Factory
Factory is an agent-native software development platform whose Droids write, review, test and document code across desktop, terminal, web, IDE and Slack, staying independent of any single model provider and running from laptops to airgapped enterprise networks.
What is Factory?
Factory is a platform for what its publisher calls agent-native software development. Rather than autocompleting lines inside a single editor, it puts autonomous agents named Droids to work across the whole delivery lifecycle. A Droid behaves identically on a desktop application for macOS and Windows, in the droid command-line tool, in a browser or on a phone through the web app, inside VS Code, Cursor, Windsurf, JetBrains IDEs and Zed, and from Slack. Every paid plan includes every surface.
The agent is filesystem-native. It reads and patches code on the machine where it runs and treats git as the source of truth; the documentation states that no repository is ever uploaded or indexed into a remote datastore. What leaves the machine is the prompt and the context sent to whichever model endpoint the customer has configured.
Model independence is the second pillar. The catalogue spans Anthropic, OpenAI, Google and xAI alongside an open-weight tier called Droid Core, each entry carrying a published usage multiplier. Customers may bring their own keys, point Droid at AWS Bedrock, Google Vertex AI or Azure OpenAI, serve models inside their own network, or let Factory Router arbitrate between providers.
Around the agent sits a configurable harness: AGENTS.md files, managed connectors for GitHub, Linear, Notion, Slack, Sentry and Google Workspace, MCP servers, skills, subagents, slash commands, hooks and plugins. Missions coordinate multi-agent work over long horizons, and droid exec takes a stabilised workflow headless into CI/CD. Software Factory, in private preview, tracks automation coverage across six stages: triage, code generation, validation, release, documentation and monitoring.
The enterprise half is substantial: single sign-on with SAML and SCIM, autonomy levels, organisation-wide deny lists, sandboxing, audit logs exported to a SIEM, customer-managed encryption keys, an isolated EU deployment and fully airgapped installations. Droid Shield scans staged diffs for secrets, vulnerabilities and intellectual-property leaks before commit and push. Factory reports SOC 2 Type II, ISO 27001 and ISO 42001, and states that customer code is never used as training data.
What it does
- Write, refactor and patch code directly on the local filesystem, with git as the source of truth
- Run automated code review, security review and QA as gates before a pull request is merged
- Launch multi-agent Missions that carry long-horizon work spanning several weeks
- Keep repository documentation current through AutoWiki and answer incidents from alerts
- Triage, deduplicate and route incoming requests from issue trackers and Slack
- Run headless in scripts and CI/CD pipelines through the droid exec command
- Detect and strip secrets, vulnerabilities and IP leaks from staged diffs with Droid Shield
When to use Factory / When not to
A quick filter to help you decide if Factory is the right fit.
When to use Factory
- Enterprise software engineers facing migrations, refactors, test coverage and code review backlogs
- Platform and DevOps teams that need agents inside hybrid, on-premise or fully airgapped environments
- Engineering leaders who want per-model and per-engineer usage analytics and SDLC automation coverage
- Security and compliance teams looking for automated security review, secret detection and audit trails
- Researchers, labs and open-source contributors eligible for the free Factory for Science and OSS programmes
When not to use Factory
- Anyone outside software work: the platform does nothing for general writing, marketing, image or video
- Users wanting a free tool, since the cheapest plan costs 20 US dollars a month and no trial is advertised
- People who need a native mobile app, as the web and mobile surfaces both run through the browser
- Non-technical users unwilling to read a diff or open a terminal, an IDE or a git repository
- Minors, as the terms require every customer to be at least 18 or of local legal age
How to use Factory
A typical end-to-end flow, from setup to results.
- Create an account on the Factory web application and pick the surface that fits your habits
- Download the desktop app for Apple Silicon, Intel Mac, Windows x64 or Windows ARM64, or skip it
- Install the command-line tool through Homebrew or npm, then run droid inside any repository
- Authenticate, then connect a repository or grant the agent access to your local machine
- Open Settings and connect third-party apps such as GitHub, Linear, Notion, Slack or Sentry
- Add custom or self-hosted tooling over MCP when the managed connector catalogue is not enough
- Delegate a task in plain language, then read the plan, the tool calls and the resulting diff
- Set the autonomy level so read-only actions run freely while destructive ones ask for confirmation
- Tailor the harness with AGENTS.md, skills, slash commands, hooks, plugins and subagents
- Move a stabilised workflow into CI/CD with droid exec, and track coverage in Software Factory
Pros & Cons
Pros
- Genuinely model-agnostic: frontier, open-weight and your own keys all live behind the same interface
- One runtime on every surface, and every surface is included in every paid plan
- Code stays local, with no remote index of the repository and an explicit no-training pledge
- Serious compliance footprint: SOC 2 Type II, ISO 27001, ISO 42001 and a published DPA with EU clauses
- Deployment reaches where most rivals stop, from cloud to an isolated EU region to full airgap
- The generated code is yours outright, commercial use included, per the pricing FAQ
- Free access programmes exist for scientific researchers and open-source contributors
Cons
- No general free plan and no advertised trial: the entry point is a paid subscription
- No native mobile app, so the mobile surface is simply the web application in a browser
- Data residency in the EU, airgap, zero data retention and SSO are gated behind Business or Enterprise
- Personal data may be kept for up to ten years after your last use of the service
- Aggregated de-identified data remains freely exploitable by the vendor for its own purposes
- Business and Enterprise pricing is not public and goes through a sales conversation
- The sub-processor list sits in a Trust Center that renders only with JavaScript, and the UI is English-only
Pricing & Plans
There is no general free plan. The cheapest paid entry point is the Pro plan at 20.00 USD per month, with Plus at 100.00 USD and Max at 200.00 USD per month; the Business and Enterprise tiers are quoted on request. No free trial is advertised. Free access is nevertheless granted on application to qualified researchers through Factory for Science and to open-source contributors, and paying subscribers who exhaust their standard usage limits may fall back at no extra cost to the open-weight Droid Core models.
- complete development agents for individuals
- desktop
- CLI and SDK access
- cloud and local background agents
- billing and usage statistics
- agent-readiness dashboard
- everything in Pro
- expanded rolling rate limits
- roughly five times the usage of Pro
- plus access to Factory-managed Droid Computers for remote Droids
- everything in Plus
- expanded rolling rate limits
- roughly ten times the usage of Pro
- and early access to new features
- up to 150 seats
- custom usage limits
- dedicated onboarding and support
- single sign-on
- SAML and SCIM provisioning
- Zero Data Retention
- audit logging and basic admin controls
- unlimited members
- dedicated compute with a partitioned inference pool
- agent-readiness improvement programme
- on-premise deployment
- sub-organisations
- full admin controls
- customer-managed encryption keys
- data residency
Data, GDPR & hosting
A consolidated view of how Factory handles your data.
GDPR overview
GDPR implementation is documented rather than merely claimed. The security page carries a GDPR badge beside SOC 2, ISO 42001 and CCPA, and a full data processing agreement is published, dated 15 July 2026, incorporating the EU standard contractual clauses of decision 2021/914 together with the UK Addendum. A Data Protection Officer is designated and reachable by email for UK and European residents. The privacy policy, last updated 29 April 2026, states its legal bases, grants access, portability in CSV or JSON, erasure and complaint rights, and names the CNIL as a supervisory authority. Authorised sub-processors are listed, changes are notified, and customers may object within ten days or audit compliance annually. No Article 27 representative in the Union is named anywhere on the site.
Who owns the data?
The customer keeps every right in its own data and in the outputs the agents produce, and the pricing FAQ is blunt about the code itself: you retain full ownership and may use it commercially. Factory keeps the rights to the service, its software and the intellectual property behind it. Two carve-outs matter. Factory may internally use and modify customer data, without disclosing it, to run the service and to build aggregated de-identified data, which it is then free to use, keep and share for its own business purposes. Feedback sent to Factory is licensed to it worldwide, perpetually and irrevocably. The security page adds that customer code is never used as training data.
Reuse rights
Reuse is unrestricted on the customer side: the code a Droid produces belongs to the customer outright, who may ship it, sell it and build on it commercially without asking Factory for permission. Two duties come with that freedom. The customer alone answers for the accuracy, legality and licensing of whatever it feeds into the service, and the terms state plainly that outputs come out of machine learning processes, are neither tested nor guaranteed, and must be reviewed independently before use. Personal data can be exported in CSV or JSON on request, or erased by writing to the address published in the privacy policy.
Data retention & training
Hosting summary
By default, personal data sits on Amazon Web Services servers in US West and all processing happens in the United States, inside a sandboxed single-tenant environment with its own VPC. Data is encrypted with AES-256 at rest and TLS 1.2 or above in transit. Enterprise customers with European requirements can be provisioned on a dedicated EU deployment, fully isolated from the global one, whose backend, database and inference endpoints all sit in Europe; session content, prompts, assistant messages, tool calls and git AI notes stay there, and LLM requests from EU organisations never transit US infrastructure. Organisation records, user profiles and billing data remain in the global US deployment even then, and carry no user-generated content. Each organisation is pinned to a region at creation and mismatches fail closed. Hybrid and fully airgapped patterns keep all traffic inside the customer's own network. Transfers outside the EEA rely on the EU standard contractual clauses and the UK Addendum.
Things to keep in mind
Risks and trade-offs to weigh before adopting Factory.
- Outputs come from machine learning and are neither tested nor guaranteed: the terms put verification on you
- Delegating review, tests and documentation wholesale erodes a team's own grasp of its codebase
- High autonomy levels let the agent take write or destructive actions without asking first
- The agent reads your filesystem and runs commands, so scope it with OS permissions and sandboxing
- Bring-your-own endpoints shift privacy guarantees onto the third party; Factory adds none on top
- Aggregated de-identified data, feedback licensing and a ten-year personal-data horizon all favour the vendor
- Mandatory individual arbitration and a class-action waiver limit your recourse if something goes wrong
Setup & Integrations
Technical difficulty
Easy for an individual developer: create an account, download the desktop app or install the CLI through Homebrew or npm, then run droid inside a repository. Third-party apps connect through a guided authorisation flow with no server to configure. Customising the harness with MCP servers, hooks, plugins or skills requires editing configuration files and a solid technical background. An enterprise rollout is a different order of work: proxies, certificates, mTLS, secure runtimes, SSO with SAML and SCIM, command policies, regional pinning and possibly an airgapped network. The product assumes you read diffs and use git.
Deployment
Integrations
Supported languages
Behind Factory
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Which AI models can Factory run?
Who owns the code the Droids write?
Is customer code used to train models?
Is there a free plan or a free trial?
Where is the data hosted?
How long is data kept?
Which certifications and legal documents are published?
Where can Droid actually run?
Is there an API and a mobile application?
What is the minimum age to use Factory?
Should you pick Factory?
Factory is one of the few AI coding platforms built for the organisation rather than the individual keyboard. Its wager is independence: the same Droid runtime follows you from a desktop app to a terminal, a browser, an IDE or Slack, and it will talk to whichever model you choose, including open-weight ones and endpoints you host yourself. That is a real answer to the lock-in most rivals impose, and the pricing FAQ backs it with an unambiguous promise that generated code belongs to the customer, commercial use included.
The compliance work is unusually visible for a company this young. SOC 2 Type II, ISO 27001 and ISO 42001 are claimed, a data processing agreement with EU standard contractual clauses is published rather than promised on request, an isolated European deployment exists, and airgapped installations are documented in detail. Code stays on the machine that runs the agent, and the vendor states it never trains on customer code.
The reservations are mostly commercial. There is no general free plan and no advertised trial, so evaluation starts at 20 US dollars a month. Everything that matters to a regulated buyer, from EU residency to zero data retention and single sign-on, sits behind quoted Business or Enterprise tiers. Personal data may be retained for a decade after your last session, aggregated de-identified data stays freely usable by the vendor, and the sub-processor list hides behind a JavaScript-only Trust Center.
Treat the headline metrics — sevenfold faster feature delivery, a 96.1 percent cut in migration time, a benchmark crown — as vendor claims. Judge instead the governance controls and the deployment options, which are documented, specific and testable during a pilot.
- Choosing a selection results in a full page refresh.
- Opens in a new window.