ForgeHelm › Product › Architecture

An architecture designed to leave source code where it is

Analysis happens inside your network; only masked file names, line numbers, and summary counts cross the boundary. Three components, each with its own boundary, each upgraded independently.

Three Components

🔍

Analysis Engine (Agent)

Installed inside your network, with the task queue and analysis results in a PostgreSQL database you provide; all scanning and analysis runs locally. The code can come from a Git repository URL or from a ZIP uploaded through the management platform. Triggers: webhook, scheduled polling, or a call to the API from your CI. Source code is never sent out.

Runs On-Premises PostgreSQL SignalR Webhook / polling / API / ZIP
CUSTOMER NETWORK

Masked summary counts only

☁️

Management Platform (SaaS)

Tenant management, project settings, dashboards, report output, and collaboration workflows all live here. Use our hosted cloud, or install the whole thing in your own environment.

PostgreSQL SignalR RBAC
CLOUD / SAAS
⬡
Shared Contracts

The data formats between the Agent and the management platform are explicitly versioned, so upgrading either side doesn't break the other.

Data Flow

  1. 1 The Agent receives a trigger: webhook, poll, or API call
  2. 2 Analysis runs inside your network; source code doesn't leave
  3. 3 Results are masked, keeping only file names, line numbers, and summary counts
  4. 4 The masked summary is pushed to the management platform in real time
  5. 5 The management platform renders dashboards and generates compliance reports

Deployment Modes

☁️

Full Cloud

Fastest Onboarding

Management platform and analysis both in the cloud, run by us.

Suitable when:

  • Policy allows code analysis in the cloud
  • Time to launch matters most
  • Unregulated or early-stage projects
🏢

Private Cloud / On-Premises

Self-Managed

Every component installed in your data center or private cloud; you control all compute and storage.

Suitable when:

  • Strict data residency requirements
  • Company policy allows no cloud at all
  • Government agencies and organizations that need full control of their infrastructure
🔒

Air-Gapped

Maximum Security

Fully offline with no outbound connections. Updates arrive on physical media.

Suitable when:

  • Classified or military environments
  • No outbound connections allowed
  • Isolated government networks

Three Ways to Connect AI

🌐

Cloud Model (Core)

Served by a model we host (currently the Google Gemini API) — the fastest to get started. Code snippets used for AI retrieval are sent to that provider for indexing. All three plans use the same assistant; Core is metered by quota.

💻

On-Premises Retrieval, Your Choice of Model (Professional)

The Agent handles data retrieval and secrets screening inside your network, then sends the question to the model endpoint you choose — public cloud or your own VPC — with no usage cap.

⚡

Fully Offline, Bring Your Own Model (BYOL, Enterprise)

Use the AI Deployment Kit to run an open-source model on your own GPUs; questions and answers never leave your network.

With AI turned off, the five modules — reports, SBOM, dashboards, migration, and data quality — work as usual; only the AI assistant needs a model. Before an answer is sent, the assistant screens for common password and API key patterns so they don't leak out with the reply.

Which network paths you'll need to open

This comes up with hybrid deployments. The two paths run in opposite directions, so it's clearer to describe them separately.

Scanning and reports: outbound only

The analysis engine (Agent) reaches out to claim tasks, report progress and push masked results and report files. This path needs no externally exposed port on the analysis engine.

Dashboards and diagrams: the platform has to reach the engine

The governance dashboard, the 20 architecture diagrams, data quality clean-up, running code conversions and the AI assistant's retrieval are all queried by the management platform from the analysis engine. If the platform is in the cloud and the engine is on your internal network, that path needs a controlled inbound channel. If you would rather not open one, put the management platform on your internal network too (the private-cloud option).

Air-gapped deployments don't have this problem — every component sits inside the same isolated segment.

How big the analysis engine host needs to be

Reference specifications for a self-hosted analysis engine and on-premises management platform. The cloud-only Core plan needs no machine of your own.

Deployment size Agent CPU Agent memory Storage Platform memory
Small (up to 10 repositories, 1M lines) 2 vCPU4 GB20 GB8 GB
Medium (10–50 repositories, 5M lines) 4 vCPU8 GB100 GB16 GB
Large (50+ repositories, 20M lines) 8 vCPU16 GB500 GB32 GB
Air-gapped + bring your own model (BYOL) 8+ vCPU + GPU 32 GB + GPU memory 1 TB+32 GB

A container image and a docker compose configuration are also provided. Bring-your-own-model (BYOL) needs a compatible GPU; a quantized model needs at least 8 GB of video memory. Scan time grows with codebase size and the number of frameworks enabled; incremental scanning is recommended for large monorepos.

The analysis engine needs PostgreSQL — three ways to provide it

The usual first reaction from IT is "another database to look after". Not necessarily; pick whichever fits your environment.

Alongside the container

Use the container setup we provide and the analysis engine starts together with PostgreSQL. The container manages the database, so nobody on your side has to maintain it. This is the easiest route.

As a service on the host

Where policy does not allow containers, PostgreSQL has official installers and runs as a Windows or Linux service. Point the analysis engine at it with a connection string.

On your existing instance

Already running PostgreSQL? Create a database and an account for the analysis engine — nothing new to install. Environments that moved off Oracle in recent years usually fall here.

The analysis engine connects by connection string, so all three look the same to it. Note: the built-in SQLite is only an offline buffer for events and cannot serve as the main database.

AI Deployment Kit for Your Own Model (BYOL, Enterprise)

Bring your own GPUs and an open-source model; ForgeHelm supplies a pre-configured deployment bundle, so the AI assistant's inference and model both stay inside your network.

  • ✓ A set of deployment templates that stand up the Agent's AI service, Ollama, and the vector database in one go
  • ✓ Offline installers and model download guides for air-gapped environments

Want to validate this architecture in your own environment?

Request a two-week proof of concept (PoC): you pick a representative repository, and we set up the Agent inside your network, run the scan, and deliver the report. Code stays in your environment the entire time.