The Forge Line is a set of small, sharp security tools that share one finding format, one brand file, and one workflow — so a scan or a set of notes becomes a branded client report with no retyping. Not a bag of utilities. A line of software.
Every tool that finds problems emits the forge-finding format; the report generator reads it. So a scanner's output is a report's input. Any producer feeds any consumer.
A single brand.yaml — company, accent, contact. Point every tool at it and your scans, digests, and reports all come out looking like they came from one shop. Yours.
The tools map to the real engagement lifecycle. Capture a finding once — from a scan, a monitor, or your notes — and it carries through to the client deliverable.
Buy only what you need — every tool stands alone. But they're built to interlock, and the more you run, the more the line does for you.
Passive external posture scan — DNS, SPF/DKIM/DMARC, TLS, headers — graded and client-ready in about a minute.
View on Gumroad →Turns unreadable DMARC aggregate XML into a plain-English, branded digest — who's spoofing you, what to fix.
View on Gumroad →The always-on version of Anvil. Re-checks your external posture every week and alerts the moment it drifts. Hosted.
Start free scan →A pentester's engagement vault for Obsidian. Capture findings as linked notes; the dashboards build themselves.
View on Gumroad →The consumer. Feed it a scan, your Redline notes, or 10 scanners' raw output — get a CVSS-scored, branded report in seconds.
View on Gumroad →A 14-question interview becomes a WISP, IR plan, AUP, and a scored cyber-insurance readiness gap checklist.
View on Gumroad →Because the tools share a format and a brand file, composing them is two commands. This is the whole trick — and the reason it's a line, not a smattering.
$ anvil acme.com --brand brand.yaml --forge acme.yaml Grade B · risk 3/100 · 1 issue · acme.yaml written $ hammer acme.yaml --brand brand.yaml --out report ✓ Scored 1 finding. report.docx · report.html — in your branding # swap `anvil` for `hearth ./dmarc/` or your Redline export — # same format in, same branded report out.
Capture findings in Redline during the engagement, then export them straight into Hammer for the client report. The capture-to-report pipeline, together.
Every tool in the Forge Line was designed and built by an AI (Claude), and is reviewed, priced, and stood behind by a real team — led by a U.S. Army veteran and Certified Penetration Tester, based in the Augusta / CSRA area. That's the whole pitch: useful tooling, openly disclosed, no pretending. The tools run on your machine and make no network calls unless stated (Anvil Watch is the one hosted service). You are responsible for authorization to test the systems you assess.