● In production inside iTmethods
Dark Factory
Governed Autonomous SDLC
The agents were never the hard part.
Governing them at scale is.
Dark Factory is a licensed platform for governed autonomous software development. Customer deployments begin with a bounded proof. It integrates with the tools your teams already use and runs autonomous AI agents in isolated sandboxes with a human approval gate before every merge. Paired with Reign, every action is sealed as tamper-evident, examiner-ready evidence.
Internal observations from iTmethods’ own production factory, on suitable work
5–7×
Effective engineering output, on suitable work
~21 hours
Median cycle time, ticket to production, on suitable work
0 reverts
across 922 merges
100%
Human-approved merges, across the same 922
Measured on iTmethods’ internal suitable-work population, across 922 merges of our own production use. These are internal observations, not a customer benchmark and not a general result. What Dark Factory does on your estate is established by a bounded proof on one of your own workflows.
● LIVE · Click the console to watch the 75-second walkthrough. Every agent action observable, every merge human-approved; paired with Reign, every action sealed to a tamper-evident ledger.
Why now
Everyone has agents.
Almost no one can govern them.
The real challenge isn't building with agents. It's running them at production scale with control, evidence, and compliance.
Pilot purgatory
Most teams can't move agentic work into production while meeting governance and audit requirements.
Tool sprawl & cost
Enterprises run 300+ SaaS tools at under 50% utilization, creating massive hidden spend.
Regulation is here
OSFI E-23 and the EU AI Act now require runtime governance and evidence for autonomous systems.
How it works
File a ticket. Agents build it.
You approve. It ships.
Work is pulled from the trackers you already use. A Supervisor routes each eligible ticket to an AI worker running in an isolated sandbox. The worker completes the change and runs every quality gate. A finished merge request waits for one required human approval before shipping. Where the factory is paired with Reign, the full run is also captured as evidence.
From tracker to production, each ticket goes to an AI worker in its own isolated sandbox (reproducible, contained, zero blast radius); the finished change arrives as a merge request and waits on a human before it merges. Paired with Reign, every step is governed at runtime and sealed as tamper-evident evidence.
Velocity
Ship in hours, not weeks
Control
Human approval on every change
Cost
Integrate now. Consolidate later.
See it run on your toolchain.
Open by design
Your stack, governed.
Your choice of coding agents, flexible, independent and open, never locked into one vendor, model or cloud. Dark Factory integrates with the toolchain you already run via open APIs, webhooks and MCP, and governs it end to end with Reign.
Coding agents
CursorClaude CodeCodexCopilotDevinFactory
Source control
GitHubGitLabBitbucket
Trackers
JiraLinearPlane
Artifacts
JFrog ArtifactoryNexusContainer registries
CI/CD & security
JenkinsGitLab CISonarQubeSnyk
Runtime & isolation
Isolated agent sandboxesReproducible · contained
Deploy
Hosted dedicatedYour cloudAir-gapped · in development, 2027Any model, any agent
Governed by Reign
Every change, provable.
Reign is the governance layer beneath the factory: it enforces your policy at runtime and records what happened as tamper-evident, examiner-ready evidence. The audit becomes a question you've already answered.
- ✓ Human approval gate. Nothing reaches production without a person. Dark Factory
- ✓ Eligibility, isolation and stop conditions on every run. Dark Factory
- ✓ Runtime policy enforcement on every model and agent action. With Reign
- ✓ Tamper-evident evidence. A sealed ledger for every change, with machine authorship attribution, model metadata and obligation records. With Reign
- ✓ Deploy dedicated. Hosted dedicated or your own cloud account, with air-gapped in development for 2027.
Dark Factory on its own carries the operating controls: work eligibility, isolated sandboxes, human approval on every merge, and stop conditions. The AI-governance record set described here is present when Dark Factory is paired with Reign. Not every deployment includes it; we scope the configuration to your obligations in the briefing.
Evidence ledger · reign-x4
✓ ticket dispatched · worker claimed✓ code + tests · all gates passed
✓ AI review · fixer cleared
· merge to main → human approved
(sealed to audit ledger)
sha-256 9f2a…c71e · examiner-exportable
Designed against the rules that now govern AI
OSFI E-23EU AI ActISO 42001NIST AI RMFFINOS AIGF
Design alignment to the control expectations in these frameworks, to help you evidence your own obligations. It is not certification, attestation, or an audit opinion under any of them, and it does not replace your own assessment.
Proof
Not a demo. A factory we run ourselves.
Our own production apps already ship through Dark Factory. It is our operating method in production inside iTmethods: governed, evidenced, and faster on suitable work. We're now opening it to a selective 2026 cohort of regulated enterprises, by application, and every customer deployment begins with a bounded proof.
21 Years
Operating regulated infrastructure
SOC 2 Type II
iTmethods corporate certification. Not a certification of Dark Factory or its AI governance.
AWS Advanced
& Validated MSP
Sovereign
Your data, models and agents stay yours
Built on open foundations
Member and contributor in the open standards behind governed AI. The Linux Foundation, FINOS, and the Agentic AI Foundation.



Questions, answered
The questions a regulated buyer actually asks.
What is Dark Factory?
Dark Factory is a licensed platform for governed autonomous software development. It integrates with the trackers and tools your teams already use, runs AI coding agents in isolated sandboxes, and requires explicit human approval before any change merges to production. Dark Factory's own controls cover work eligibility, isolation, human approval, and stop conditions. Paired with Reign, every action is additionally sealed as tamper-evident, examiner-ready evidence. Dark Factory is part of the Forge portfolio from iTmethods.
How is Dark Factory different from AI coding tools like Copilot or Cursor?
Coding assistants help one developer write code. Dark Factory runs the whole delivery workflow: a Supervisor pulls tickets from your tracker, dispatches agents that build, test, and security-scan in isolated sandboxes, and holds every finished change at a human approval gate before it ships. It is open by design and works with agents such as Claude Code, Cursor, Codex, Copilot, Devin, and Factory rather than replacing them.
Does Dark Factory keep a human in the loop?
Yes. Nothing reaches production without explicit human approval. Every merge waits for one required human sign-off. Where Dark Factory is paired with Reign, that approval is also sealed to a tamper-evident evidence ledger. The model is governed autonomy, not full autonomy.
Is Reign included, or is Dark Factory governed on its own?
They are separate layers, and the distinction matters for your control mapping. Dark Factory on its own gives you the operating controls: only eligible work is dispatched, every agent runs in an isolated sandbox, every merge clears a human approval gate, and stop conditions halt the run. Reign is the governance and evidence layer. Paired with Reign, you also get machine authorship attribution, model metadata, obligation records, and a tamper-evident, examiner-ready record of every action. If you need the full AI-governance record set, you need the paired configuration. We scope which one fits your obligations during the briefing.
How does Dark Factory support compliance and audit?
Paired with Reign, policy is enforced at runtime and every change is recorded as examiner-ready evidence, so the audit becomes a question you have already answered. That output is designed against the control expectations in OSFI E-23, the EU AI Act, ISO 42001, NIST AI RMF, and the FINOS AI Governance Framework. To be explicit: this is design alignment to help you evidence your own obligations. It is not certification, attestation, or an audit opinion under any of those instruments, and it does not substitute for your own assessment.
Which tools and agents does Dark Factory work with?
Dark Factory is open by design and integrates through open APIs, webhooks, and MCP. It works with coding agents (Claude Code, Cursor, Codex, Copilot, Devin, Factory), source control (GitHub, GitLab, Bitbucket), trackers (Jira, Linear, Plane), CI/CD and security (Jenkins, GitLab CI, SonarQube, Snyk), and artifact registries (JFrog Artifactory, Nexus). You are never locked into one vendor, model, or cloud.
What results does Dark Factory deliver?
The figures we publish are internal observations from iTmethods' own production factory, on our own suitable-work population. They are not a customer benchmark and not a general result. On that suitable work we observe 5 to 7x effective engineering output and a median cycle time of about 21 hours from ticket to production. Across the 922 merges in that population there were 0 reverts, and 100% of merges were human-approved. Work outside the suitable-work envelope is not represented in these numbers. What Dark Factory does on your estate is established by a bounded proof on one of your own workflows, not assumed from ours.
How is Dark Factory deployed?
Two options today. Hosted dedicated is a dedicated environment operated by iTmethods and connected securely to your trust boundary. Customer cloud is deployed and managed inside your own AWS, Azure or GCP account, under your keys and access controls. Air-gapped is in development, targeted 2027. Your data, models, and agents stay yours, with customer-owned model keys. It is delivered and operated with you, forward-deployed by iTmethods.
What ongoing support and guidance does iTmethods provide?
Dark Factory is forward-deployed. iTmethods experts stand it up alongside your teams, tune it to your workflows, and operate it with you. The relationship does not end at go-live: our engineers provide ongoing guidance as your delivery needs, toolchain, and regulatory obligations evolve, keeping the factory and the evidence it produces aligned to the business. You get a dedicated team, not a ticket queue.
How is Dark Factory priced?
Dark Factory is licensed, not sold per seat. Pricing is an annual platform license scoped to your deployment model (hosted dedicated or your own cloud) and the volume of governed work it runs. Every engagement begins with a bounded proof on one of your own workflows, which establishes the result on your estate before any annual commitment. We share specific numbers in the briefing, once we understand your environment and scope.
How do we get started?
Start with a 30-minute briefing. From there we scope a bounded proof on one of your own workflows. iTmethods runs a selective 2026 pilot cohort with regulated enterprises, by application. It is not generally available beyond that cohort.
Pilot cohort · 2026
See it run on your toolchain.
A selective 2026 pilot cohort for regulated enterprises, by application. Every deployment starts with a bounded proof on one of your own workflows. Begin with a 30-minute working session.
Limited 2026 cohort, by application only.