Skip to main content
Forge turns your existing network into an agentless control point for AI. A firewall, SASE platform, or secure web gateway can automatically route selected AI traffic through Forge, where the LLM Gateway and MCP Gateway apply policy without requiring users to reconfigure their applications or install software on every device. The same policy and evidence model also covers native network controls, explicitly configured gateways, and Forge on managed devices. You can use one deployment model or combine them to match how your organization works.

Choose a deployment model

Agentless network routing is the recommended starting point when supported traffic already passes through a compatible network platform. Forge on managed devices extends that coverage beyond the corporate network, while explicit gateways give application owners direct control over integrations.

Agentless network routing

Forge works with your network platform to identify selected AI destinations and route their traffic to the appropriate Forge Gateway. Users continue to access ChatGPT, Claude, Gemini, coding agents, model APIs, and MCP tools through their usual interfaces. Forge recognizes the destination and protocol, evaluates the request with the user’s identity and your policies, and forwards allowed traffic to the original service. The organization chooses which destinations are routed and manages certificate trust through its existing TLS-inspection process. This provides content-aware enforcement without installing Forge on each endpoint or asking teams to replace their existing AI tools.

Native network enforcement

Forge can also compile Access policies directly to a connected firewall, SASE platform, or secure web gateway. These controls cover the broader catalog of AI applications and enforce access at the network edge without redirecting content to Forge. Native enforcement and agentless routing complement each other: use native controls for broad application access, then route selected traffic when you want content-aware policy, detailed sessions, or MCP tool governance.

Forge on managed devices

Forge on devices extends governed routing to enrolled Windows and macOS endpoints, including devices away from the corporate network. It also connects traffic to the initiating device and process, discovers local AI products and configuration, and supports health and lifecycle operations through Fleet. Administrators choose which devices use managed routing. Supported desktop, browser, developer API, and MCP traffic is sent to the same LLM and MCP Gateways used by agentless network routing. Other traffic keeps its normal route. See Forge for devices for setup.

Explicit gateways

Applications and workloads can connect directly to the LLM Gateway or MCP Gateway. This model is useful for developer APIs, shared services, and MCP clients whose endpoints are centrally configured. The LLM Gateway manages provider access, models, budgets, and content policy. The MCP Gateway controls which servers and tools each user or workload can access. Both produce a consistent session and audit trail alongside traffic routed from network and device control points.

Shared policy and evidence

Every deployment model connects to the same Forge control plane. Forge combines identity, application, device, and configuration context from connected enterprise systems, then uses that context across policy, investigations, and operations. Source records retain their origin and observation time as Forge correlates identities, devices, applications, workloads, and sessions. Sensitive session content follows the organization’s evidence-retention settings, and secrets are resolved only by authorized collectors and runtime components. Review LLM Gateway, MCP Gateway, Privacy, and Audit Log for the controls that apply across these deployment models.