Platform
One Control Plane for Your Entire AI & API Estate
1
control plane
Catalog, policy, identity, and GitOps for API, AI, MCP, and agents.
3
install models
SaaS, hybrid (private data plane), and self-hosted / air-gapped.
SSO
enterprise identity
OIDC, SAML, SCIM, and workload identities bound to every gateway.
GitOps
config as code
Terraform, Helm, and Kubernetes operator with revisioned rollback.
Reference architecture
ForgeCrux One: unified control plane
One control plane for your entire AI, MCP, agent, and API estate — catalog, policy, routing, and compliance in a single fabric.
ForgeCrux One: Unified Control Plane Architecture
ForgeCrux One control plane for your entire AI, MCP, agent & API estate
Consumer & application layer
End users
Chatbots, apps
Enterprise applications
CRM, ERP
Developers
IDE, SDKs
Microservices
Internal workloads
Installation & deployment models
SaaS
ForgeCrux managed
Hybrid
Control plane SaaS, data plane VPC / on-prem
Self-hosted
Air-gapped / private cloud
Transformation layer
Protocol translation
Data normalization
Semantic mapping
Payload optimization
ForgeCrux One control plane
Centralized management & registry
Unified catalog
AI, MCP, agents, APIs
Dashboard & policy manager
Configuration database
Orchestration & routing engine
MCP hub & router
Model Context Protocol
AI model switcher & load balancer
Multi-model routing
API Gateway
OAS / GraphQL / gRPC
Agent manager & event bus
Identity, A2A, HITL
API Gateway fabric
Policy, quota, mediation
Agent bus manager
Workflows and events
Security & identity
IAM & zero trust
RBAC, ABAC
DLP & PII masking
API security
OAuth 2.0, mTLS
Audit logging
Governance & compliance
Compliance frameworks
GDPR, CCPA, HIPAA
AI ethics & fairness monitoring
Usage quotas & rate limiting
Performance & drift monitoring
Cost control
Managed AI, MCP, agent & API estate
AI estate
Commercial LLMs
OpenAI, Anthropic, Google
Open-source models
Llama, Mistral
Vector databases
Embeddings APIs
MCP estate
Local MCP tools
ForgeCrux MCP gateways
Remote MCP services
Upstream agents
Agent estate
ForgeCrux agents
Custom agents
Partner agents
Agent registries
API estate
Legacy systems
Third-party SaaS APIs
Internal microservices
Microservices mesh
One pane for four gateways
Platform teams manage API, AI, MCP, and Agent gateways without four consoles, four IAM models, or four GitOps pipelines.
Policy once, enforce everywhere
Identity, quota, residency, and audit rules are defined in the control plane and enforced in every data plane hop.
Install where the enterprise already runs
SaaS for speed, hybrid for data sovereignty, or self-hosted Kubernetes for regulated and air-gapped sites.
Key Capabilities
Complete Control Plane capabilities
Everything required to publish, secure, mediate, observe, and operate control plane workloads on ForgeCrux.
Enterprise uses
How platform, security, and product teams run ForgeCrux One in production.
- Platform engineering: one catalog and promotion path for APIs, models, tools, and agents
- API modernization: keep existing proxies while adding AI and MCP on the same plane
- AI Centers of Excellence: model allow lists, spend caps, and eval gates by business unit
- Agent operations: identity, budgets, and HITL for autonomous workloads
- Security & GRC: shared IAM, DLP, residency, and immutable audit across every hop
- SRE: SLOs, multi-region failover, and config rollback without touching four products
- Partner ecosystems: isolate tenants, credentials, and quotas per organization
- Regulated industries: hybrid or air-gapped data planes with SaaS or private control
Installation & deployment
Choose the footprint that matches data residency, ops model, and scale.
- SaaS: ForgeCrux-managed control plane and data plane with regional pin
- Hybrid: SaaS control plane, customer-owned data plane in VPC, Kubernetes, or on-prem
- Self-hosted: full control plane on private Kubernetes, OpenShift, or air-gapped clusters
- Helm charts, Terraform modules, and a Kubernetes operator for day-0 install
- Connected, disconnected, and proxy-restricted network modes
- Multi-region active-active and disaster-recovery pairs
- Environment groups: development, test, staging, production, sandbox
- Capacity planning: horizontal scale of control APIs, policy PDP, and config DB
Setup & onboarding
Stand up organizations, identity, catalogs, and the first production gateway.
- Create organization, billing entity, and environment topology
- Connect SSO (OIDC/SAML), SCIM provisioning, and break-glass local admins
- Define custom roles: platform admin, gateway operator, developer, auditor, partner
- Import existing API proxies, OpenAPI specs, and model provider credentials
- Register MCP servers, agent definitions, and shared policy packs
- Wire Git remotes, Terraform state, and CI promotion workflows
- Attach observability exporters (OpenTelemetry, Prometheus, SIEM)
- Run a dual-control cutover: shadow config, then promote with rollback
Security & identity
Zero-trust access to the control plane and every data-plane hop it governs.
- SSO, OIDC, SAML, MFA, and session policies for operators
- Workload identity, mTLS, and short-lived tokens for gateways and agents
- RBAC/ABAC on catalogs, environments, secrets, and policy packs
- Secrets vault, KMS integration, and automated key rotation
- DLP and PII masking policies pushed to API and AI gateways
- Network policies, private link, and IP allow lists for control APIs
- Separation of duties: who can change policy vs who can deploy vs who can audit
- Immutable audit of logins, config diffs, secret access, and policy hits
Governance, compliance & operations
Prove control to GRC, finance, and SRE without a second stack.
- Policy-as-code with review, approval, and environment promotion
- Framework mappings for GDPR, CCPA, HIPAA, SOC 2, and ISO 27001 controls
- Usage quotas, rate limits, and cost allocation by org, team, and product
- AI ethics, fairness, and model-drift signals aggregated in one dashboard
- Change windows, dual-control, and emergency freeze for production
- Config drift detection between Git and the live control plane
- Backup, point-in-time restore, and region failover of the config database
- Status, incident comms, and SLO burn-rate alerts across all four gateways
Enterprise architecture
Control Plane reference architecture
Enterprise data path for Control Plane: producers, ForgeCrux control, gateway enforcement, and systems of record.
Consumers
End users
Apps, chat, partners
Developers
IDE, SDK, portal
Enterprise apps
CRM, ERP, ITSM
Microservices
Internal callers
ForgeCrux One
Catalog
APIs • models • MCP • agents
Policy manager
Identity • quota • residency
Config DB
Revisions • GitOps
PDP
Decisions for every hop
Data planes
API Gateway
Proxies • products
AI Gateway
Models • guardrails
MCP Gateway
Tools • vault
Agent Gateway
Identity • HITL
Estate
LLMs
Cloud & self-hosted
MCP servers
Local & remote
Systems of record
SAP, SFDC, data
SIEM / APM
Audit & traces
Data flows
How requests, policies, and telemetry move through ForgeCrux in this solution.
Install and attach a data plane
From cluster to registered gateway under one org.
Choose model
SaaS • hybrid • self-host
Install
Helm • Terraform • operator
mTLS join
Workload identity
Pull config
Catalog • policy packs
Serve traffic
API • AI • MCP • agent
Policy change to production
A shared rule reaching every gateway without manual copies.
PR in Git
Policy as code
Review / SSO
Separation of duties
Control plane
Revision + PDP
Fan-out
All data planes
Audit
Who • when • diff
How teams run Control Plane on ForgeCrux
Install the control plane
Pick SaaS, hybrid, or self-hosted. Bootstrap org, environments, and the first admin via SSO.
Connect identity
Wire OIDC/SAML, SCIM groups, custom roles, and break-glass accounts before any production traffic.
Register data planes
Join API, AI, MCP, and Agent gateways with workload identity so they pull catalog and policy from One.
Import the estate
Bring OpenAPI specs, model providers, MCP servers, and agent definitions into the unified catalog.
Turn on GitOps
Store policy packs and environment config in Git; promote with Terraform or the Kubernetes operator.
Prove control
Export audit, traces, and cost to SIEM and FinOps. Freeze production with dual-control for GRC reviews.
Related Products
API Gateway
ForgeCrux API Gateway covers the full API lifecycle: proxies, products, policies, developer portal, analytics, monetization, hybrid runtime, and promotion across environments—on the same control plane as AI, MCP, and agents.
AI Gateway
ForgeCrux AI Gateway is the single endpoint for multi-model access, intelligent routing, prompt control, guardrails, token and cost management, evaluation, and LLM observability—across OpenAI, Anthropic, Gemini, Bedrock, Azure OpenAI, and self-hosted models.
Observability
ForgeCrux One Observability is the telemetry plane for APIs, LLMs, MCP tools, and agents. Platform, SRE, security, and FinOps teams ingest logs, metrics, and traces from every gateway hop, then act from one dashboard—maps, alerts, incident tools, and audit replay included.
Agent Gateway
ForgeCrux Agent Gateway gives every agent an identity, permissions, routing, memory controls, guardrails, tracing, evaluation, cost limits, and lifecycle—so multi-agent systems can reach models, APIs, MCP tools, and data without unmanaged autonomy.
Ready to get started with Control Plane?
Talk to our team about deploying Control Plane in your enterprise environment.