Factory for Enterprise
Deploy, secure, govern, and observe Droid across cloud, hybrid, and fully airgapped environments.
Factory helps enterprise teams run Droid across developer laptops, CI runners, VMs, Kubernetes clusters, and airgapped networks without losing central control.
Use this section to decide where Droid runs, which models and tools it can use, how identity and policy are enforced, and how platform teams measure activity at scale.
Enterprise playbook
Start with the path that matches the decision you need to make.
Choose cloud, hybrid, or airgapped deployment patterns, then configure proxies, certificates, mTLS, regions, and secure runtimes.
Bound agent behavior with command policies, hooks, sandboxing, Droid Shield, and CLI security defaults.
Manage identity, Enterprise Controls, model access, MCP servers, plugin registries, and service accounts.
Export OpenTelemetry metrics, use the Analytics API, and map Droid activity to audit and compliance workflows.
Core model
Droid is a local agent runtime governed by managed settings and observable through product telemetry.
- Deployment is flexible. Droid runs where your code already lives, with cloud, hybrid, airgapped, EU, proxy, and certificate patterns.
- Data paths are explicit. Code and files stay local unless selected context is sent to a configured model or gateway, as described in Data Flows & Privacy.
- Controls are centralized. Enterprise Controls & Managed Settings define model access, command policies, MCP allowlists, hooks, sandbox policy, retention, and feature toggles.
- Safety is layered. Deterministic controls, hooks, sandboxing, and Droid Shield reduce risk before model behavior matters, as covered in Agent Safety & Controls.
- Measurement is structured. Droid emits OpenTelemetry metrics and exposes hosted analytics for adoption, activity, and cost reporting, per Telemetry & Analytics.
These controls let teams adopt Droid incrementally while keeping higher-risk workloads inside stricter environments.
Trust
Factory maintains a security and compliance program for enterprise procurement and regulated deployments:
| Program | Scope |
|---|---|
| SOC 2 Type II | Security and availability |
| ISO 27001 | Information security |
| ISO 42001 | AI management systems |
Find current reports, subprocessor lists, and security architecture details in the Trust Center.
For audit mapping and regulated-deployment patterns, see Compliance & Audit.