Architecture · Zero-Trust · On-premise

Your AI expertise, tailored to your environment.

Hub Forge AI plugs into what you already have — your AI tool, your infrastructure, your processes. No need to change everything: we adapt, we compartmentalize, and every sensitive action stays under human control.

// On-premise VM · Private cloud · EU SaaS — same features, you choose where it runs

Sovereign by design Application-level Zero-Trust BYOK / LLM-agnostic GDPR & NIS2 compliant 100% local AI possible
Concrete use cases

What Hub Forge AI does in your industry.

Select your industry: each row shows a tool you already have, the Zero-Trust Proxy that compartmentalizes it, and the operational agent that results.

Internal tool
SIEM (Splunk, QRadar, Wazuh...)
Proxy
Reads alerts, correlation, IOC enrichment
Resulting agent
SOC agent
triages, qualifies and prioritizes alerts in real time
Internal tool
Vulnerability scanner (Nessus, Qualys...)
Proxy
Reads scan results, cross-references with CMDB
Resulting agent
Patch management agent
prioritizes critical fixes per asset
Internal tool
SOAR / playbooks
Proxy
Triggers playbooks, tracks execution
Resulting agent
Incident response agent
executes the first containment actions
Internal tool
Threat Intel feeds
Proxy
IOC ingestion, correlation with your estate
Resulting agent
Threat monitoring agent
alerts you when a threat affects your perimeter
Compatible

What can we connect to?

REST / GraphQL APIs, databases (SQL, NoSQL), CLI & scripts, files (CSV, JSON, logs), webhooks, LDAP, SSH, SMTP, SNMP.

Built-in safeguards — human validation required

Nothing is written without a human

ReadOnly mode by default for continuous auditing. Every write action is automatically intercepted: the agent is paused until the administrator manually validates it on the dashboard. Full audit logs, granular per-agent permissions.

Ecosystem

A complete pipeline — each building block feeds the next

Hub Forge AI is not a standalone tool. It's a pipeline where auditing, expertise, technology monitoring and your internal tools converge into operational agents.

Audit & diagnosis

Intelligent scoring of your IT estate. Identifies gaps, tools in place, and optimization opportunities.

Intelligent correlation

Each detected gap is cross-referenced with the skills and frameworks available in the Forges. AI identifies what can be automated.

Continuous monitoring

GitHub is scanned continuously. New tools, methods, vulnerabilities — your agents stay up to date without intervention.

Specialized agent

An agent is created with the domain expertise suited to your context. It masters your vertical and your specific challenges.

Connection to your tools

A custom MCP connector plugs the agent directly into your internal tools. It no longer just advises — it acts.

Measurable results

The agent acts within your IT estate: remediation, reporting, triage, alerting. Concrete ROI, time saved, errors avoided.

Virtuous loop — each result feeds the next cycle

The audit sharpens

The results of the first cycle reveal new optimization opportunities and new needs.

The agents improve

GitHub monitoring continuously enriches the skills. Your agents integrate the latest tools and methods automatically.

Coverage expands

Each new MCP connector widens the scope of action of your agents within your IT estate.

You already have AI. What you're missing is the pipeline.

Generic AI

  • Answers general questions
  • Doesn't know your industry
  • Doesn't know your tools
  • Frozen in time
  • Disconnected from your processes

Hub Forge AI

  • Domain expertise — agents trained on your vertical
  • Client context — the audit maps your IT estate and your tools
  • Always up to date — continuous GitHub monitoring, skills enriched every week
  • Connected to your tools — the agent reads and acts in your environment
  • End-to-end pipeline — from audit to remediation
Business model

MCP connectors are a separate engagement

The Hub Forge AI license includes the expertise centers, the audits and the conversational agents — you're autonomous immediately. The MCP connectors that plug your agents directly into your internal tools are custom-built for your environment. It's an integration engagement carried out by our teams, billed separately depending on the complexity of your tools.

License — Expertise + Audits + Agents Engagement — Custom MCP connectors Maintenance — Connector monitoring & evolution

Choose your access mode

Three ways to use Hub Forge AI. Each mode gives access to the same features — the difference is where it runs and who manages the infrastructure.

SaaS

Immediate access, nothing to install. We host, you use.

  • Ready in 2 minutes
  • Monthly subscription
  • France / EU hosting
  • AI via cloud API
IdealConsultants · Freelancers · SMBs

Private Cloud

Dedicated VPS in the datacenter of your choice.

  • Dedicated instance
  • Datacenter of your choice
  • Managed maintenance
  • Multi-user
IdealTeams · Multi-site

On-Premise VM

Inside your infrastructure. Local AI possible. Full control. A standard VM is enough.

  • Your hypervisor
  • Local AI (Ollama) or API
  • On-demand startup: 0 MB RAM at rest
  • Proxy Aggregator NextGen
IdealMid-market · Enterprises · MSSP

All modes give access to the same expertise centers and audit dashboards. The On-Premise VM is the only mode compatible with custom MCP connectors.

Deployment

Technical details per mode

What each mode means concretely for your IT team.

SaaS · Consultants / Freelancers / SMBs

SaaS

No installation. Log in and use the platform immediately from your browser.

  • Nothing to install or maintain
  • France / EU hosting
  • Monthly subscription, scalable
  • AI via cloud API (Claude, GPT, Gemini...)
  • Automatic updates
VM · Mid-market / Enterprises / MSSP

On-Premise VM

A pre-configured virtual machine, deployed inside your existing infrastructure. You only receive the modules of your plan.

  • Compatible with VMware, Proxmox, Hyper-V, Azure VM, AWS EC2
  • Docker Compose — all services isolated in containers
  • Integrated local AI — DeepSeek, Qwen, Llama, Mistral...
  • Project directives — your business rules per service, automatically inherited by each agent
  • Automatic change detection — the agent sees changes even before starting
  • Your security team can audit and monitor the VM
  • Inbound/outbound traffic 100% transparent and verifiable
  • Secure updates via internal pull
Private Cloud · SMBs / Independent consultants

Private Cloud

A dedicated VPS hosts your instance. You choose the datacenter (France, EU). We manage maintenance, you keep control of the data.

  • Dedicated VPS (Hetzner, OVH, Scaleway...)
  • Datacenter of your choice — geographic sovereignty
  • HTTPS + custom domain
  • Managed maintenance and updates
  • Complete isolation between clients
Sovereignty

Data security — adapts to your policy

Every organization has its own constraints. Hub Forge AI respects your existing security policy, whatever the chosen deployment mode.

Compartmentalized data

Audit data, agent conversations and documents are isolated per user. Nothing is shared between clients.

Compatible with your AI

Already have an AI tool in-house? We plug into it. If not, we guide you to choose the right option.

Transparent traffic

In VM deployment, your team can audit all traffic. In SaaS, hosting is in France/EU.

GDPR & NIS2 compliant

Complete traceability of agent actions. The local AI option enables zero transfer outside your network if needed.

Business rules per service

Drop project directives into each folder of your organization. Agents inherit the service's constraints (HR anonymization, Dev tech stack, accounting standards). Zero AI reconfiguration.

BYOK / LLM-agnostic

AI compatibility — we plug into what you have

Already have an AI tool deployed in-house? Perfect, Hub Forge AI uses it directly. If not, several options are available to you.

You already have an AI tool

Claude Code, Copilot, Cursor, or any other installed tool — Hub Forge AI plugs into it without changing anything in your setup.

Claude CodeCopilotCursor

You prefer a cloud API

Configure your own API key (BYOK). You keep control of your consumption and your provider.

Claude APIOpenAIGeminiMistral

You want 100% local AI

The model runs on your GPU or your server. No prompt leaves your network.

DeepSeekQwenLlamaMistral
Compatible runtimes

Ollama

The simplest. One command to start.

LM Studio

Graphical interface. Ideal for testing.

vLLM

Maximum performance. Multi-GPU.

Text Gen WebUI

Flexible. Large community.

Any runtime exposing an OpenAI-compatible API (/v1/chat/completions) is supported.

MCP connectors · Custom engagement

Your agents plug into your tools — via a Zero-Trust Proxy

MCP (Model Context Protocol) lets your agents communicate directly with your internal tools. But your agents never connect directly to your systems. Every request transits through our Proxy Aggregator NextGen — a single foundation that filters, authenticates and routes each call to the target system.

Application-level Zero-Trust architecture

AI agents

CyberForge, OpsForge, LeadForge... Each agent only has access to the Proxy.

Proxy Aggregator NextGen

Authentication, filtering, rate-limiting, audit trail. Single control point for the CISO.

AuthN/AuthZ Rate Limit Audit Log

Your IT estate

SIEM, AD, GLPI, CRM, ERP... The tools only receive validated requests.

Zero direct attack surface. No agent has credentials to your tools. The Proxy is the only component authorized to communicate with the IT estate — the CISO has just one point to audit and monitor.

On-demand startup — zero RAM footprint

Default state: off

Each MCP connector is registered but its process is never started at boot. Memory footprint: 0 MB.

On-demand wake-up

When an agent strictly needs the connector, the Proxy performs an on-demand startup in a few milliseconds. The MCP connection is negotiated on the fly.

Auto-shutdown after inactivity

An automatic cleanup monitors inactivity. After a period of inactivity, the process is terminated cleanly. RAM is fully released.

From the IT estate to the operational agent
01

IT estate audit

We identify your tools and your security constraints.

02

Proxy Aggregator

Centralized routing, filtering and audit foundation.

03

MCP connectors

On-demand bridges to each tool in the IT estate.

04

Operational agent

The agent reads, acts — supervised by the Proxy.

See concrete use cases by industry →

Modules & dependencies

Compose your solution

Each module is independent. You take only what you need. Here's what each module requires to work.

Available modules and their dependencies
ModuleAI requiredInternetClient tool accessWhat works without AI
Central HubAuthentication, dashboard, routing NoNoNoEverything
LeadForgeB2B prospecting, CRM, scoring OptionalYesNoSearch, CRM, scoring, pipeline
Audit dashboards (x6)MSP, ESN, CIO, MSSP, Accounting, Recruitment OptionalNoNoQuestionnaire, scoring, gaps, correlations
Expertise centers (x5)Cyber, Ops, Compli, Data, Lead YesYesNoMarket, ForgeGuard CVE
MCP connectorsSIEM, GLPI, AD, accounting, ATS... YesNoYes
Agent MonitorReal-time dashboard, audit trail, alerts NoNoNoEverything
Not required Optional — the module works without it, but some AI functions are disabled Required
Example configurations

A few typical configurations. Each solution is composed custom to your need.

Prospecting

Find and qualify clients.

  • Hub + LeadForge
  • Optional AI (auto emails)
  • No tool access required
2 servicesLightweight & fast

Audit

Score and pitch to your clients.

  • Hub + 1 to 6 audits of your choice
  • Optional AI (auto quotes and reports)
  • No tool access required
StandaloneWorks without AI or Internet

Expertise

Specialized agents by domain.

  • Hub + 1 to 5 Forges of your choice
  • AI required
  • Internet for GitHub monitoring
ScalableContinuous skill growth

Audit + Expertise

Diagnosis and remediation.

  • Hub + Audits + Forges
  • AI required for the Forges
  • The audits correlate with the Forges
End to endThe audit identifies, the agents remediate

Full pipeline

From audit to action in your IT estate.

  • Everything + MCP connectors
  • AI required + internal tool access
  • Agent Monitor included
OperationalThe agent acts in your tools

White-label

Resell under your own brand.

  • Any configuration above
  • Branded with your name
  • Redistributable to your own clients
ResellingOur engine, your brand
Ready to deploy?

Let's deploy your agents in your infrastructure.

Book a slot for a personalized demo or a deployment scoping session in your environment — VM, private cloud or SaaS.