-b0ea-e5f624a88283",
"organization_name": "Meridian Defense Systems",
"compliance_officer_name": "Alan Blecher",
"bom_name": "Contaminated Reference BOM",
"entity_db_version": "seed-9ed1e786aab9180e",
"regime_versions": [
{ "regime_id": "50cb4283-60f5-4c13-bcef-dfeef510fa76", "version": "1" },
{ "regime_id": "129f27bf-a2bd-43ac-afb6-64a658381a86", "version": "1" },
{ "regime_id": "9bb7fc7d-e342-4567-bf89-af2109f6d88d", "version": "1" },
{ "regime_id": "958ca89c-ac62-4d1b-b95e-448b9fc4aae0", "version": "1" }
],
"summary": {
"total": 50, "compliant": 47, "non_compliant": , "unknown": 0
},
"components": [
{ "line_number": 1,
"manufacturer_declared": "Texas Instruments",
"manufacturer_resolved": "Texas Instruments Incorporated",
"part": "TMS320C6678", "overall_verdict": "compliant",
"regime_verdicts": [ … ] },
ndaa_889 · ofac_sdn · csl · ear_entity_list — all compliant
{ "line_number": 48,
"manufacturer_declared": "HiSilicon Technologies",
"manufacturer_resolved": "HiSilicon Technologies Co., Ltd",
"part": "Hi3559AV100", "overall_verdict": "non_compliant",
"regime_verdicts": [
{ "regime_id": "ndaa_889", "verdict": },
{ "regime_id": "ear_entity_list", "verdict": "non_compliant" },
{ "regime_id": "ofac_sdn", "verdict": "compliant" },
{ "regime_id": "csl", "verdict": "compliant" }
] },
{ "line_number": 49,
"manufacturer_declared": "JOINT STOCK COMPANY MIKRON",
"manufacturer_resolved": "JOINT STOCK COMPANY MIKRON",
"part": "1892VM14YA", "overall_verdict": "non_compliant",
"regime_verdicts": [ … ] },
ofac_sdn · csl non_compliant — ndaa_889 · ear_entity_list compliant
… 47 more components elided for display — all 50 are inside the signed bytes
],
"dispositions": [
{ "line_number": 48,
"regime_name": "NDAA FY2019 Section 889 - Covered Telecommunications and Video Surveillance Equipment Prohibition",
"action": "request_exception", "status": "open",
"justification": "De-minimis use in a non-networked test fixture; mitigation per Program Directive MDS-2026-014. Requesting a documented exception pending redesign.",
"cited_basis_citation": "Pub. L. 115-232, § 889(a)(1)(A)",
"cited_basis_excerpt": "The head of an executive agency may not— (A) procure or obtain or extend or renew a contract to procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system…",
"cited_basis_status": ,
"resolution_note": null }
],
"issued_at": "2026-07-17T12:46:01Z"
}
the signed JSON verifies offline — no Forge account

A signed compliance certificate being checked by someone who does not have to trust whoever issued it. The certificate's hash is recomputed from its contents and matches, so it verifies. Then a field in the document is altered, the hash is recomputed, and it no longer matches — verification fails immediately. The point is that anyone holding the document can run this check themselves and get the same answer.

Powered by Veracity-Engine

One platform for every regime or contractual requirement your program touches

Forty regimes ship with the engine, spanning sixteen jurisdictions and five multilateral development banks — the United States, the European Union, the United Kingdom, the United Nations, the full Five Eyes, wider Europe from Bern to Ankara, and the Indo-Pacific from Tokyo to New Delhi. Screening runs against live designation feeds, and every determination cites verbatim text from the canonical government publication. For anything not on that list, hand Forge the regulation's own PDF or a spreadsheet of designated parties: it extracts the rules, proposes the entity list for your review, and screens against the result with identical rigor.

15 REGIMES · LIVE FEEDS

United States

NDAA §889 and §5949. OFAC SDN. US Consolidated Screening List. BIS EAR Entity List and EAR country controls. ITAR / USML. DFARS counterfeit avoidance. DoD §1260H Chinese military companies. DoD Blue UAS approved list. UFLPA Entity List. FCC Covered List. CBP forced-labor orders. BIS military-intelligence end-user list. CAATSA §231 specified persons. Entity resolution traces corporate ownership, so a permitted subsidiary of a proscribed parent is caught.

4 REGIMES · BUILT IN

European Union

Dual-Use Regulation (EU) 2021/821, screened against Annex I categories. Consolidated Financial Sanctions List, including designated individuals as well as entities. The Russia military end-user list — all 921 entities of Annex IV, Regulation 833/2014. Common Military List, ML1 through ML22.

3 REGIMES · BUILT IN

United Kingdom & United Nations

UK Sanctions List, published live by the FCDO — the single source for every UK designation, trade-sanctions targets as well as asset freezes. UK Strategic Export Control Lists. UN Security Council Consolidated List. All carry the full designated-person rosters, not entity names alone.

6 REGIMES · 3 COUNTRIES

Five Eyes — Australia, Canada, New Zealand

Australia's DFAT Consolidated List and Defence and Strategic Goods List. Canada's Export Control List and SEMA autonomous sanctions. New Zealand's Russia Sanctions Register and Strategic Goods List. With the US and UK above: Five Eyes, covered end to end.

5 REGIMES · 3 COUNTRIES

Switzerland, Norway & Türkiye

SECO Consolidated Sanctions — sixty-five programmes in one state-published live feed — with the Goods Control Ordinance annexes. Norway's Sanctions Act measures, applying the EU list by reference and cited to Norwegian law. Türkiye's MASAK asset-freeze designations under Law 6415 — domestic and foreign-request lists that appear on no UN roster.

6 REGIMES · 4 COUNTRIES

Indo-Pacific — Japan, Taiwan, India, Thailand

Japan's MOF asset-freeze list and METI End User List. Taiwan's Strategic High-Tech Commodities Entity List, regenerated daily. India's SCOMET dual-use categories. Thailand's AMLO Designated Persons List and Foreign Business Act List Two.

Configurable

Wassenaar Arrangement

Multilateral export controls. Map components to Wassenaar munitions and dual-use categories. Author custom rules for national implementation variations.

Custom · live feed · your contracts and customers

Anything not on this list

World Bank ineligible-firms list with ADB, AfDB, EBRD, and IDB cross-debarments, in one daily feed. Prime contractors impose supplier restrictions beyond statutory requirements. Contract flow-downs, prohibited-supplier lists, sovereign procurement rules, and customer-specific frameworks are authored as custom regimes and screened with the same evidentiary rigor as the built-ins. Every BOM revision is re-screened automatically.

An ITAR expert on every bill of material

§ 126.1 proscribed destination screening

Flags defense articles sourced from prohibited countries with evidence tracing to the specific regulatory provision.

USML category identification

Maps components across all 21 Munitions List categories and catches items requiring classification review before procurement, not during audit.

Corporate structure traversal

Traces manufacturer ownership through subsidiaries and affiliates to the ultimate parent entity, because a subsidiary that is clean on its own record can be covered, blocked, or restricted through its parent — and it is always a finding you must run down.

Specification-level honesty

When a component's category triggers a potential ITAR classification, Forge flags it for formal commodity jurisdiction analysis and tells the user exactly why, citing the USML criteria that apply.

IRay Technology · Tiny1-C · thermal_imaging · Banned
Non-Compliant
ITAR / USML — 22 CFR Parts 121, 126Watching Forge trace the verdict…
  • InputBOM line 12 — thermal imaging sensor

    line=12 mpn="Tiny1-C" manufacturer="IRay Technology" category=thermal_imaging qty=4 ref_des=U7,U8,U9,U10 country_of_origin=<not declared on BOM line>

    line 12 · qty 4category: thermal_imaging
  • Entity ResolutionNormalizedEntity resolution — "IRay Technology"1 step

    match="Yantai IRay Technology Co., Ltd." confidence=0.97 method=alias+jurisdiction country_of_incorporation=CN origin_basis=manufacturer_incorporation (BOM line declared no country)

    CN5 entity lists · 0 matches
    • Regime EvaluationVerifiedEntity-list screen — clean

      ndaa_889_covered=0 bis_entity_list=0 ofac_sdn=0 csl=0 dfars_covered=0 → no entity-based flag. Screening continues on jurisdiction.

  • Regime EvaluationProhibitedCountry-of-origin screen — 22 CFR § 126.1(d)(1)2 steps

    condition_dsl: component.category IN [sensor, optical, rf, crypto] AND entity.country IN [BY, MM, CN, CU, IR, KP, SY, VE] eval: component.category=thermal_imaging → sensor ✓ entity.country=CN ∈ Table 1 (policy of denial) ✓ → MATCHED result_type=banned

    Rule itar_126.1-d1
    • Regime EvaluationTable 1 membership test

      CN ∈ [BY, MM, CN, CU, IR, KP, SY, VE] → true

      BYMMCNCUIRKPSYVE
    • Regime EvaluationTier test — why banned, not restricted

      Table 1 → blanket policy of denial → banned Table 2 → denial per associated paragraphs → restricted (RU, ER, ZW, …) CN ∈ Table 1 → banned

  • Source VerificationVerifiedAuthority verification — 22 CFR § 126.1(a)

    excerpt matched verbatim against the ingested authority issuer=US Dept. of State, DDTC trust_tier=1 doc=cfr_22_126_1 source=eCFR versioner API, corroborated vs. govinfo CFR 2024 annual edition latest amendment on record: 90 FR 61061 (Dec. 30, 2025)

  • Regime EvaluationProhibitedUSML category classification — 22 CFR § 121.1

    component.category=thermal_imaging → defense-article proxy [sensor] USML mapping → Category XII (Fire Control, Laser, Imaging, and Guidance Equipment) adjacent: Category XI (Military Electronics)

    thermal_imaging
  • Regime EvaluationProhibitedRule itar_126.1-d1 → Banned

    defense-article category (USML Cat XII) + proscribed origin (CN, Table 1) → result_type=banned regime=itar_usml verdict=non_compliant

  • Banned — a defense article originating in a proscribed destination. It is the policy of the United States to deny licenses for defense articles destined for or originating in China (§ 126.1(a), (d)(1)); the component's category maps to USML Category XII (§ 121.1).

    Category-level screen. Definitive ITAR classification requires a commodity-jurisdiction determination reviewing the component's technical specifications against the specific USML subcategory criteria. Forge flags this part for that review — it does not perform it, and does not claim to.

The other way a component fails: not who made it, but where. The entity-list screen on this supplier comes back clean — the flag is jurisdictional. A defense article on the USML is traced to a country of origin in the ITAR §126.1(d)(1) proscribed list, which carries a general policy of denial under 22 CFR § 126.1(a). The demo opens the supplier's profile, the proscribed-country tables, the USML Category XII detail, and the verbatim regulation text behind each, all quoted from the Code of Federal Regulations.

Powered by Veracity-Engine

A deterministic compliance engine that proves its own citations, written in Rust, with AI to research what the database doesn't already know

Rust because a compliance verdict must be deterministic and reproducible.

Forge is a compiled Rust compliance engine. The rule evaluation is deterministic — Rust is chosen because although it is more demanding of the software developer (), it produces output that is fundamentally more reliable. Rust compiles to native machine code with zero runtime overhead, enforces memory safety without a garbage collector, and catches errors at compile time that other languages discover in production. The same BOM checked against the same regime version produces the same result every time. The type system enforces evidence chain production at compile time — a function that evaluates a rule cannot compile unless it returns the evidence nodes that document its reasoning.

ndaa_889-r1
Banned
HiSilicon Technologies · Hi3559AV100
Compiled condition
entity.parent_chain CONTAINS_ANY ndaa_889_covered
Deterministic trace
1.resolve("HiSilicon Technologies")
→ hisilicon · deterministic exact match
2.parent_chain(hisilicon)
→ [ hisilicon → huawei ] · corporate ownership traversal
3.parent_chain ∩ ndaa_889_covered
→ { huawei } · set membership
4.CONTAINS_ANY(parent_chain, ndaa_889_covered)
→ TRUE · 1 member matched
5.result_type(ndaa_889-r1)
→ Banned · § 889(a)(1)(A)
ndaa_889_covered5 members
  • huaweiHuawei Technologies Co., Ltd.
  • zteZTE Corporation
  • hyteraHytera Communications Corporation
  • hikvisionHangzhou Hikvision Digital Technology Co., Ltd.
  • dahuaDahua Technology Co., Ltd.
Non-Compliant
Matched a covered entity via the corporate parent chain.
verdict signature 8ed74ba0dbebdfaf… · identical across 1 run

Deterministic: the same BOM produces the same verdict and the same Ed25519 signature every time — and every verdict cites the verbatim statute it relied on.

A rule evaluating against a component one step at a time: resolve the supplier, walk the corporate parent chain, test membership in the covered-entity set, reach a verdict. Each step is grounded in a source excerpt quoted verbatim and marked Verified. The same evaluation is then run a second time and produces an identical result under the same signed hash — which is the claim being made: the engine is deterministic, and it proves its own citations.

Powered by Veracity-Engine

Agent-driven statutory/regulatory verification and entity research where deterministic lookup cannot reach.

AI enters the pipeline at exactly two points. When a manufacturer name cannot be resolved deterministically through e.g., exact match, alias lookup, or phonetic encoding, an agent researches the entity, finds its corporate parent, and sources the relationship to a verifiable filing. When a cited authority cannot be found in the local database, an agent discovers candidate URLs on primary government sources, fetches them, and grounds the citation. In both cases, the agent's work is verified before it enters the system. The evidence chain documents what the agent found and where it found it. The determination is the engine's. The research is the agent's.

Veracity-Engine can discover and verify any legal authority from any jurisdiction on demand. The first user who triggers a lookup for an obscure Thai procurement regulation or a Wassenaar category definition pays the one-second network cost. Every user after that — across every organization — gets the verified authority instantly. The database doesn't need to know about a statute before someone asks. It learns on first contact and serves every contact after.

Powered by

Declared manufacturerline 31 · qty 40
"SHENZHEN HYT SCIENCE&TECH CO.,LTD"
Determination — the engineDeterministic. Signed.

normalization · exact / alias / phonetic · set membership · rule evaluation · verdict · Ed25519 signature

Research — the agentNever decides.

entity discovery when deterministic resolution fails · sourced to a verifiable filing · verbatim-gated

What happens when deterministic resolution fails. The declared supplier is "Shenzhen HYT Science & Technology Co., Ltd.", a former corporate name that exact matching, alias lookup and phonetic encoding all miss. An agent researches the name, finds the rename to Hytera Communications Corporation Limited — itself a covered entity under NDAA §889 — and sources the relationship to an exchange filing. Nothing the agent found enters the system until a verification gate confirms that filing text. The research is the agent's; the determination stays the engine's.

Powered by Veracity-Engine

Every citation is checked word for word against its source.

The Sovereign Library is a cross-tenant authority cache built on the citation verification methodology developed for Veracity-Engine. When the engine cites a statute, the cited excerpt must appear as a verbatim substring of a page actually fetched from the canonical government source. A model-authored or hallucinated URL or quote cannot survive the grounding and evaluation. A citation that passes grounding is stored as a verified, trust-tiered authority and reused across every subsequent check that references the same provision. The first lookup pays the network cost. Every lookup after it is instantaneous.

The source viewer shows a green ✓ Verified badge on every grounded authority, the verbatim excerpt with the relevant passage highlighted, and a direct link to the government publication. The user can read the statute themselves. The tool proves it cited correctly.

Grounding gate

a citation enters the record only as a verbatim substring of the fetched page

The head of an executive agency may not— (A) procure or obtain or extend or renew a contract to procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system; ... (f) DEFINITIONS.—In this section: ... (3) COVERED TELECOMMUNICATIONS EQUIPMENT OR SERVICES.—The term "covered telecommunications equipment or services" means any of the following: (A) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities). (B) For the purpose of public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities).

The engine never asks a model whether a citation is right. It fetches the canonical government source and tests whether the quoted text is present, character for character. A hallucinated URL 404s; a hallucinated quote returns -1. Neither can reach a verdict.

Two citations side by side, one genuine and one fabricated. The genuine one is the NDAA § 889(a)(1)(A) citation from a real check: its quoted excerpt is searched for as a literal substring inside the text of the page actually fetched from the government source. It is found, so it passes. The second is a model-authored citation whose quote does not appear in the fetched page anywhere. It is rejected, and the rejection is the state the demo holds on: a hallucinated quote or URL cannot survive the check.

Powered by Veracity-Engine

Signed and tamper-evident.

A report generated today can be independently verified two years from now without contacting Forge or Blecher Group. The Ed25519 digital signature proves the document has not been modified since generation. The hash chain computes a cryptographic fingerprint of every element in the report — each verdict, each evidence node, each source citation, each disposition — and combines them into a single root hash embedded in the signed certificate, so that altering any single element invalidates the entire chain. The hash chain covers the evidence tree, the source citations, and every disposition recorded against the findings.

Priced to your program

Put your next BOM through Forge.

Create an account, upload a bill of material, and get a signed, evidence-traced compliance report you can defend.

Your BOMs are never retained beyond your account, never shared across organizations, and never used for training.

Forge uses a small number of cookies to keep you signed in and remember your interface preferences. Essential and security cookies are always on. Optional, non-essential analytics cookies stay off until you accept. Forge sets no third-party advertising cookies and does not sell your data. You can change your choice any time from Cookie Preferences. Privacy Policy