Anvil
Software Factory
Mission impact
Anvil turns software delivery into a repeatable, auditable capability that your organization owns outright — a force multiplier for programs that must build and ship at pace under regulatory and classification constraints. By keeping the entire pipeline inside your sovereign boundary and enforcing provenance at every stage, Anvil reduces supply-chain risk, removes dependence on commercial SaaS toolchains, and gives program leadership defensible evidence of how every artifact was built and released.
In regulated and air-gapped environments, software delivery velocity and operational control are too often treated as competing priorities.
Anvil is the name for scoped software-factory environments Wilkes & Liberty implements inside a customer-controlled boundary. The engagement can integrate source control, continuous integration, automated testing, artifact management, security gates, and controlled release into one governed pipeline. Requirements determine the supported components, accreditation boundary, disconnected-operation needs, and relationship to the customer’s infrastructure.
What Anvil Provides
- Air-gap-deployable pipeline — the complete CI/CD capability deploys inside the authorization boundary with no external dependency, on classified networks and disconnected enclaves alike.
- Security gates at every stage — integrated static and dynamic analysis, container scanning, and dependency auditing enforced continuously through the pipeline, not as a final checkpoint before release.
- Provenance and chain-of-custody — artifact management with SBOM generation and build provenance, producing the documentation program offices and Inspector General reviews require.
- Governance built in — a delivery-process framework and documentation set that gives program managers a defensible, auditable process satisfying acquisition oversight requirements.
The engineering practice behind Anvil is DevSecOps. Engage that practice to assess or improve an existing delivery system; use the Anvil scope when the work calls for an integrated software-factory environment with documented ownership and operations.
Key capabilities
Secure CI/CD pipeline automation with branch-based promotion and environment isolation — no external SaaS required
Secure CI/CD pipeline automation with branch-based promotion and environment isolation — no external SaaS required
Container registry with integrated image scanning and vulnerability detection before any artifact reaches deployment
Container registry with integrated image scanning and vulnerability detection before any artifact reaches deployment
Infrastructure-as-Code integration with automated testing gates at every pipeline stage
Infrastructure-as-Code integration with automated testing gates at every pipeline stage
Air-gapped software delivery designed for classified and disconnected environments
Air-gapped software delivery designed for classified and disconnected environments
Static analysis, SAST/DAST, and dependency auditing built into every pipeline stage by default
Static analysis, SAST/DAST, and dependency auditing built into every pipeline stage by default
Artifact management with full provenance and chain-of-custody records for compliance and audit
Artifact management with full provenance and chain-of-custody records for compliance and audit