# AnyForge — The Agentic Software Delivery Platform # https://anyforge.ai # Full reference for LLM crawlers and AI assistants AnyForge is the agentic software delivery platform: end to end, from discovery to delivery, with every step audited. Product signals become RICE-scored opportunities, opportunities become roadmap themes and spec-verified initiatives, and specs become shipped code — without leaving the platform. Delivery runs three ways over one governance layer — AnyForge Control (a governed LLM proxy for teams using their own agents: Claude Code, Cursor, Cline, Continue, or raw SDK clients), AnyForge Code Studio (a browser-based agentic coding workspace with governance built in), and AnyForge Crew (governed multi-agent delivery with one mandatory human approval gate at PR review) — surrounded by a full engineering-organization platform: product planning, spec-driven development, leadership insights, a workspace-grounded AI assistant (the Oracle), integration and skills marketplaces, observability and incident management, coverage ingestion, source-code escrow, and living architecture documentation. Cost analytics, intent routing, portable memory, and a hash-chained audit trail are shared across every surface. ## Company Overview - Name: AnyForge - Website: https://anyforge.ai - Founded: 2025 - Founder: Edwin Poot (https://linkedin.com/in/edwinpoot) - Category: Agentic Software Delivery Platform - Tagline: The Agentic Software Delivery Platform — discovery to delivery, with every step audited - Brand verbs: enforce, prove, predict - Positioning: "The complete agentic engineering platform — from raw customer signal to merged, audited pull request. One platform, one ledger, one flat fee." ## Pricing (universal, all surfaces) - One flat per-million-token platform fee on tokens routed through AnyForge — provider-agnostic: the same rate whether you use Anthropic, OpenAI, Bedrock, Vertex, OpenRouter, or self-hosted/private models (Ollama, vLLM, llama.cpp, dedicated gateway). The exact rate is not published here — it is shared with design partners and platform accounts. - BYOK (bring your own keys): model spend bills directly to your provider under your own account. AnyForge never resells model capacity and never marks up provider usage. Platform fee and model spend are separate line items. - 100M-token free trial on signup (≈1–2 weeks of active dev use). - First Crew free: a one-per-company 20K-token Crew trial via Code Studio escalation. - No subscription, no seats, no credit packs, no plan tiers, no daily caps. - Only tokens that actually flow are billed — timeouts and failed calls never accrue. - Budget enforcement in the execution path: per-codebase and per-initiative token budgets, soft warning at 80%, hard stop at 100% (auto-pause + incident). - Prompt caching typically saves 30–40% of model spend; smart routing + caching typically save more than the platform fee costs — the net effect is savings. - Monthly Stripe invoicing; automated dunning aligned with Stripe Smart Retries. - Enterprise SKU: same per-token rate on an annual contract (procurement instrument) — NET-30 invoicing, SOC 2 attestation, dedicated support, audit-log retention guarantees, SSO, optional self-host. - Crew Managed Service contracts sold separately as a managed dev pod, anchored on offshore-engineer equivalence; these also accrue the per-token fee (dual revenue per customer). ## Products ### AnyForge Control (bring your own agent) - URL: https://anyforge.ai/control - Category: Governed LLM proxy and AI control plane - Install: `npx anyforge init` — 4 steps, ~5 minutes. Detects Claude Code, Cursor, Cline, Continue, or a raw SDK client and rewrites config. Mints a scoped AnyForge API key. Features: - SDK-compatible drop-in endpoints: POST /v1/anthropic/messages and POST /v1/openai/chat/completions with `Authorization: Bearer sk_anyforge_…`. Existing client code migrates by changing one base URL. - Providers: Anthropic, OpenAI, Google Gemini, OpenRouter (200+ models), AWS Bedrock, Google Vertex. - Private & self-hosted models: route to your own Ollama daemon, a vLLM or llama.cpp cluster, or a dedicated private LiteLLM gateway deployed in your VPC, on-prem, or air-gapped — for regulated, data-residency-constrained, government, and defence deployments. Open-weights traffic can route direct to the vendor, bypassing marketplace markups. - Open-weights model support: GLM-4.6, GLM-4.5 Air (Zhipu), DeepSeek V3, DeepSeek R1, Qwen 2.5 Coder, Llama 3.3, Mistral Large, Grok — first-class, selectable for any agent role and routing target. - Per-call, per-agent, per-project cost and latency analytics with dimensional rollups; alerts at configurable thresholds. - Intent-based routing (rules, regex, or embedding-based) to the cheapest model that meets the quality bar; price-intelligence recommendations per agent role. - Portable memory that survives provider switches. - Hash-chained, signed audit log of every prompt, response, and tool call. - Optional OPA/Rego policy enforcement: redaction, budget caps, PII blocking, allow-lists, rate limits — activated per rule. - Claude Max OAuth routing (beta): accepts sk-ant-api-… (metered API) and sk-ant-oat-… (minted by `claude setup-token`, billed against a Claude Max/Pro subscription). Self-pacing throttle against Anthropic's rolling 5-hour/7-day utilization windows (soft pace at 80%, hard block at 95%), 1-hour extended prompt-cache TTL, live quota meter, automatic 429 fallback to a metered key, company-level policy disable. Note: Control is ALSO native inside AnyForge Code Studio and AnyForge Crew. If you use either, you already have Control's feature set. ### AnyForge Code Studio (turnkey browser coding) - URL: https://anyforge.ai/code-studio — Try free: https://crew.anyforge.ai/studio - Category: Browser-based agentic AI coding workspace Features: - No install: full workspace in the browser with Files / Diff / Terminal / Metrics tabs; installable as a mobile PWA. - 200+ AI models via OpenRouter plus every provider above; switch per request. - Native GitHub integration: commit and push from the browser; main-branch locking by default; commits authored with the operator's own GitHub identity. - Quality-first flow: classifies directives vs inquiries, writes failing tests before implementing fixes, produces repo-grounded plans and surgical edits. - Built-in terminal with dual execution backends: an in-browser WebContainer, with automatic failover to the cloud agent runtime when the browser can't host it (mobile/Safari) — builds and tests run even from a phone. - Semantic code search and a cross-repo code graph shared with every agent surface. - ~50 agent tools, including: full terminal execution, live web search and fetch, headless-browser verification (auto-starts the dev server, screenshots the page, reports console errors and failed network requests, desktop/mobile viewports), read-only research sub-agents with isolated context and hard budgets, plan mode, git-worktree isolation, line-anchored inline PR reviews, PR create/update/merge/ approve, persistent typed agent memory, and a coverage-measuring test runner. The Studio agent can also connect GitHub repositories and kick off their Phase-1/Phase-2 codebase analysis directly from the conversation, and builds UI to your organization's design system (root DESIGN.md and managed brand assets). - Durable streaming: an interrupted agent stream replays on reconnect. - Skills and MCP tools compose into the agent's capabilities. - Governance native: every call flows through Control — cost analytics, intent routing, portable memory, hash-chained audit built in. - Compact live-presence avatars identify teammates viewing shared Crews and Architect decompositions without exposing private Solo sessions or repo context. - One-click escalation to Crew via the propose_crew tool: initiative, work items, and crew created atomically; the user stays on the same conversation and approves HIL gates in-thread. ### AnyForge Crew (governed multi-agent delivery) - URL: https://anyforge.ai (pilot access via #pilot form) - Category: Governed multi-agent engineering delivery - Status: Pilot phase, accepting applications; Crew Managed Service contracts available. Architecture: - Built on LangGraph StateGraph with Firestore-persisted checkpoints — every run resumable, replayable, and auditable at graph-state level. - Hub-and-spoke "One Engineer" model: a single capable Engineer agent (up to 80 tool rounds) drives the build — reads code, applies patches, runs tests, opens the PR — consulting read-only specialists (Architect, Security & Compliance, QA, Sage) on demand. Designed against published multi-agent handoff failure rates of 41–87%. - Deterministic edits: apply_patch runs `git apply --check` then `git apply`; stale diffs are rejected loudly, never fuzzy-matched. Anchor/file rejection caps and a hallucination guardrail (3 rejections → escalate) stop silent loops. - run_tests auto-detects the project's test runner (.anyforge/test-command pin, package.json, pytest, Cargo, go.mod) and is treated as ground truth. - Read-only context repositories: dispatch a crew with sibling repos mounted read-only — the Engineer and specialists read cross-repo code, contracts, and patterns (a shared library, an upstream API producer, a design system) while every edit and the PR stay confined to the single writable target repo; the read-only boundary is enforced at the tool layer. - Structural (AST) code search alongside semantic search: an ast_search tool gives the Engineer and reviewers ast-grep-style structural pattern queries over the live worktree, not just string or semantic matches. - Integration validation for third-party APIs, payments, and webhooks: crews build and verify real HTTP/REST integrations against a live sandbox or staging environment without ever holding provider credentials or egress. A typed run_integration_test tool returns normalized evidence (status, artifacts, logs, webhook confirmation); the crew can instead trigger the flow itself under an egress allow-list with server-side credential injection and confirm the async webhook through a connected observability MCP (Datadog), with an internal Slack test-bot bridge as the zero-infrastructure fallback. The architect validates the provider's real API at decomposition time; the provider's real response and webhook evidence attach to the PR-review card, and a failed integration check holds Approve behind an explicit operator override. A block-reflex guard forces the crew to try the validation paths before it may declare the task blocked. - Scoped local runtime validation: the Engineer starts a worktree-scoped dev server, drives localhost HTTP paths, and captures headless-browser evidence — screenshots, console and network errors — with no public tunnel; the bounded runtime evidence and latest verified preview attach to the PR-review card, so a UI or endpoint change ships with proof it actually ran. - Monorepo migrations: dispatch a crew to migrate source paths from a source repository into a target monorepo — copy, history-preserving, or subtree import strategies — with the migration scope threaded through decomposition, dispatch, and PR review like any other governed work. - On PR open, Architect / Security / QA specialists review the diff in parallel — OWASP-class security findings, coverage analysis, architectural conformance — and attach reports to the approval card. Overlapping findings are consolidated into one evidence-backed item per underlying issue across reviewers. - One mandatory human-in-the-loop gate at PR review: approve / amend / reject. Amend re-enters the Engineer on the same branch with feedback — which also carries through to the parallel specialist reviewers on re-review — and a no-new-commits amend round halts loudly. The Approve gate is enforced server-side on every path — chat card, control API, and Approvals queue re-read the PR's live GitHub checks and refuse to land an approval while CI is red, pending, or the branch is in conflict (the control API returns 409); the CI verdict at approval is recorded in the audit trail, and a completed-but-failing check ships only through a conscious, recorded override. - The autonomy dial (configured in Settings → General, off by default, each envelope requiring the previous): (1) CI-failure triage on bound branches; (2) unattended CI auto-fix with hard caps (bounded fix rounds and a token ceiling per attempt); (3) auto-merge for small fixes only (configurable line and file limits); (4) Release Health auto-heal for failed releases inside an operator-defined safe-path glob allow-list with a max-LOC threshold and capped attempts per release. Auto-merge-on-approval defaults cascade org → program → initiative → individual gate, with explicit opt-out at every level. Everything above an envelope waits for a human. - Release Health (opt-in per company): when a deployed PR's CI fails, a hotfix work item auto-dispatches; PRs fitting the configured safe-diff envelope auto-merge without operator review. Everything else falls back to the normal gate. - Enforced coverage gate (opt-in per codebase): when a PR-head coverage measurement falls below the codebase threshold, the crew holds the ship (coverage_below_threshold) instead of offering the approval card — a required "> N% coverage" criterion can't ship on a self-attested number. Fail-open and default off. Merge-blocked PRs (auto-merge refused by branch protection or required reviewers) are flagged on the work item and initiative until the change actually lands on the base branch. - Per-run model control: dispatch with organization defaults, a reusable profile, or a one-off configuration that pins the provider and model for each Crew role. One-off configurations are immutable run snapshots; they do not change company defaults or create reusable profiles. A reasoning-level control (low → max) is set alongside the provider/model per role and maps to each provider's native reasoning field. - Model benchmarking (/benchmarks): run one work item across two per-role run profiles (Profile A / Profile B) as two isolated arms, each on its own seeded branch — neither arm can auto-merge or mutate the source work item. Launch is from the work-item Dispatch modal ("Benchmark two profiles"), guarded by a per-run token budget (100K–5M) whose ×2 aggregate the operator confirms up front. When both arms reach a decision, a deterministic recommendation ranks them by a fixed priority — run outcome → test outcome → open reviewer findings → cost → token spend → duration — and the first differing dimension picks the winner (else "no deterministic winner"). The side-by-side report shows each arm's tests, open findings, duration, tokens, cost, and diff with a PR link. The recommendation is advisory: the operator clicks "Use this output" to select an arm (recorded, not merged — reviewed and merged through the normal GitHub flow), and a failed or halted arm can be retried in one click. - Operator run experience: a live activity feed with a three-phase pipeline tracker (Engineer → Specialist Review → PR Review), typed interaction cards (plan approval, QA approval, agent questions, typed questions, task proposals, backlog refinement, ADR revisions), @architect mentions in the thread, and desktop notifications when a gate needs a decision. Every PR opens in a three-pane review cockpit: AI-generated walkthrough touring the diff in reading order, syntax-highlighted diff with click-to-comment on any line (posted to GitHub and in-app with @-mentions), and agent chat with approve / amend / auto-merge inline. - Automations/routines: saved crew templates dispatched on cron or signed webhooks (HMAC-SHA256, GitHub-style X-Hub-Signature-256), e.g. nightly security audits, weekly tech-debt refactors. Run Now confirms with a toast linking to the crew it created, and each routine card links to the crews it dispatched (a routine= filter on /crew) so the audit findings are one hop away. - Operator Workflows: declarative, versioned multi-step orchestrations — agent, deterministic-tool, parallel, map (bounded fan-out), bounded loop, human-gate, and crew steps with {{...}} templating and `when` condition guards — compiled onto the same Firestore-checkpointed LangGraph runtime as crews. Runs are durable (survive restarts, pause indefinitely at gates), token- AND cost-budget-enforced (budget exhaustion pauses the run resumably — an operator tops up the cap and continues rather than losing the run — and every spec edit is an immutable version with roll-forward rollback), role-gated (editors author, operators run/decide), and dispatchable from the Console, the key-authenticated control API, MCP tools, cron or signed-webhook Routines, or automatically when an accepted observability signal matches a flagged workflow (the signal's fields arrive as declared inputs). A crew step dispatches entire governed crews (engineer → review fan-out → HIL) per fleet item and the run resumes as each finishes; gates appear in the same approvals inbox as crew gates, offer approve / amend (send the previous step back with guidance) / reject, and push Slack, in-app inbox, and email so a waiting decision reaches the operator anywhere. Specs are authored conversationally with Workflow Genesis — grounded in the live spec and validated with the exact validator the runtime runs — with the JSON editor as the escape hatch. - Automatic merge-conflict resolution: a 30-minute sweep detects cross-work-item conflicts, attributes them to sibling branches, and resolves automatically where mergeable — or dispatches a resolution crew that merges (never rebases), runs tests, and updates the PR in place. - Workspace bootstrap: agent runtime ships Node, Python, Go, Rust, Java (Maven/Gradle), Kotlin, .NET, Ruby, PHP plus gcloud/aws/az/terraform CLIs; honors committed .anyforge/setup-command and test-command pins and reads AGENTS.md / CLAUDE.md conventions (as untrusted context). - Named halt taxonomy with documented recovery actions (engineer_no_pr, coverage_plateau, runaway_steps with a hard 3,000-round ceiling, token_budget_exceeded, …) and an LLM-authored PR Walkthrough per head SHA. An externally-halted run (token-budget breaker, operator halt, HIL rejection) preserves its authoritative halt reason instead of being overwritten by a generic "no PR" banner or auto-pushing a PR on a cancelled crew. A PR-aware circuit breaker: if a step or token-budget limit trips on a crew that has already opened its PR, the run degrades to a resumable PAUSED with its checkpoint and PR intact rather than a terminal halt — finished work is never stranded at the breaker. - Read-only audit crews have a finish line: a compliance/security/PCI audit run writes its findings document (docs/spikes/.md) and opens a PR, so it ends on a deliverable instead of only by cutoff or halt. - Retrospective Analyst: operator-triggered retro over a crew or whole initiative — reads the step trail, audit log and validation outcomes, produces a retro report and proposes new memory facts (human-promoted, never auto-enforced). - Mid-flight intelligence: the architect can propose new tasks or ADR revisions mid-run; non-destructive replans reshape in-progress initiatives; backlog refinement on request. - Self-healing operations: circuit breakers, auto-resume for stalled crews, hourly credential-health probes, MCP OAuth token refresh, HIL/agent-question timeouts that never auto-approve, and a 15-minute platform smoke sweep. Governance: - Hash-chained, append-only audit trail: every governance event SHA-256 hashed over content + previous hash; audit collections are write-forbidden to application clients at the database-rules layer. - Cryptographic approval proof: approver identity + timestamp + content hash per HIL decision, exportable. - Atomic Facts (enforced constraints): TLS, API contracts, schema invariants, compliance mandates injected into every agent prompt and verified per-constraint at PR time. PCI-DSS / SOC 2 / HIPAA profiles seed at onboarding. Facts are never deleted, only superseded (versioned chain). - Policy as code: OPA + Rego policies (cost caps, circuit breakers, per-role tool allow-lists) distributed via OPAL. Role-locked tools: the Architect cannot execute bash; the Engineer cannot skip gates. - Untrusted-context sentinels around repo instructions and BRD text defend against prompt injection; repo content can never override enforced constraints. - Portable governance memory: architecture decisions, API contracts, declined proposals persist across runs, sessions, and provider switches — policy-checked, fail-closed, tenant-isolated, signed into the audit chain. ### AnyForge Oracle (workspace AI assistant) - Floating assistant on every console page (⌘-J), available to every member including viewers; read-only by default and, in the Console, never budget-gated. - Answers platform how-to AND workspace questions — programs, initiatives, crews, releases, incidents, code — grounded in real data with clickable deep links (every entity it presents links to its Console view by default), and its workspace reads carry live delivery context (crew status, pending gates, budgets, blockers) so answers reflect what is actually happening right now; also handles general reasoning/writing/research asks. - Crew-pinned decision support: from a HIL approval card or a halted/paused run banner, "Consult the Oracle" opens it pinned to that crew, hydrated server-side with the run status, task, repo, PR, budget, stop reason, reviewer verdicts and the pending gate — for merge-safety, blast-radius and halt-diagnosis advice right where the decision is made. It advises with an evidence-based risk posture; it never rubber-stamps. - Confirm-first operator action tier: for operators (role re-checked server-side) the Oracle can act on what it finds — dispatch / amend / halt / resume a crew, approve a HIL gate or task proposal, dispatch the architect, and close an already-delivered run as delivered (naming the work item and initiative, and collapsing the stale "action needed" card), and connect GitHub repos and kick their Phase-1/Phase-2 codebase analysis — including fanning Phase-1 across a whole org with a dry-run preview — each step confirmed first. Benchmark and integration-validation runs are refused. - Person-scoped delivery activity: ask what one operator shipped, delivered, and which gate is holding them up ("what did I ship last week?", "what's blocking Priya?") — grounded in the record, self-reporting open to everyone and colleague queries gated to owners and operators; it reports what happened and says plainly that intent has to come from the person. - 360° codebase view correlated with production reality: reads connected observability systems live (Datadog, Sentry, Google Cloud Logging, Crashlytics, AWS CloudWatch, Aikido security findings) and correlates a production error with the code path that throws it, the release that shipped it, and the PR that introduced it — then can hand off to a fix crew. - Semantic doc search, entity resolution, code-graph queries, telemetry helpers. - run_code: a credential-isolated, network-less Python/Node sandbox for real computation inside a conversation — parse, aggregate, calculate, chart. - Exportable answers: Markdown, JSON, CSV, HTML, DOCX. Per-user memory. - ⌘K global search: Spotlight over everything, an instant catalogue tier that matches generated codebase docs by title, type, and repo (runbooks, data models, threat models), plus a semantic deep tier from the indexed code. - Also reachable headlessly: the anyforge_ask_oracle MCP tool, the /oracle Slack slash command, and @AnyForge mentions in a Slack channel (answered in-thread; opt-in per company because the reply is public) share one server-side runner. - Runs on the customer's own AI key (BYOK). ### Product planning layer (above delivery) - Signals: raw demand capture (client / sales / stakeholder / internal / strategy sources); never deleted, source travels downstream. - Opportunities: triaged, typed (FEATURE / ENHANCEMENT / TECH_DEBT / KTLO / BUG), staged (IDEA → VALIDATED → READY_TO_PLAN → PLANNED → SHIPPED → MEASURING), with commercial fields (expected revenue, region, account). - RICE scoring: (Reach × Impact × Confidence) ÷ Effort, server-recomputed from anchored buckets with required rationale on all four inputs; Effort measures operator attention (the real bottleneck), Impact anchors to a company goal metric; AI Suggest drafts scores grounded in the signals. - Revenue at Risk: monthly MRR blocked by unshipped work, annual run-rate, concentration by region/account/reason, new-business vs expansion split. - Roadmap Themes: Now / Next / Later horizons, OKR anchors, investment-mix guardrails (e.g. 60% feature / 25% tech debt / 15% KTLO), quarter timeline with drag-to-reschedule. - Capacity: span-of-control math over operator review attention; measured HIL cadence, Review-Quality-Index, context-switch penalties; Little's-Law lead times and Monte-Carlo P50/P85/P95 forecasts over the trailing 8 weeks; what-if simulator (add operators, raise autonomy, fewer crews). - Spec-driven development (ICE): every initiative carries Intent / Context / Expectations with observable acceptance criteria and explicit non-goals; a deterministic (no-model) readiness rubric gates dispatch; the PR carries the spec snapshot and is checked against the criteria, including "verify NOT introduced" non-goals. Spec-first auto-refine at the ship gate (default; a plain-severity floor is the alternative mode) reads the reviewers' per-criterion ICE alignment and decides refine vs ship: unmet acceptance criteria refine regardless of finding severity, a spec that is met but carries an open CRITICAL still refines the critical, a spec met with no criticals ships and files remaining in-scope HIGH/MEDIUM findings as one follow-up work item (a critical never rides that exemption), and genuine drift or unverifiable alignment falls back to a human. Both the program brief and each initiative spec are hard-gated at plan approval: the architect's plan cannot be approved until ICE scores exactly 100% (a below-bar approval returns a 409 with the score and the specific gaps). Genuinely simple items waive optional sections per-field (required substance never can), and an owner-only "Approve anyway" override waives the gate with an audit event. - Program Brief (ICE): every program carries one always-structured brief — intent, context, expectations, dependencies, assumptions, non-functional and compliance requirements, non-goals — scored by the same deterministic ICE readiness rubric as initiative specs, with a live readiness chip and one-shot Improve/Suggest passes to close gaps. It is the single spec-driven-development entry point; Program Genesis interviews the operator to 100%. Briefs and specs are commentable inline — Google-Docs-style margin threads on wide screens (composer at the selection, collapsed author/time bubbles), with an inline fallback on mobile. - Work hierarchy: Programs (cross-codebase portfolios) → Codebases → Initiatives → Work items (one PR each) with dependency waves; initiatives are bounded (delivered once, terminal integration-validation on close) or long-lived (ongoing, skipping the terminal validation to absorb a continuing stream of work); program cockpits with KPI tiles, risks, blockers, a cross-initiative dependency map you can dispatch crews from, and PDF/Markdown export. - External blockers: operators can mark an initiative "Blocked" on an outside dependency (client sign-off, vendor credential, partner API) as an orthogonal overlay — delivery status is preserved and unblocking resumes exactly where work stopped (distinct from a crew halt) — and a blocked-initiatives report groups everything waiting on someone else, by program, on the Delivery view. - Business Capability Map: BIZBOK-style L1→L3 capability tree synthesized from the codebases themselves; heatmap badges expose gaps (0 owners) and likely duplication (4+); exports to Markdown/PNG/PDF. - Value Chain: a board-legible Porter Value Chain projected from the Business Capability Map onto a fixed scaffold — primary activities (inbound → operations → outbound → marketing/sales → service) with support activities (firm infrastructure, technology, HR, procurement) beneath. Derived from the map, not re-synthesized, so the two stay consistent by construction; each stage inherits the map's coverage badges so capability gaps (0 owners) and duplication (4+) read directly on the value-chain frame. Capability areas fold open to their L2 sub-capabilities and realizing codebases; both surfaces name and attribute the framework in-context (Porter; BIZBOK). Exports to Markdown/PNG/PDF. - Genesis agent family (conversational planning specialists): Opportunity Genesis turns signals into versioned PRDs with browsable, responsive, whole-product HTML UI mockups (every page, in a dedicated popout-able Mockups tab, offered proactively when customer-facing UI is in scope); Program Genesis proposes program scope, creates initiatives, interviews the operator to a structured ICE-scored Program Brief (versioned), manages risk registers and generates status reports, and reconciles externally completed work through separately confirmed, audited work-item and initiative close-out actions; Spec Genesis drafts and refines initiative specs and dispatches the architect; both Program and Spec Genesis can halt a running crew whose plan they are reshaping, behind an explicit confirmation; Report Genesis builds live dashboards. The intake front door adapts to how the operator thinks — product, technical, or business — and reorders the scoping interview to that altitude. Programs export to Markdown/PDF. - Community request board (/community): a public intake and roadmap-transparency surface. Users file bugs, features, and enhancements — attaching a screenshot as evidence — through an Oracle-guided, ICE-gated intake; Submit unlocks only at a complete Intent / Context / Expectations (a hard readiness gate re-checked server-side). Reporter metadata (name, email, uid, company) is captured on the work item but never leaves the server. An "Explore" tab shows an anonymized global feed (pseudonymized authors; sortable Top / New / Trending) and a "My Requests" tab tracks the caller's own with a tracking code and ICE score. Public request states map friendly stages onto internal work status — Received → Under review → Planned → In progress → Shipped, plus an off-path Declined — so sprint mechanics never leak. Upvoting is optimistic and locked (client- and server-side) once a request reaches a terminal state (shipped/declined). A filter-independent delivery-pulse strip shows four aggregates: open requests, crews working now (in progress), shipped in the trailing 30 days, and the median calendar days filed→shipped. Every request is a real work item in one shared intake company, so a suggestion a crew picks up becomes "In progress" and a merged one becomes "Shipped"; the feed exposes only a sanitized projection (title, summary, pseudonym, votes, ICE) and never the description, author, or company. ### Insights & operations console - Management Overview: deterministic leadership brief — what shipped, what was decided, committed vs forecast vs variance dates (append-only history), honest change-failure rate from tracked incidents; printable board pack; optional weekly brief email. - Custom Reports: dashboards built by chatting (Report Genesis) — stat tiles, timeseries, bar, table widgets over crews, work items, initiatives, usage, codebases; executed live at view time. Reports share via a company-scoped deep link and export to PDF or Markdown. - Delivery analytics: cost per completed crew (the headline metric), deployment frequency, lead time (median + p90), change-failure rate, MTTR, first-pass acceptance-criteria rate, amend rounds per initiative, plan/QA rejection rates, and token forecast-vs-actual — pivotable by operator, initiative, codebase, work item, program, or team. - Operator effectiveness: a composite 0–100 score per operator (outcomes 40, cost 20, spec quality 15, responsiveness 15, context reuse 10) with tiers and per-operator coaching notes. - Usage & billing: month-to-date token spend, model spend, AnyForge fee, and projected month-end by user, initiative, provider, model, repo, and product surface; per-run billing-weighted token percentiles (p50/p75/p90/p95). - Traces: full LLM trace waterfalls and span trees per crew run and Studio session, with three lenses (recent / highest-spend / errors), period and source filters (Crew / Code Studio / Control external-agent), readable initiative/work-item labels with stable deep links, dimensional tags (initiative, role, model, ticket, portfolio company), and opt-in run-tree tracing that nests every LLM round under its graph node. - Two-ledger spend reconciliation: AnyForge's metered ledger reconciled against each provider's own usage API (Anthropic, OpenAI, Google, OpenRouter) with leakage surfaced per provider, model, and day. - Audit view: range + event-type filtered ledger (fifteen event types, from sign-ins and API-key use through node transitions, HIL decisions, circuit breakers, fact writes, and compliance violations) with raw payloads, full hashes, and deep links; reconstruct enforced constraints at any past moment. - Platform Health: 30-second live refresh, configuration preflight with fix hints, smoke-test heatmaps, halt taxonomies, active crew counts. - Incidents: manual, release-captured, and observability-ingested incidents with severity and customer impact; drives stability metrics; a crew can be dispatched to fix an incident directly. - Production Watchdog (managed, opt-in per company): a standing production-observability agent. On a cadence (default every 6 hours, hourly heartbeat) and reactively on newly accepted signals, each pass deterministically diffs the company's ingested observability signals against the previous run's fingerprint snapshot to surface what is newly wrong — new issues, occurrence spikes, severity increases — then has the headless Oracle explain the why against the company's connected observability MCP servers (the numbers are copied verbatim; the model only adds prose). It delivers a digest to the notification bell plus opt-in Slack and email and, when enabled, auto-files critical anomalies as KTLO incidents through the same accept path an operator would use — or, in suggest mode, leaves them as open signals to triage. Configurable cadence, severity floor, quiet hours, delivery channels, auto-file policy, and a dedicated company-key enrichment model (deterministic detection needs no model). Every pass — including a manual "Run now" that found nothing — writes an audit record with per-run diagnostics (signal count, baseline status, anomaly count, trigger), so operators can prove it ran. Configured from /workflows/watchdog, reached via Playbooks → Manage. - AnyForge Playbooks: a browse → enable → customize library of bundled operational templates. The featured managed Production Watchdog plus workflow Playbooks — Cost Anomaly Watch, Release Health Report, Security Findings Triage — ship as pre-built Operator Workflows. Enabling a workflow Playbook clones it into the org disabled (tagged with its playbook provenance) and opens it in the editor to customize; re-enabling dedupes to the existing workflow and the gallery shows an Enabled badge with Open/Manage. Workflow Playbooks reach live production state through an ask_oracle workflow step — the tool that relays to the headless Oracle so a running workflow can query connected observability MCPs before it acts. - Code-intelligence graph index: a continuously refreshed call-and-import graph of every connected codebase (TypeScript compiler API for TS/JS, tree-sitter for Go/Kotlin/Python/Java/Rust) plus vector embeddings of symbol-aligned code chunks for cross-repo semantic search. SHA-gated incremental indexing refreshes on every PR merge, operator demand, and a rolling sweep. Every call edge carries a confidence label (extracted / inferred / ambiguous). Each pass runs graph analysis: god nodes, module communities, surprising connections, doc-to-code drift, suggested questions, and structural deltas between runs. One index powers the Engineer, PR-review specialists, the Oracle, semantic global search, and interactive per-repo + cross-repo Code Graph views. - Documentation engine (living architecture docs): deep reverse-engineering analysis when a repo connects, then kept current by an always-on pipeline — the same merged-PR webhook that reindexes the code incrementally patches the affected docs (SHA-gated on a doc watermark, changed files deterministically mapped to doc types via path rules and the code graph, one bounded LLM edit per affected doc with version++ and an audit entry, patched-doc embeddings re-upserted; oversized diffs reconcile with a full pass), on top of the opt-in scheduled reanalysis cadence. Generates C4 context/container/component diagrams, ADRs authored by the architect agents as they work, an L1 deployment topology with component-to-component dependency arrows and relationship overlays, cross-repo dependency maps, Conway analysis (org chart vs architecture), a per-codebase AI-readiness score, a security-posture view, and documentation gap analysis. - DORA metrics & governance correlation: lead time and change-failure rate per codebase and portfolio, plus a correlation view that empirically ties HIL-override decisions to later failures — governance you can measure. - Cloud & provider cost intelligence: GCP cost sync with per-service and per-SKU drill-downs (30/60/90-day charts), and reconciliation that pulls real spend from Anthropic, OpenAI, Google, and OpenRouter to verify metered usage. - Notifications: four channels — in-app inbox with @mention tracking, email, Slack DM, Discord — with per-event preferences; HIL approval alerts carry severity; Slack slash commands (/oracle to ask, /signal to file demand) and @AnyForge mentions answered in-thread by the Oracle. - Portfolio view for PE operators: crews, spend by surface, approval decisions, velocity across portfolio companies, each in an isolated tenant. - Releases & changelog: on a version-tag push, AnyForge auto-generates redacted, customer-safe release notes (new/improved/fixed, secrets scrubbed), publishes a release timeline and changelog UI, and announces to Discord; shipped user-reported items are announced per type. Routine merged feature work can auto-cut an annotated release tag (Conventional-Commits versioning) so notes publish continuously, not only on manually pushed version tags. SemVer tags sync from tracked codebases automatically. - Org narrative: a background worker synthesizes a business-readable, org-wide documentation home page across every analyzed system; documentation pages support external share links and full-text search. ### Integrations & extensibility - Universal MCP support (inbound): AnyForge speaks the Model Context Protocol natively — connect ANY MCP server over Streamable HTTP or SSE, authenticated with OAuth (tokens auto-refresh in the background), Bearer tokens, API keys, or no auth; scoped per-user or company-wide. Connected tool surfaces flow to the Oracle, the Genesis agents, and (with permission) crews. Read tools are broadly available; mutating tools are operator-gated with confirmation. A mid-session credential lapse self-heals on the next call, and an unrecoverable one surfaces a one-click reconnect link instead of failing silently. - MCP integrations marketplace (one-click connectors for the popular ones): GitHub, Datadog, Sentry, Jira, Confluence, Linear, Notion, Salesforce, Stripe (the vendor's full API, plus an AnyForge-hosted read-only Revenue & Payments surface: customers, subscriptions, invoices, failed payments, disputes, payouts — GET-only, so no write to gate), Cloudflare, CloudZero, AWS Cost & Billing (FinOps), Snowflake (Cortex Analyst, Cortex Search, and SQL over your governed warehouse), Databricks (lakehouse ops — jobs/runs, pipelines, warehouses, query history, Unity Catalog), Google Drive, Google Calendar, Microsoft 365, Firebase Observability (App Hosting/Functions logs, Crashlytics), Aikido Security. Custom and internal MCP servers plug in the same way. - Skills marketplace: reusable prompt packs composed into every agent's system prompt; scope by toolchain (go/python/rust/java/kotlin/ruby/dotnet/node) or codebase; import SKILL.md; curated third-party registries pinned to immutable commits; auto-detect skills committed in your repos. Ships with a bundled library of AnyForge engineering-discipline skills — planning, code review, security/compliance scanning, deploy and QA practice, with deterministic guard scripts — advertised to crew agents by role and phase, tiered core/optional per company and scoped to your repo languages. - Organization design systems: AnyForge reads a repository's root DESIGN.md as the visual source of truth for every agent (machine-readable tokens plus guardrails), falling back to an org-wide default design system you manage in the console, and resolves managed brand assets (logos, imagery) into the same design context. Code Studio, the Genesis UI-mockup generators, and crews all build UI to your real visual identity — validated on write — so agent output looks like your product, not a generic template. - AnyForge MCP server (outbound): ~50 anyforge_* tools for Claude Code, Cursor, or any MCP client — dispatch/amend/halt/resume crews, approve HIL gates, manage work items, initiatives, programs, opportunities, signals and themes, query the Oracle, sync coverage, drive escrow, refresh repo analysis. stdio via `npx @anyforge/mcp-server` or hosted Streamable HTTP at https://anyforge.ai/api/mcp. Scoped keys: read / write / approve. CLI device auth flow mints scoped keys into ~/.anyforge/credentials with a key management UI for listing and revocation. - Config Packs: one-click installable bundles of agent configs, enforced constraints (Atomic Facts), routines and skills that stand up a working governance posture in one action. Ten packs ship today, listed at https://anyforge.ai/platform#config-packs: - PCI-DSS — cardholder-data guardrails (encryption, TLS minimums, access logging) + a weekly Compliance/Security review of recent commits. - SOC 2 Type II — trust-services common criteria: logical access, change management, monitoring, backup-recovery testing + a quarterly audit routine over access-change logs. - HIPAA Security & Privacy — Security Rule technical and administrative safeguards for ePHI (encryption, unique user identification, audit controls, automatic logoff, minimum necessary, contingency-plan testing), the business-associate requirement, the Breach Notification Rule's 60-day clock, and a monthly §-cited safeguard report. - HIPAA + SOC 2 (Healthcare SaaS) — one cross-mapped control set where each constraint cites both its CFR section and the SOC 2 criterion it satisfies, so one piece of evidence answers both auditors. Install instead of the two standalone packs, not alongside them. - NIST Cybersecurity Framework 2.0 — the six core functions (Govern, Identify, Protect, Detect, Respond, Recover) as engineering constraints: asset inventory and SBOM, least privilege + MFA + encryption, security logging and detection, incident-response hooks, tested recovery. - NIST SSDF (SP 800-218) — the practice set behind US Executive Order 14028: code integrity and provenance, pinned well-secured dependencies, static review before merge, security testing, threat modelling, timely remediation, with review prompts citing practice IDs. - NIST AI RMF 1.0 — for AI/ML features: model and system cards, risk mapping, accuracy/safety/bias evaluation with metrics, human oversight, and hardening against prompt injection, data poisoning and model exfiltration + a quarterly AI-risk review. - EU Consumer Credit Directive 2 — Directive (EU) 2023/2225, fully applicable 20 November 2026, for BNPL and consumer-credit software: expanded scope, creditworthiness assessment, right to human intervention on automated credit decisions, SECCI disclosure, 14-day withdrawal, tying and unsolicited-credit bans. Engineering guidance, not legal advice. - Software Escrow — deposits buildable and operable by a skilled third party, a current dependency register, quarterly refresh and annual audit routines; pairs with the Escrow Bundle generator. - Startup — the velocity direction: feature flags over branch protection, tests required on shipped paid paths, a daily PR digest instead of a compliance audit, simpler architectures and cheaper default models. Packs seed normal, editable, operator-owned records and stack — constraints from several packs accumulate, each tagged with its source pack — while agent configs are keyed by role and do not merge (hence the combined HIPAA + SOC 2 pack). Company configuration exports/imports as a manifest for templating and backup. - Skills auto-detection: skills committed in your repos are discovered and offered for install; skills follow the open agentskills.io SKILL.md format with progressive disclosure (metadata in the prompt, bodies on invocation). - Control API: key-authenticated HTTP surface (/api/v1/control/*) covering repos, crews, initiatives, programs, work, approvals, coverage, themes, signals, opportunities, escrow, observability. - Observability ingestion: universal signal endpoint normalizing alerts from Datadog, Sentry, New Relic, Grafana, CloudWatch, Aikido, or any generic webhook into fingerprint-grouped production signals; accept → tracked KTLO incident, dismiss → noise. - Coverage ingestion: POST percent or raw lcov from any CI (Jest, pytest, Go, Java, C/C++); SonarQube, Codecov, Coveralls integrations; batch up to 200 items; coverage informs scope, tests remain the gate. - CI/CD: works with GitHub Actions, GitLab, Jenkins, CircleCI, Azure DevOps, Cloud Build on any cloud — plain HTTPS + bearer token; release-failure and release-success hooks close the fix loop; every PR ships DEPLOYMENT_NOTES.md. - Slack: OAuth app with channel picker, event subscriptions, HIL approval alerts with severity colors, DM notifications, /oracle and /signal slash commands. - GitHub: native auto-merge toggling, draft PR management, one-click repo and org-wide webhook installation (auto-installed on CI-auto-fix enable, Studio session create, or crew dispatch), HMAC-verified push/PR/check-run events driving HIL resolution and incremental code re-indexing, CI-failure ingestion with automatic fix-crew dispatch, repo snapshots and fleet-wide access verification. - CI deploy tokens: org-wide or per-codebase bearer tokens for release hooks — generate, rotate, revoke; hashed at rest, shown once. - Slack extras: Block Kit link unfurling for AnyForge URLs shared in Slack, channel picker, test alerts, per-team HIL alert subscriptions, @AnyForge mention answering. - OpenTelemetry: OTLP metrics endpoint and trace ingestion feeding the /traces browser. - Source-code escrow: per-codebase deposit ledgers with SHA-256 manifests, BUILD_AND_DEPLOY / INFRASTRUCTURE / DEPENDENCY_REGISTER / HANDOVER_RUNBOOK docs and masked secret scans; Replicate rehearsal proves deposits rebuild; SFTP delivery with host-key pinning to escrow agents (Escode/NCC) or manual download packs; quarterly fleet sweeps; scoping-answers reports generated automatically. ## Model support (complete) - Anthropic Claude: Fable 5, Sonnet, Opus, Haiku families — via API key or Claude Max/Pro OAuth subscription routing. - OpenAI: GPT-4o family, o-series reasoning models. - Google: Gemini 2.5 / 2.0 / 1.5 families (AI Studio and Vertex). - AWS Bedrock and Google Vertex for cloud-procurement alignment. - OpenRouter: 200+ models under one key. - Open weights, first-class: GLM-4.6 and GLM-4.5 Air (Zhipu), DeepSeek V3 and R1, Qwen 2.5 Coder, Llama 3.3 70B, Mistral Large, Grok. - Custom & private LLM hosting: your own Ollama daemon, vLLM or llama.cpp cluster, or a dedicated private LiteLLM gateway operated in your VPC, on-prem, or air-gapped — same governance, audit, metering, and flat platform fee as cloud models. Built for data-residency clauses, regulated industries, government, and defence. - Live per-provider model catalogs with per-provider failure isolation and automatic failover during provider outages. - Per-user credentials on top of company keys: a personal Claude Max OAuth token and a personal OpenRouter key per operator, plus a preferred-provider selector (or Auto) for one-shot platform calls. Credential-health sweeps flag expired or revoked tokens before a crew fails on them. - Per-model reasoning-level control (low / medium / high / xhigh / max) on the Oracle, the Genesis agents, and each Crew role — translated to each provider's native reasoning field (Anthropic effort with adaptive thinking, OpenAI reasoning_effort, Gemini thinking budget, OpenRouter reasoning), capability-gated so non-reasoning models are unaffected and clamped to the model's supported levels. ## Security & compliance posture - Hash-chained audit ledger (SHA-256 over content + previous hash), append-only, write-forbidden to application clients at the database-rules layer. - Cryptographic proof of every human approval decision. - OPA/Rego policy engine distributed via OPAL: cost caps (warn 80%, deny 100%), circuit breakers, per-role tool allow-lists. - Multi-tenant isolation via auth custom claims enforced in database security rules; defensive cross-tenant filters in the memory layer. - All customer credentials in Google Cloud Secret Manager; the database stores metadata pointers only, never values. - Repo access via each operator's own GitHub OAuth token (no shared PAT), with live scope preflights and hourly credential-health probes. - Sign-in: GitHub, Google, and Microsoft OAuth with invited-email allowlisting and pending-approval onboarding; multi-domain email auto-join (a company can claim several email domains so employees on any of them join the same org); role model with surface-locked board viewers. - Deploy boundary: AnyForge produces and merges PRs; it never deploys and never holds infrastructure keys. - Supply-chain discipline: dependency pinning against known-compromised versions; memory/telemetry self-hosted — customer tokens never routed to third-party analytics clouds. - Enterprise: SOC 2 attestation, SSO, audit-log retention guarantees, optional self-host. ## Key Differentiators ### vs. coding agents (Claude Code, Codex, Cursor, GitHub Copilot) AnyForge sits a layer above these tools — and is the only platform where one ledger governs your IDE agent, your browser agent, and your background crews: 1. Control governs existing agents from the outside (5-min install, SDK-compatible proxy). 2. Or replace them with Code Studio (turnkey browser) and Crew (governed delivery). 3. Planning, insights, audit, incidents, escrow — the engineering organization around the agent, which tool-level products don't attempt. 4. BYOK + intent routing: 3–10× cheaper than vendor-agent pricing. 5. Portable memory: switch providers without losing context or decisions. ### vs. observability proxies (Langfuse, Portkey, Helicone-class) 1. Watching spend is not governing it: AnyForge enforces — budgets that halt, policies that block, approval gates the model cannot skip. 2. A full delivery layer (crews, specs, releases, incidents) on top. 3. Governance is graph topology in Crew, not middleware. ### vs. agent frameworks (LangChain, CrewAI, AutoGen) 1. Frameworks give you primitives; you still build checkpointing, HIL, audit, cost control, and tenancy yourself — then maintain them forever. 2. AnyForge is that production harness, already built, already governed. ### vs. building in-house 1. Install in 5 minutes (Control) or sign in to a browser (Code Studio). 2. Routing, portable memory, policy engine, audit chain, escrow, capacity science — years of platform work you don't have to staff. 3. Continuous provider support (new models, new APIs) without engineering effort. ## Cross-Surface Interaction Model - Code Studio ↔ Crew: after escalation, Code Studio stays live on the crew conversation; every agent message streams in; HIL gates approved in-thread. - External IDE ↔ platform: the AnyForge MCP server exposes crew dispatch, HIL approval, work-item management, coverage sync, and the Oracle to Claude Code, Cursor, and any MCP client. - One operator console: cross-surface spend on /usage, unified audit schema, per-surface trace filtering. ## Technical Architecture (summary — full detail at /technology) - Orchestration: LangGraph StateGraph, Firestore-persisted checkpoints, interrupt()-based HIL. - Agent runtime: dedicated Cloud Run container image with all major language toolchains and cloud CLIs baked in; fresh git worktree per crew. - Code intelligence: call/import graph (TypeScript compiler API + tree-sitter for Go/Kotlin/Python/Java/Rust), vector embeddings for semantic code search, SHA-gated incremental indexing refreshed on merge; confidence-labelled call edges (extracted / inferred / ambiguous); god-node and community analysis. - Frontend: Next.js App Router + React + TypeScript; Code Studio uses in-browser WebContainers with cross-origin isolation and cloud failover. - Data & auth: Firestore (EU region), deny-by-default rules, Firebase Auth. - Memory: governed bi-temporal store (Zep-based), policy-checked, fail-closed. - Policy: OPA + OPAL; Rego policy library. - Model gateway: provider adapters + self-hostable LiteLLM gateway. - Billing: Stripe-backed usage invoicing, dunning, in-path budget enforcement. - Agent-discovery surfaces: llms.txt, llms-full.txt, RFC 9727 API catalog at /.well-known/api-catalog, RFC 8288 Link headers, JSON-LD on every page. ## Frequently Asked Questions Q: What is AnyForge? A: The complete agentic engineering platform: one governance layer consumed as Control (governed proxy for your existing agents), Code Studio (browser agentic coding), and Crew (governed multi-agent delivery) — plus planning, insights, marketplaces, incidents, escrow, and an in-workspace AI assistant. Q: Do I need Control separately if I use Code Studio or Crew? A: No. Control is the underlying layer and is native inside both. Install it standalone only to govern an external agent. Q: What AI models does AnyForge support? A: Everything: Anthropic (API or Claude Max OAuth), OpenAI, Google Gemini, AWS Bedrock, Google Vertex, 200+ via OpenRouter, open weights (GLM-4.6, GLM-4.5 Air, DeepSeek V3/R1, Qwen, Llama, Mistral, Grok), and custom/private hosting on your own Ollama, vLLM, or llama.cpp infrastructure or a dedicated private gateway — on-prem, VPC, or air-gapped. Q: Can AnyForge run fully on private models? A: Yes. Route every surface — Control, Code Studio, Crew, the Oracle — to models on infrastructure you control, with identical governance, audit, and the same flat platform fee. Q: Does AnyForge do product management or just coding? A: The full loop: Signals → RICE-scored Opportunities → Roadmap Themes → spec-verified Initiatives → governed delivery → releases, incidents, and board-ready reporting. Revenue-at-Risk and Monte-Carlo capacity forecasting included. Q: How is AnyForge different from Claude Code, Codex, or Cursor? A: Those are agents. AnyForge is the platform above them — govern them through Control or replace them with Code Studio/Crew. BYOK, no markups, intent routing, portable memory, hash-chained audit, human approval gates, and an entire planning + insights layer. Q: Is AnyForge suitable for private equity portfolio companies? A: Yes. A Portfolio view gives PE operators single-pane visibility — crews, spend by surface, approvals, velocity — across isolated per-company tenants, plus board packs, escrow, and audit evidence per company. Q: Is AnyForge audit-ready? A: Governance is the architecture: hash-chained append-only audit ledger, cryptographic approval proofs, enforced constraints verified at PR time, OPA policy engine, Secret Manager-backed credentials, and a hard deploy boundary (AnyForge never deploys, never holds infra keys). Q: How does pricing work? A: One flat per-million-token platform fee routed, provider-agnostic, BYOK, no seats or tiers; 100M-token free signup trial; first Crew free (20K-token trial). Enterprise SKU (annual, NET-30, SOC 2, SSO) and Crew Managed Service contracts available. The exact rate is shared with design partners and platform accounts. Q: Does AnyForge deploy my code? A: No — by design. AnyForge produces and merges PRs; your CI/CD deploys. Release failure hooks let AnyForge open hotfix crews automatically, so the fix loop closes without AnyForge touching production. ## AI Cost Calculator (/cost) URL: https://anyforge.ai/cost Estimates LLM spend under flat vs tier-routed vs Crew-delivered strategies across Claude, GPT, and Gemini model families with current per-million-token pricing. Key takeaway: tier routing (cheap model for simple tasks, frontier for complex) typically cuts the bill 40–70%; the calculator makes it tangible with your own token volumes, task mix, and team size. ## Pages - / — Homepage (platform overview, three products, adoption ladder, FAQ) - /platform — Full platform tour: plan, build, govern, see, extend, any model - /technology — Engineering deep-dive: architecture, determinism, security, stack - /control — AnyForge Control product page (bring-your-own-agent path) - /code-studio — AnyForge Code Studio product page (turnkey browser coding) - /pricing — Flat platform fee, BYOK model, free trial - /cost — AI cost calculator and model pricing comparison - /privacy — Privacy policy - /terms — Terms of service ## Contact & Access - Website: https://anyforge.ai - Install Control: `npx anyforge init` (see /control) - Try Code Studio free: https://crew.anyforge.ai/studio - Crew pilot application: https://anyforge.ai/#pilot - Twitter/X: @anyforge_ai - Founder LinkedIn: https://linkedin.com/in/edwinpoot