Platform licensing

The canonical data layer for industrial AI.

Your platform connects to equipment.
Forge makes every vendor's data mean the same thing, and proves it.
985 canonical fields defined · 366 resolvable today. 2,086 mappings in production.
Your brand. Your deployment. Our corpus.

985Canonical fields defined
2,086Mappings in production
45Vendor packs
19Verticals

Three different counts, because they measure three different things. 985 fields are defined in the production registry (/health layers.registry.fields). 366 is what resolution can currently emit, and 619 of the 985 have no vendor mapping behind them yet. The published MIT schema is a fourth number again, 694 at v2.1.0: github.com/FoundryNet/canonical-schema. We publish all four rather than pick the flattering one.

The vendor-side count gets the same treatment. We quote 45 vendor packs across 19 verticals because both are computed by the live kernel and returned by an endpoint you can call without a key (GET /v1/coverage, vertical_packs). We used to say “18 OEM families”. That number was a hardcoded literal in the kernel and it counted neither manufacturers nor canonical field families — it was withdrawn from /health on 2026-10-04 rather than restated, because a corrected version of a field that named nothing would have kept the ambiguity alive. For reference: the union of the OEM sets the engine recognises is 85, and the number of OEMs with actual corpus vocabulary is 8. That last one is the smaller, truer number, and it is the one to argue with.

13Protocol adapters

Verify it before you talk to us. Every production number on this page is returned by an endpoint that needs no key, no account and no call with us (curl -s https://forge.foundrynet.io/v1/coverage), and the engine itself is a public image. The free sandbox resolves 719 canonical fields and 3,444 mappings across 29 OEM packs, including robotics, AMR and J1939 fleet, on your own machine, no key and no time limit. docker pull ghcr.io/foundrynet/forge-sandbox

Start the conversation → Test it against your data first →

The gap

Every vendor you add is another integration project.

Your engineers spend 6-18 months per OEM.

Cost you already carry

Your competitors are shipping cross-vendor.

Deadline you don't control

Your customers are asking for it.

Demand already in your pipeline

Cross-vendor support is not a feature you ship once. It is a permanent maintenance surface: every new OEM, every firmware revision, every renamed tag, every unit change lands on your roadmap. The work never converges, and it never becomes your product.

6-18 months per OEM is the conservative end of that range, and it is not our number. The protocol adapter is the easy part: days to weeks per machine family, which is why Kepware ships 150+ drivers and Litmus ships 250+. What takes the time is the semantics: the per-vendor tag vocabulary, the unit declarations, the sentinel codes and the conflict resolution behind every mapping. On that unit of work the public record is unambiguous. ODVA and the OPC Foundation announced a CIP-to-OPC-UA companion specification in April 2020; ODVA's live page still says, present tense, that the working group “is working to identify critical device-to-cloud use cases which will drive the scope of the work to be done”: roughly six and a half years, nothing published. VDMA's Glass Technology Forum stood up its working group in 2019 and released OPC UA 40301 for flat-glass processing in January 2022: about three years, for the first module of one specification. That is the shape of the cost, and it accrues per vendor you support.


Before you ask

The corpus is not the moat. We published it.

The canonical schema and all 16,908 tag mappings are MIT-licensed and public, and have been since the first commit on 2026-08-10: github.com/FoundryNet/canonical-schema. Clone it, fork it, ship it in your product. We would rather tell you that than have you discover it after signing something.

The public file is in some ways richer than our private table: it carries type, unit, description, physics_bounds, accepted_input_units, value_mappings and provenance per field. So a vendor telling you their mapping dictionary is the defensible asset is either not ours, or has not read ours.

What is not published, and why it is the part that matters

Decoder tier21 decoders Per-vendor state, polarity and enum decoding: 9 states, 21 decoders, 12 commands. A Haas controller reports a door bit where 1 means open; Fanuc and Siemens report the same measurement where 1 means closed. A name-level mapping gets both tags to door_state and then hands your agent the opposite answer on two thirds of the fleet. Only 4 of the 694 published fields carry any value_mappings at all.
Layer orderLayer 1 first The curated layer is consulted before anything probabilistic, so under a pinned corpus version a tag resolves to the same field at the same confidence. A dictionary does not give you that; an engine that orders its layers does. We hold it to a 33-test harness (tests/test_corpus_determinism.py) rather than to an assertion, and that harness, with the resolution fixes it pins, is not in the shipped build yet. Ask which build you are getting before you rely on it.
CitabilityPer field Every resolution returns which layer answered, at what confidence, and from which source tag, and abstains instead of guessing below the floor. That record is what makes a mapping arguable with an engineer who disagrees with it.

So what you license is the engine, the vendor packs and their signing keys, the embedding index, and the decoder tier. Not the dictionary. The dictionary is a gift, and it is the cheapest way we know to show you the hard part is underneath it.


The engine

What you are licensing.

Industrial AI models are probabilistic. Run the same question twice and the answer can change. The engine underneath one should not work that way, and most of what you are licensing is the machinery that refuses to guess.

WritesNone Forge never writes to equipment; your safety systems stay in control. Not a policy, an absence you can verify yourself. Across all five protocol stacks in the licensed kernel there is no OPC UA write, no Modbus write-register or write-coil, no CIP set-attribute, no MAVLink command and no BACnet writeProperty. Grep the image for the write primitives and the only hit is a regex in logging_setup.py that redacts the string WriteValue(…) out of logs. The BACnet adapter polls presentValue and nothing else.
Refusals7 named When Forge cannot establish a value it refuses to guess, and says which of seven named reasons applied: no candidate at all, below the confidence floor, failed a deterministic guard, unstable across calls, failed physics, incompatible unit, or filtered as a lab annotation. The grading goes further than most buyers expect. corpus_version.py maps every model-derived match type (vector, signal, llm_inferred) to refuse, so anything a model decided is marked as such and is never settlement-grade. All of that is live today. What is not covered: refusal here means “not resolved, not settlement-grade”, not that your request errors; and abstention on derived metrics such as a health index is built but not yet shipped.
ConflictsVendor-level The same raw value can mean opposite things on two machines. Door polarity, enum codes, scaling and protocol paths live in the corpus, versioned and reviewable, not buried in adapter code. Some entries are a named rejection: robot.safe_position is explicitly disabled, because a stationary arm parked inside the envelope reads clear and is not, and the rejection is retained so nobody re-adds it.

Corpus growth, by design

An unrecognized tag resolves, gets cached, and is designed to graduate into a deterministic vendor pack once it has earned it. The promotion gate is deliberately high (ten mappings for one OEM, each used at least five times at 0.90+ confidence) and nothing has met it yet. So every mapping in production today is curated by us, not self-generated. We would rather tell you the flywheel has not turned than sell you one that has not.

Unit conversion, in the one order that works

Fahrenheit, PSI, Wh and inches are converted to a single SI basis, in the one order that works: sentinel codes are caught on the raw wire value before conversion can launder them (65535 Wh becomes 65.535 kWh, which matches no sentinel and passes every check below it), and bounds are checked after, in the field's own unit, because a raw 200 °F tested against a Celsius range would reject a real 93.3 °C reading. 357 conversions, and the ordering is pinned by tests including one that asserts the wrong order would let a sentinel through.

Unit provenance, three states

Declared by the device, assumed from the vendor pack, or not established. Units are never inferred from the value, and every field reports which of the three it got. 174 of the 366 emittable fields carry a declared unit today; the rest say the unit was not established rather than assuming one. The third state is the point: a guess that looks like a declaration is worse than a blank.

Bounds and sentinels, with the coverage

Values are checked against declared physical bounds and 37 known sentinel codes (65535, 9999, −273, 0xFFFF), so a vendor’s “no reading” placeholder is not charted as a measurement. Not every value, and we will show you which: 432 of the 985 canonical fields carry a declared range today. The rest fall back to a bound for their physical quantity, and those are type limits rather than machine limits, wide enough that “checked” against them is close to not checked. We publish which is which per field.

Every answer carries its provenance

Every field comes back with which layer answered, at what confidence, and from which source tag. Every response carries a hash taken over the answer with the corpus version and the corpus-state index sealed inside it, so a record always names the exact decision surface behind it. The published recipe for checking it is two lines. One limit, stated plainly: we do not yet archive the index itself, so a record names its decision surface but cannot replay against it once the container that computed it is gone.

MCP-native

The engine speaks Model Context Protocol as a first-class transport (32 tools, the same set over REST and over Streamable HTTP), so the AI agents your customers are already building can coordinate against normalized equipment data without a bespoke adapter.

Unrecognized tags are recorded, not routed

Unrecognized tags are recorded per machine with the reason they could not be resolved, and unrecognized vendors are queued for corpus work. Documented vendor identifiers become pack mappings with the manual cited; integrator-invented names become a site mapping. Review is done by us, not automatically: there is no work-order queue in the product, and we would rather you heard that from us than find it.

Signed corpus updates

Corpus updates are signed and the kernel refuses to apply an unsigned or mis-signed delta: the signature is checked before the payload is parsed, which is the only order that helps. What a signature buys you depends on the key: under a shared development key it detects accidental corruption; it detects tampering only when the key is one you do not hold. Keys are configured per deployment and we will tell you which key your releases are signed under.

Action gating: federation layer, not the kernel

Forge can gate a proposed action on machine state it has actually verified: a precondition check that refuses when the state it needs is unresolved, and that will not enter live mode on a signed config alone. It ships with the federation layer, not with the normalization kernel you are licensing here. Ask us for the current status rather than assuming it is in the container.

One container. And the coverage number, before you ask for it.

Point it at a machine and it resolves what the vendor packs cover. How much that is depends entirely on whose tags you send, so here is the measurement rather than the adjective. In September 2026 we put 3,734 distinct tag names through this engine, taken verbatim out of Haas, FANUC, Siemens, MTConnect and OPC UA’s own published manuals: names only, no values, no vendor hint beyond the family, which is exactly what a historian export gives you. Seven of the twelve cohorts are shown.

Haas MDC40.0% 12 of 30 names. Mill Operator’s Manual (NGC) 2022, §9.2.11, Machine Data Collection query labels. This is the best cohort.
FANUC FOCAS13.6% 17 of 125. Documented struct members in fwlib32.h.
MTConnect13.4% 29 of 216 observation types, Standard Part 2.0.
Haas macros7.1% 7 of 98 numbered system variables, same manual, §6.13.7.
OPC UA machine tool3.8% 9 of 237 nodes, OPC 40501-1 nodeset. With no OEM hint at all: 0.0% at high confidence.
Siemens sysvars0.68% 12 of 1,774 system variables, SINUMERIK 840D sl / 828D Parameter Manual (LIS3, 03/2013). This is the worst cohort.
Our own corpus100.0% 869 of 869 pack-native keys across Haas, FANUC and Siemens. This is the number a vendor quotes you when they have only ever tested themselves. We had been measuring ourselves with our own dictionary.

So we do not claim vendor-native tags resolve out of the box, and we do not sell this as zero-configuration. Tags the packs do not carry get a site mapping; documented vendor identifiers we are missing become corpus work with the manual cited. At 0.68% on Siemens system variables the site-mapping path is doing the main work, not the exception work, and any vendor telling you otherwise has not run this measurement or has not published it. We will tell you the number for your own fleet before you buy it: that is what the pilot produces, and it is why there is no coverage floor and no coverage-contingent fee anywhere in this offer.

The math

Build it, license it, or ship it.

Building it $600K-$850K Two senior software engineers for eighteen months: $600,000-$850,000 fully loaded, in the US. Three person-years against the BLS Occupational Outlook Handbook for software developers (median $135,980; 75th percentile $171,980) and Levels.fyi US median total compensation ($196,000), loaded by the employer benefit cost in BLS Employer Costs for Employee Compensation, June 2026. Buying the same three person-years on a federal schedule costs more, not less. And the corpus starts empty on day one of month nineteen, which is the part that never appears in the salary line.
Licensing it $0.15 per 1,000 normalized events Usage-based licensing: $0.15 per 1,000 normalized events, graduating to $0.03 at scale. Annual platform license sized to your deployment. Scales with your deployment, not your headcount.
Shipping it Days to the container
weeks to the coverage
The container drops into your stack in days: one image, one endpoint, nothing to compile against. What takes longer is the part worth paying for: measuring your own tag set, resolving the unit conflicts and sentinel codes it turns up, and writing the site mappings for whatever the packs do not carry. Your team keeps its roadmap either way.

Annual Platform License: from $150,000. The base license includes core engine deployment, white-label rights with named-account channel protection, and signed corpus updates. Annual terms beyond the base are scoped per deployment.

Graduated tiers: normalized telemetry events, per 1,000
First 100M$0.15
100M-1B$0.12
1B-10B$0.09
10B-50B$0.06
Above 50B$0.03

A Normalized Telemetry Event (NTE) is each individual tag-value pair submitted for resolution: a request carrying N tag-value pairs is N NTEs. Tiers are graduated, not flat: the first 100M events bill at $0.15 per 1,000 regardless of total volume, and only events above each threshold bill at the next rate. Like tax brackets, the bill is always monotonically increasing.

Premium actions (predict, diagnose, fleet health, integrity proof) are priced explicitly on the public rate card rather than quoted case by case. Usage is uncapped; budget alerts are available.


The proof

Don't take the number. Take the container.

The sandbox is the same engine, running locally, with no key and no account. Send your vendor's tags. See what comes back.

docker pull ghcr.io/foundrynet/forge-sandbox
docker run -p 8000:8000 ghcr.io/foundrynet/forge-sandbox
# your vendor's tag names, your payload shape, no key, no account
curl -X POST http://localhost:8000/v1/normalize \
  -H "Content-Type: application/json" \
  -d '{"oem":"haas","data":{"S SPEED (RPM)":8500,"COOL_TEMP [°F]":161.8}}'
{ "spindle_speed_rpm": 8500,
  "sensor_readings.coolant_temp": 72.1111,  ← °F converted, not relabelled
  "coverage_pct": 100.0 }

Evaluating the engine is running the engine. There is no proof-of-concept phase to schedule, because the artifact your engineers would evaluate is the artifact you would license.


The architecture

Built for a deployment you don't own.

Your platform runs inside your customers' networks. So does the engine, on their terms, and the security review they will put you through is the one this was designed to pass.

No inbound connections from us

Forge reaches our control plane over outbound HTTPS; nothing has to be opened to the internet for it, and there is nothing for your customer to firewall-punch on our behalf. Two listeners do exist inside their network and we would rather name them: the container serves its own API on 8080/tcp, and if you enable the BACnet adapter it binds the standard BACnet/IP port (UDP 47808) and registers a BACnet device on the local segment, because BACnet/IP is a LAN broadcast protocol and has to be polled from the edge.

Works behind any firewall

Air-gapped, DMZ, or plant network. The engine does not need to be reachable to be useful.

Remote corpus updates. No restart required.

New OEM coverage lands as corpus, not as a version bump, and the sequence is the interesting part: the delta's HMAC is verified before the payload is parsed, the apply is an atomic os.replace onto a temp copy rather than an in-place write, the new mappings are mirrored straight into the live in-memory resolution layer, and the cache epoch is bumped so stale resolutions drop on the next read. No process restart is involved anywhere in it. Your customers get vendor support they never scheduled a maintenance window for.

Corpus updates carry tag names, never values.

Not one process value is part of a corpus update, and a field name that is still identifying after scrubbing is dropped rather than sent. Attestation sends hashes and a count. The licensed container has no LLM egress at all. Grep it for an AI provider and you get nothing. Values leave the network only where you configure an export: a webhook or an MQTT publish to a destination you choose. We say “corpus updates” rather than “never” because the exports are a feature you asked for, and a blanket claim would be false the first time somebody used one.

Read-only by design. The engine reads equipment data. It never sends commands. Nothing it does can control, alter, or damage a machine.

We license to platforms. We don't sell to your customers.

Your brand throughout. No Forge branding required. Your sales team deploys. Your support team supports. We maintain the engine and the corpus. That is the whole arrangement, and it is the whole company.

Channel protection is priced in, not promised.

Our public API is $0.30 per 1,000 normalized events. Your platform rate is $0.15. The API rate is exactly twice the platform rate at every tier: standard channel economics, so you are never undercut by your own supplier, and any developer who outgrows the API becomes a licensing conversation, not a competitor.


Contact

Start with a 30-day paid pilot.

$25,000. Full engine. Your tags. 30 days. Credited in full against year one if you proceed. What it buys is the measurement: the coverage number for your own tag set, every unit conflict and sentinel value behind it, and a canonical schema you keep. Prove it on your own data before you sign anything.

Book a 20-minute technical intro →

Or email foundrynet@proton.me

Tell us what your platform connects to today, which vendors your customers keep asking for, and where the engine would sit in your deployment. We will tell you within a week whether the corpus already covers them.

Usage-based, sized per platform · No per-machine pricing under a platform license · We never sell to your customers


Related

What the engine already covers.

Vendors in the corpus

45 vendor packs across 19 verticals, 2,086 mappings in production.

Fanuc Siemens ABB KUKA Haas Mazak All OEMs →

Protocols in the engine

13 industrial protocols, one canonical output.

Of the 15 transports the kernel declares, 13 are available: MQTT Sparkplug B reads metrics but does not yet decode protobuf payloads, and SNMP and Modbus RTU ship no client. Reach serial through a Modbus TCP gateway.

OPC UA Modbus TCP MQTT / Sparkplug B MTConnect EtherNet/IP All protocols →
Get the thesis behind this infrastructure: The Machine Agent, weekly.