Platform

Anvil

Software Factory

Anvil is the Wilkes & Liberty software factory platform for rapid, repeatable software delivery inside a sovereign boundary, spanning continuous integration, automated testing, artifact management, and controlled release.

Mission impact

Anvil turns software delivery into a repeatable, auditable capability that your organization owns outright — a force multiplier for programs that must build and ship at pace under regulatory and classification constraints. By keeping the entire pipeline inside your sovereign boundary and enforcing provenance at every stage, Anvil reduces supply-chain risk, removes dependence on commercial SaaS toolchains, and gives program leadership defensible evidence of how every artifact was built and released.

In regulated and air-gapped environments, software delivery velocity and operational control are too often treated as competing priorities.

Anvil is the name for scoped software-factory environments Wilkes & Liberty implements inside a customer-controlled boundary. The engagement can integrate source control, continuous integration, automated testing, artifact management, security gates, and controlled release into one governed pipeline. Requirements determine the supported components, accreditation boundary, disconnected-operation needs, and relationship to the customer’s infrastructure.

What Anvil Provides

  • Air-gap-deployable pipeline — the complete CI/CD capability deploys inside the authorization boundary with no external dependency, on classified networks and disconnected enclaves alike.
  • Security gates at every stage — integrated static and dynamic analysis, container scanning, and dependency auditing enforced continuously through the pipeline, not as a final checkpoint before release.
  • Provenance and chain-of-custody — artifact management with SBOM generation and build provenance, producing the documentation program offices and Inspector General reviews require.
  • Governance built in — a delivery-process framework and documentation set that gives program managers a defensible, auditable process satisfying acquisition oversight requirements.

The engineering practice behind Anvil is DevSecOps. Engage that practice to assess or improve an existing delivery system; use the Anvil scope when the work calls for an integrated software-factory environment with documented ownership and operations.

Key capabilities

  • Secure CI/CD pipeline automation with branch-based promotion and environment isolation — no external SaaS required

    Secure CI/CD pipeline automation with branch-based promotion and environment isolation — no external SaaS required

  • Container registry with integrated image scanning and vulnerability detection before any artifact reaches deployment

    Container registry with integrated image scanning and vulnerability detection before any artifact reaches deployment

  • Infrastructure-as-Code integration with automated testing gates at every pipeline stage

    Infrastructure-as-Code integration with automated testing gates at every pipeline stage

  • Air-gapped software delivery designed for classified and disconnected environments

    Air-gapped software delivery designed for classified and disconnected environments

  • Static analysis, SAST/DAST, and dependency auditing built into every pipeline stage by default

    Static analysis, SAST/DAST, and dependency auditing built into every pipeline stage by default

  • Artifact management with full provenance and chain-of-custody records for compliance and audit

    Artifact management with full provenance and chain-of-custody records for compliance and audit

Related solutions