The Autonomous Anvil — a glowing forge anvil etched with circuit traces and FORGE branding, throwing sparks as defences are hammered out
The Forge Pipeline

Shield enforces. Forge learns. Crucible proves. Blackbox explains.

How Thuban turns real-world AI incidents into verified endpoint protection at machine speed.

Nine steps between a headline and a signed release.

This is not AI reading the news. It is a controlled machine-speed security research pipeline — every step logged, every step gated.

The Autonomous Anvil dashboard: CVE, npm and GitHub threat feeds flowing in on the left, pipeline stages of verification, forging, testing and defence deployment on the right, with a Time to Defence 4h 23m countdown
1

Signal appears

A report, advisory or disclosure enters the system from a source with a known trust tier.

2

Provenance checked

The source is classified against the trust tiers before anything else happens.

3

Corroborated

Independent confirmation is required. One unverified post never moves the pipeline forward alone.

4

Safely reproduced

Forge attempts to reproduce the incident in isolation — no production access, no live credentials.

5

Defence generated

A candidate protection rule is drafted. It is an untrusted artefact, not a shipped fix.

6

Attacked by Crucible

The candidate is thrown against adversarial variants to see if it actually holds up.

7

Regression tested

The candidate must not break existing protections or legitimate workflows.

8

Human approved

A person signs off. The machine does not mark its own homework.

9

Signed release

Only now does the protection cross the release boundary and reach your machine.

Not every report is equal.

Every signal entering Forge is classified before it can influence anything.

TIER 1 · AUTHORITATIVE

Vendor advisories, CVE/NVD, CISA, OWASP, NIST, maintainer disclosures, peer-reviewed research.

TIER 2 · REPUTABLE

Established cybersecurity publications, named researchers with evidence, major news organisations, IR company reports.

TIER 3 · UNVERIFIED

Social posts, forums, anonymous claims, blogs without technical evidence, auto-generated summaries.

Tier 3 can trigger research. It can NEVER trigger protection.

One invented story cannot become a protection rule.

A malicious actor should not be able to invent a story and cause Thuban to block legitimate commands across thousands of machines.

One reputable story
Observe
Multiple independent credible sources
Investigate
Vendor advisory or successful reproduction
Generate candidate defence
Crucible pass + human approval
Release

Even Thuban's own AI is not trusted by default.

Forge is treated as a potentially hostile research laboratory. Generated protections are untrusted artefacts until they cross the release boundary.

Autonomous Anvil assembly line rendering candidate defences stage by stage inside an isolated research laboratory
NO signing keys
NO deployment credentials
NO customer secrets
NO write access to main repo

Not every threat gets the same response.

Confidence determines action. Nothing gets blocked on a hunch.

OBSERVE

Unconfirmed or poorly documented reports: add telemetry, increase logging, create research tasks. Do not block anything.

WARN

Credible but incomplete threats: alert user, require approval, offer temporary high-security mode, add expiring narrow rules.

BLOCK

Reproducible high-confidence threats: ship signed enforcement rules, record Crucible test results, provide rollback and compatibility data.

The public proof that machine-speed defence works.

A worked example of what a real Forge run will show on the dashboard.

Global threat map monitors behind the Autonomous Anvil, tracking incidents feeding the Time to Defence countdown
Incident published08:10
Reproduced09:04
186 variants tested10:22
Protection approved11:47
Signed update released12:02
Time to Defence3h 52m

See the live Time to Defence dashboard →

Protect your codebase in the next 60 seconds.

No install, no config files, no signup required.

$ npx thuban shield init

Click to copy