Resources · Architecture
Enterprise architecture for the whole estate
1
control plane
Catalog, policy, identity, and GitOps for the whole estate.
4
data planes
API, AI, MCP, and Agent—same PDP and audit trail.
3
install models
SaaS, hybrid, and self-hosted / air-gapped.
N
systems of record
CRM, ERP, ITSM, lakes, and model providers stay put.
Architecture catalog
Each product and solution page has a unique reference diagram. Start here, then open the page that matches your wave.
API Gateway
Ingress, policy, mediation, and backends.
AI Gateway
Models, guardrails, routing, and spend.
MCP Gateway
Tools, vault, virtual servers, and audit.
Agent Gateway
Identity, A2A, HITL, and hop limits.
Control Plane
ForgeCrux One catalog, PDP, and GitOps.
Observability
Collectors, maps, anomalies, incidents.
API Modernization
Discovery factory, dual-run, cutover.
AI Governance
Classify, permit, redact, audit.
Agentic AI
Supervisor, specialists, HITL, SoR.
MCP Security
Default deny, vault JIT, tool audit.
Enterprise Integration
Façade, strangler, IdP, SoRs.
Reference architecture
ForgeCrux One: unified control plane
One control plane for your entire AI, MCP, agent, and API estate — catalog, policy, routing, and compliance in a single fabric.
ForgeCrux One: Unified Control Plane Architecture
ForgeCrux One control plane for your entire AI, MCP, agent & API estate
Consumer & application layer
End users
Chatbots, apps
Enterprise applications
CRM, ERP
Developers
IDE, SDKs
Microservices
Internal workloads
Installation & deployment models
SaaS
ForgeCrux managed
Hybrid
Control plane SaaS, data plane VPC / on-prem
Self-hosted
Air-gapped / private cloud
Transformation layer
Protocol translation
Data normalization
Semantic mapping
Payload optimization
ForgeCrux One control plane
Centralized management & registry
Unified catalog
AI, MCP, agents, APIs
Dashboard & policy manager
Configuration database
Orchestration & routing engine
MCP hub & router
Model Context Protocol
AI model switcher & load balancer
Multi-model routing
API Gateway
OAS / GraphQL / gRPC
Agent manager & event bus
Identity, A2A, HITL
API Gateway fabric
Policy, quota, mediation
Agent bus manager
Workflows and events
Security & identity
IAM & zero trust
RBAC, ABAC
DLP & PII masking
API security
OAuth 2.0, mTLS
Audit logging
Governance & compliance
Compliance frameworks
GDPR, CCPA, HIPAA
AI ethics & fairness monitoring
Usage quotas & rate limiting
Performance & drift monitoring
Cost control
Managed AI, MCP, agent & API estate
AI estate
Commercial LLMs
OpenAI, Anthropic, Google
Open-source models
Llama, Mistral
Vector databases
Embeddings APIs
MCP estate
Local MCP tools
ForgeCrux MCP gateways
Remote MCP services
Upstream agents
Agent estate
ForgeCrux agents
Custom agents
Partner agents
Agent registries
API estate
Legacy systems
Third-party SaaS APIs
Internal microservices
Microservices mesh
Enterprise data
Uses, installation, setup, and security—the same operating model as the platform and solutions pages.
Enterprise uses
When teams pull architecture reviews from this library.
- Target-state design for a unified API + AI + MCP + agent fabric
- Hybrid and air-gapped placement of control vs data planes
- Strangler and dual-run patterns off legacy API management
- Zero-trust MCP and agent identity before production autonomy
- Governance evidence path from PDP to SIEM and GRC
- Observability maps spanning all four gateway hops
Installation patterns
Where each box in the diagrams actually runs.
- SaaS: ForgeCrux-operated control and optional data planes
- Hybrid: SaaS control, customer VPC/K8s/on-prem data planes
- Self-hosted: full stack on private Kubernetes with GitOps
- Coexistence: ForgeCrux northbound, existing ingress southbound
- Multi-region active-active with config DB replication
- Disconnected promotion with signed Helm/Terraform artifacts
Setup & review
How an architecture engagement typically proceeds.
- Map channels, IdP, current gateways, SoRs, and telemetry
- Choose SaaS, hybrid, or self-hosted for control and data
- Draw trust boundaries: vault, mTLS join, residency pins
- Sequence waves: APIs first, then AI, MCP, agents
- Define SLO, audit, and rollback contracts before cutover
- Leave with GitOps repo layout and environment topology
Security architecture
Controls that appear on every reference diagram.
- Identity: SSO for operators, workload identity for planes
- PDP in path for APIs, completions, MCP tools, and A2A
- Vaulted credentials—never in agent memory or MCP stdio configs
- Network: private link, allow lists, sandbox egress for tools
- Data: classification, DLP, residency, and payload truncation
- Evidence: immutable decisions, traces, and session replay ACLs
Need a custom architecture review?
Our solutions architects can design SaaS, hybrid, or air-gapped deployments for your estate.