Platform

One Control Plane for Your Entire AI & API Estate

ForgeCrux One is the enterprise control plane for APIs, AI models, MCP tools, and agents. Platform, security, and SRE teams use it to install, configure, govern, and operate every gateway from one catalog, one policy engine, and one audit trail—across SaaS, hybrid, and air-gapped footprints.

1

control plane

Catalog, policy, identity, and GitOps for API, AI, MCP, and agents.

3

install models

SaaS, hybrid (private data plane), and self-hosted / air-gapped.

SSO

enterprise identity

OIDC, SAML, SCIM, and workload identities bound to every gateway.

GitOps

config as code

Terraform, Helm, and Kubernetes operator with revisioned rollback.

Reference architecture

ForgeCrux One: unified control plane

One control plane for your entire AI, MCP, agent, and API estate — catalog, policy, routing, and compliance in a single fabric.

ForgeCrux One: Unified Control Plane Architecture

ForgeCrux One control plane for your entire AI, MCP, agent & API estate

ForgeCruxProbing Deeper, Stacking Precision

Consumer & application layer

End users

Chatbots, apps

Enterprise applications

CRM, ERP

Developers

IDE, SDKs

Microservices

Internal workloads

ForgeCrux SDKs & gateways

Installation & deployment models

SaaS

ForgeCrux managed

Hybrid

Control plane SaaS, data plane VPC / on-prem

Self-hosted

Air-gapped / private cloud

Transformation layer

Protocol translation

Data normalization

Semantic mapping

Payload optimization

ForgeCrux One control plane

Centralized management & registry

Unified catalog

AI, MCP, agents, APIs

Dashboard & policy manager

Configuration database

Orchestration & routing engine

MCP hub & router

Model Context Protocol

AI model switcher & load balancer

Multi-model routing

API Gateway

OAS / GraphQL / gRPC

Agent manager & event bus

Identity, A2A, HITL

API Gateway fabric

Policy, quota, mediation

Agent bus manager

Workflows and events

Security & identity

IAM & zero trust

RBAC, ABAC

DLP & PII masking

API security

OAuth 2.0, mTLS

Audit logging

Governance & compliance

Compliance frameworks

GDPR, CCPA, HIPAA

AI ethics & fairness monitoring

Usage quotas & rate limiting

Performance & drift monitoring

Cost control

Managed AI, MCP, agent & API estate

AI estate

Commercial LLMs

OpenAI, Anthropic, Google

Open-source models

Llama, Mistral

Vector databases

Embeddings APIs

MCP estate

Local MCP tools

ForgeCrux MCP gateways

Remote MCP services

Upstream agents

Agent estate

ForgeCrux agents

Custom agents

Partner agents

Agent registries

API estate

Legacy systems

Third-party SaaS APIs

Internal microservices

Microservices mesh

One pane for four gateways

Platform teams manage API, AI, MCP, and Agent gateways without four consoles, four IAM models, or four GitOps pipelines.

Policy once, enforce everywhere

Identity, quota, residency, and audit rules are defined in the control plane and enforced in every data plane hop.

Install where the enterprise already runs

SaaS for speed, hybrid for data sovereignty, or self-hosted Kubernetes for regulated and air-gapped sites.

Key Capabilities

Unified catalog of APIs, models, MCP servers, agents, and policies
Organizations, environments, and promotion pipelines
SSO, OIDC, SAML, SCIM, and workload identity
RBAC/ABAC with custom roles and separation of duties
Shared policy packs applied to API, AI, MCP, and Agent gateways
GitOps, Terraform provider, Helm, and Kubernetes operator
SaaS, hybrid (SaaS control + private data plane), and self-hosted
Config database, revision history, and instant rollback
Dashboard, policy manager, and configuration as code
Multi-region HA, DR, and environment isolation
Centralized secrets vault and key rotation
Audit logs for every config, identity, and policy change

Complete Control Plane capabilities

Everything required to publish, secure, mediate, observe, and operate control plane workloads on ForgeCrux.

Enterprise uses

How platform, security, and product teams run ForgeCrux One in production.

  • Platform engineering: one catalog and promotion path for APIs, models, tools, and agents
  • API modernization: keep existing proxies while adding AI and MCP on the same plane
  • AI Centers of Excellence: model allow lists, spend caps, and eval gates by business unit
  • Agent operations: identity, budgets, and HITL for autonomous workloads
  • Security & GRC: shared IAM, DLP, residency, and immutable audit across every hop
  • SRE: SLOs, multi-region failover, and config rollback without touching four products
  • Partner ecosystems: isolate tenants, credentials, and quotas per organization
  • Regulated industries: hybrid or air-gapped data planes with SaaS or private control

Installation & deployment

Choose the footprint that matches data residency, ops model, and scale.

  • SaaS: ForgeCrux-managed control plane and data plane with regional pin
  • Hybrid: SaaS control plane, customer-owned data plane in VPC, Kubernetes, or on-prem
  • Self-hosted: full control plane on private Kubernetes, OpenShift, or air-gapped clusters
  • Helm charts, Terraform modules, and a Kubernetes operator for day-0 install
  • Connected, disconnected, and proxy-restricted network modes
  • Multi-region active-active and disaster-recovery pairs
  • Environment groups: development, test, staging, production, sandbox
  • Capacity planning: horizontal scale of control APIs, policy PDP, and config DB

Setup & onboarding

Stand up organizations, identity, catalogs, and the first production gateway.

  • Create organization, billing entity, and environment topology
  • Connect SSO (OIDC/SAML), SCIM provisioning, and break-glass local admins
  • Define custom roles: platform admin, gateway operator, developer, auditor, partner
  • Import existing API proxies, OpenAPI specs, and model provider credentials
  • Register MCP servers, agent definitions, and shared policy packs
  • Wire Git remotes, Terraform state, and CI promotion workflows
  • Attach observability exporters (OpenTelemetry, Prometheus, SIEM)
  • Run a dual-control cutover: shadow config, then promote with rollback

Security & identity

Zero-trust access to the control plane and every data-plane hop it governs.

  • SSO, OIDC, SAML, MFA, and session policies for operators
  • Workload identity, mTLS, and short-lived tokens for gateways and agents
  • RBAC/ABAC on catalogs, environments, secrets, and policy packs
  • Secrets vault, KMS integration, and automated key rotation
  • DLP and PII masking policies pushed to API and AI gateways
  • Network policies, private link, and IP allow lists for control APIs
  • Separation of duties: who can change policy vs who can deploy vs who can audit
  • Immutable audit of logins, config diffs, secret access, and policy hits

Governance, compliance & operations

Prove control to GRC, finance, and SRE without a second stack.

  • Policy-as-code with review, approval, and environment promotion
  • Framework mappings for GDPR, CCPA, HIPAA, SOC 2, and ISO 27001 controls
  • Usage quotas, rate limits, and cost allocation by org, team, and product
  • AI ethics, fairness, and model-drift signals aggregated in one dashboard
  • Change windows, dual-control, and emergency freeze for production
  • Config drift detection between Git and the live control plane
  • Backup, point-in-time restore, and region failover of the config database
  • Status, incident comms, and SLO burn-rate alerts across all four gateways

Enterprise architecture

Control Plane reference architecture

Enterprise data path for Control Plane: producers, ForgeCrux control, gateway enforcement, and systems of record.

Consumers

End users

Apps, chat, partners

Developers

IDE, SDK, portal

Enterprise apps

CRM, ERP, ITSM

Microservices

Internal callers

ForgeCrux One

Catalog

APIs • models • MCP • agents

Policy manager

Identity • quota • residency

Config DB

Revisions • GitOps

PDP

Decisions for every hop

Data planes

API Gateway

Proxies • products

AI Gateway

Models • guardrails

MCP Gateway

Tools • vault

Agent Gateway

Identity • HITL

Estate

LLMs

Cloud & self-hosted

MCP servers

Local & remote

Systems of record

SAP, SFDC, data

SIEM / APM

Audit & traces

Data flows

How requests, policies, and telemetry move through ForgeCrux in this solution.

Install and attach a data plane

From cluster to registered gateway under one org.

1

Choose model

SaaS • hybrid • self-host

2

Install

Helm • Terraform • operator

3

mTLS join

Workload identity

4

Pull config

Catalog • policy packs

5

Serve traffic

API • AI • MCP • agent

Policy change to production

A shared rule reaching every gateway without manual copies.

1

PR in Git

Policy as code

2

Review / SSO

Separation of duties

3

Control plane

Revision + PDP

4

Fan-out

All data planes

5

Audit

Who • when • diff

How teams run Control Plane on ForgeCrux

Install the control plane

Pick SaaS, hybrid, or self-hosted. Bootstrap org, environments, and the first admin via SSO.

Connect identity

Wire OIDC/SAML, SCIM groups, custom roles, and break-glass accounts before any production traffic.

Register data planes

Join API, AI, MCP, and Agent gateways with workload identity so they pull catalog and policy from One.

Import the estate

Bring OpenAPI specs, model providers, MCP servers, and agent definitions into the unified catalog.

Turn on GitOps

Store policy packs and environment config in Git; promote with Terraform or the Kubernetes operator.

Prove control

Export audit, traces, and cost to SIEM and FinOps. Freeze production with dual-control for GRC reviews.

Ready to get started with Control Plane?

Talk to our team about deploying Control Plane in your enterprise environment.