Three Components
Analysis Engine (Agent)
Installed inside your network, with the task queue and analysis results in a PostgreSQL database you provide; all scanning and analysis runs locally. The code can come from a Git repository URL or from a ZIP uploaded through the management platform. Triggers: webhook, scheduled polling, or a call to the API from your CI. Source code is never sent out.
Masked summary counts only
Management Platform (SaaS)
Tenant management, project settings, dashboards, report output, and collaboration workflows all live here. Use our hosted cloud, or install the whole thing in your own environment.
Data Flow
- 1 The Agent receives a trigger: webhook, poll, or API call
- 2 Analysis runs inside your network; source code doesn't leave
- 3 Results are masked, keeping only file names, line numbers, and summary counts
- 4 The masked summary is pushed to the management platform in real time
- 5 The management platform renders dashboards and generates compliance reports
Deployment Modes
Full Cloud
Fastest OnboardingManagement platform and analysis both in the cloud, run by us.
Suitable when:
- Policy allows code analysis in the cloud
- Time to launch matters most
- Unregulated or early-stage projects
Hybrid
Management platform in the cloud, Agent installed in your network. Source code doesn't leave your network.
Suitable when:
- Source code has to stay in your hands
- You want both speed and security
- Regulated industries such as finance and healthcare
Private Cloud / On-Premises
Self-ManagedEvery component installed in your data center or private cloud; you control all compute and storage.
Suitable when:
- Strict data residency requirements
- Company policy allows no cloud at all
- Government agencies and organizations that need full control of their infrastructure
Air-Gapped
Maximum SecurityFully offline with no outbound connections. Updates arrive on physical media.
Suitable when:
- Classified or military environments
- No outbound connections allowed
- Isolated government networks
Three Ways to Connect AI
Cloud Model (Core)
Served by a model we host (currently the Google Gemini API) — the fastest to get started. Code snippets used for AI retrieval are sent to that provider for indexing. All three plans use the same assistant; Core is metered by quota.
On-Premises Retrieval, Your Choice of Model (Professional)
The Agent handles data retrieval and secrets screening inside your network, then sends the question to the model endpoint you choose — public cloud or your own VPC — with no usage cap.
Fully Offline, Bring Your Own Model (BYOL, Enterprise)
Use the AI Deployment Kit to run an open-source model on your own GPUs; questions and answers never leave your network.
With AI turned off, the five modules — reports, SBOM, dashboards, migration, and data quality — work as usual; only the AI assistant needs a model. Before an answer is sent, the assistant screens for common password and API key patterns so they don't leak out with the reply.
Which network paths you'll need to open
This comes up with hybrid deployments. The two paths run in opposite directions, so it's clearer to describe them separately.
Scanning and reports: outbound only
The analysis engine (Agent) reaches out to claim tasks, report progress and push masked results and report files. This path needs no externally exposed port on the analysis engine.
Dashboards and diagrams: the platform has to reach the engine
The governance dashboard, the 20 architecture diagrams, data quality clean-up, running code conversions and the AI assistant's retrieval are all queried by the management platform from the analysis engine. If the platform is in the cloud and the engine is on your internal network, that path needs a controlled inbound channel. If you would rather not open one, put the management platform on your internal network too (the private-cloud option).
Air-gapped deployments don't have this problem — every component sits inside the same isolated segment.
How big the analysis engine host needs to be
Reference specifications for a self-hosted analysis engine and on-premises management platform. The cloud-only Core plan needs no machine of your own.
| Deployment size | Agent CPU | Agent memory | Storage | Platform memory |
|---|---|---|---|---|
| Small (up to 10 repositories, 1M lines) | 2 vCPU | 4 GB | 20 GB | 8 GB |
| Medium (10–50 repositories, 5M lines) | 4 vCPU | 8 GB | 100 GB | 16 GB |
| Large (50+ repositories, 20M lines) | 8 vCPU | 16 GB | 500 GB | 32 GB |
| Air-gapped + bring your own model (BYOL) | 8+ vCPU + GPU | 32 GB + GPU memory | 1 TB+ | 32 GB |
A container image and a docker compose configuration are also provided. Bring-your-own-model (BYOL) needs a compatible GPU; a quantized model needs at least 8 GB of video memory. Scan time grows with codebase size and the number of frameworks enabled; incremental scanning is recommended for large monorepos.
The analysis engine needs PostgreSQL — three ways to provide it
The usual first reaction from IT is "another database to look after". Not necessarily; pick whichever fits your environment.
Alongside the container
Use the container setup we provide and the analysis engine starts together with PostgreSQL. The container manages the database, so nobody on your side has to maintain it. This is the easiest route.
As a service on the host
Where policy does not allow containers, PostgreSQL has official installers and runs as a Windows or Linux service. Point the analysis engine at it with a connection string.
On your existing instance
Already running PostgreSQL? Create a database and an account for the analysis engine — nothing new to install. Environments that moved off Oracle in recent years usually fall here.
The analysis engine connects by connection string, so all three look the same to it. Note: the built-in SQLite is only an offline buffer for events and cannot serve as the main database.
AI Deployment Kit for Your Own Model (BYOL, Enterprise)
Bring your own GPUs and an open-source model; ForgeHelm supplies a pre-configured deployment bundle, so the AI assistant's inference and model both stay inside your network.
- ✓ A set of deployment templates that stand up the Agent's AI service, Ollama, and the vector database in one go
- ✓ Offline installers and model download guides for air-gapped environments
Want to validate this architecture in your own environment?
Request a two-week proof of concept (PoC): you pick a representative repository, and we set up the Agent inside your network, run the scan, and deliver the report. Code stays in your environment the entire time.