Resources · Case studies

How enterprises run ForgeCrux in production

Industry programs—not logos. Each study covers install model, security outcomes, and how APIs, models, tools, and agents landed on one plane.

Global financial services

Unified API and AI policy without a partner rewrite

Region-by-region cutover from legacy API management; same hostnames and keys; AI Gateway on the same plane for copilots.

0

planned downtime

1

policy surface

3

regions dual-run

Healthcare technology

PHI-safe model access and MCP tools in one audit trail

Residency-pinned models, prompt/completion DLP, vaulted EHR connectors, and HITL on chart-write tools.

100%

requests classified

0

raw secrets in agents

7yr

audit hold option

Fortune 500 retailer

Agent operations for fulfillment with hop limits and kill switch

Supervisor agents on ITSM cases; MCP tools for inventory APIs; budgets and compensation on failed writes.

N-hop

A2A bound

HITL

on refunds

CI

eval before prod

Industrial manufacturer

Hybrid control plane, on-prem data plane, air-gapped plants

SaaS control for HQ; self-hosted gateways in plants; signed artifact promotion; OTEL stays in-region.

Hybrid

install model

GitOps

promotion

Private

telemetry

Enterprise data

Uses, installation, setup, and security—the same operating model as the platform and solutions pages.

Enterprise uses

Patterns these programs share.

  • Modernize APIs first, then attach AI/MCP/agents on the same plane
  • Never let agents hold SoR credentials—vault JIT via MCP Gateway
  • Put governance in the request path before scaling copilots
  • Dual-run until SLO and audit sign-off, then decommission
  • One trace ID for SRE, security, and FinOps
  • Choose SaaS, hybrid, or air-gapped per data class—not per product

Installation & setup

How engagements typically land.

  • Wave 0: org, SSO, environments, observability exporters
  • Join data planes with workload identity and mTLS
  • Import catalogs: proxies, models, MCP servers, agents
  • Pilot one domain or one agent workflow with a named owner
  • GitOps for policy packs; HITL on high-risk verbs
  • GRC evidence: decision logs, traces, and recertification

Security outcomes

What security and GRC asked to see in production.

  • SSO + custom roles + separation of duties
  • Default-deny MCP catalogs and arg-level authZ
  • PII/PHI redaction on prompts, tools, and session replay
  • Immutable audit of config diffs and policy hits
  • Kill switch and pause for agent fleets
  • Residency pins and private ingest for regulated regions

Map this to your estate

Bring your current gateways, IdP, and data-residency constraints—we will sketch SaaS, hybrid, or air-gapped.