Ambera
AI made building cheap. Knowing what to build is not.

Your agent forged it.Does anyone want it?

Every week, Forge reads the companies in your market — what they shipped, what they started charging, what their users complain about — and writes you a brief with a source under every line. It checks whether your deployed app leaks a key, and opens the fix as a pull request in your own repository.

  • Google, GitHub or email
  • no card
  • 15 free credits
  • a brief a week
forge.ambera.app

What Forge does

The four things your generator does not tell you.

It made the app. It did not tell you whether anyone wants it, whether it is safe to show, or how to fix what it got wrong. Forge does — and every answer is a count you can check, never a score you have to trust.

01 · Before you build it

Read whether anyone wants it — every week.

Describe the idea in a sentence. Signal proposes who to watch, writes down the bets the idea rests on with what would refute each, and sends a brief a week: what moved, tagged FACT, COMPANY CLAIM or USER OPINION with the link it came from, and which of your bets the market just refuted.

first idea read free · a market-fit number that can fall

02 · Before strangers see it

Know in ten seconds whether your app leaks a key.

Paste the URL. Forge reads exactly what a visitor’s browser downloads and counts the two leaks that take generated apps down: a database service-role key or an API key shipped in the bundle. Plus transport, headers and source maps. Nothing stored, no probing.

5 checks · read from the shipped bundle · free

03 · No tracker, no ticket

Fix it for me — as a pull request in your own repo.

A committed .env or an exposed database table gets a deterministic fix, free. Anything else, the model proposes the edit and the same detector that found the finding re-runs over the files before and after — the pull request opens only if the count fell. Never a push to main.

branch + PR · verified by the detector, not by opinion

04 · Inside the agent

Your agent cannot ship a leaked key without hearing about it.

A Claude Code plugin and a Cursor rule run the same deterministic read over uncommitted changes when a turn ends, and exit 1 on an introduced urgent finding — in the agent’s own loop, before a review round is spent. Local, nothing uploaded.

Stop hook + MCP · zero config

Signed in, all four meet in one place: the app you built, read nightly; the market around it, read weekly; the fixes, opened where your code lives.

Start free

Signal

Before you build it — and every week after — read whether anyone wants it.

Building got cheap. Knowing what to build did not. Signal watches the market around one idea or one app and writes you a brief a week: what changed, which of your bets the market just refuted, and a market-fit number that is allowed to go down.

  1. 01

    Describe it, in one sentence

    An idea before any code, or a repository you connected. Signal proposes who to watch and pulls out the bets the idea rests on — each with what would refute it. You confirm both.

  2. 02

    A brief a week, two minutes to read

    What moved: prices, launches, funding, what users of the competition complain about. Every claim tagged FACT, COMPANY CLAIM, USER OPINION or INFERENCE, with the link it came from.

  3. 03

    Your bets, moved by the market and not by you

    A bet changes to confirmed or refuted only when this week’s entries meet the test you wrote — and the card shows the fact, its date and its source rather than a sentence about them. You cannot grade your own bet, which is the point.

  4. 04

    Your own code on the same page

    Connect the repository and Forge reads it deterministically — no model — then places what it found against what this market’s companies declare. Which of them your code evidences, which it did not, and what that does not mean.

  5. 05

    A number that can fall

    Once the floors are met, a versioned market-fit reading: the market half read from the web, your half from your own manifests where they evidence a capability and from your description for the rest, correctable by you, every component with its sample and which side it came from.

Your first idea read is free: fifteen credits, one seed and one cycle. Your description is kept verbatim and shown as yours — the one thing here Forge did not measure.

forge.ambera.app/signal/invoice-reminders

A recording of the product’s own design harness — the shipped components over fixture data, computed by the shipped math. The companies in frame are the fixture’s; a real brief names real ones, with sources, and says plainly when nothing material moved.

From the market to your repository

The market names the gap. You decide. Forge opens the pull request — and only the read says it landed.

Nobody else holds both ends: a deterministic read of your code and a weekly read of your market. Joined, a competitor’s launch becomes a decision on your screen, a decision becomes a scaffold in your own repository, and “did we build it” is answered by the instrument instead of by anyone’s memory.

  1. 01

    The market names a gap

    The companies in your market declare a capability your repository was read as not carrying — or the market refuted one of your bets. Forge asks for a decision, never for code.

  2. 02

    You decide, in one line

    Log the decision and name the capability it commits to: payments, sign-in, offline, calls a model. That line is the only thing here a person writes.

  3. 03

    Forge opens a scaffold — if the read agrees

    A model proposes the dependencies and the entry points, and the same deterministic capability read that reads your repository every night runs over the proposal. The pull request opens only if that read now evidences the capability and no urgent count rose. Otherwise nothing opens and the credits return.

  4. 04

    Your agent finishes it, from the same brief

    Over MCP, Forge hands Cursor or Claude Code where to start: the gaps without a decision, the refuted bets, the decisions not yet landed, the open findings, the gates — every line with its source.

  5. 05

    The instrument says when it landed

    The next nightly reading stamps the decision landed when the manifests and tree evidence the capability — not your memory, not a checkbox. The weeks after show whether anyone on the web mentioned it.

A scaffold costs 10 credits, refunded when the read refuses it. The market never writes code; you decide, the read verifies, your agent finishes.

The pull request, as Forge writes it

> Review before merging. This is a scaffold, not the feature: dependencies and entry points for the capability the decision named. Nothing in it was run.

Opened by Ambera Forge from a decision logged in Signal (source: `capability:cx9…`).

### The decision, as logged
> Take payments for the launch check — three of five competitors declare it, we do not.

### What the reading will check
The capability read (v1) over this branch evidences **Payments** from: `stripe`. The next full reading of the default branch is what stamps the decision *landed* — the same read, not a person.

### Before merging
Run your package manager so the lockfile matches the manifest; until it does, the nightly reading counts manifest–lockfile drift.

The body template the product ships, with a decision filled in. The dependency named is what the capability read recognised on the branch; nothing here is invented.

The market, top down

Is the market you are building into growing? Read it from the category down to the companies.

A growing market says you are not building into a headwind — and nothing about whether this application has customers. Forge shows the first with every figure attributed to who published it, and leaves the second to Signal.

  1. 01

    Start from what you are building

    Describe the application and Forge proposes the sector it already reads that fits — chosen from its own list, never invented, with the words in your description it matched on. You confirm, or pick another.

  2. 02

    How big the market is, as its publishers state it

    Six years of history and the publisher’s own outlook for the category — a statistical body where one publishes, a research house where none does — each figure with the sentence it was copied from and the year it was published. The outlook is drawn dashed and is the publisher’s, never Forge’s. Two publishers are shown side by side, never averaged.

  3. 03

    What the companies in it did this week

    The sector’s companies are read once a week, for every customer at once. What each shipped, priced or announced, tagged FACT, COMPANY CLAIM or USER OPINION with the link — and a company not read yet says so, because not read is not quiet.

  4. 04

    Money into the sector, by quarter

    Rounds counted from dated, sourced entries, the stated amounts summed as a floor per currency and never combined, every quarter carrying how many companies were read in it. A private market has rounds, not a market cap, and Forge shows the one it can check.

forge.ambera.app/signal/categories/us-healthcare

A recording of the product’s own design harness — the shipped components over fixture figures, composed by the shipped math. The publishers in frame are the fixture’s; a real category names the statistical body or research house, with the sentence each figure was copied from.

What Forge does not do here

  • It never states what a market is worth in its own voice. A figure is a publisher’s, named on the same line, with the year it was published beside the year it describes.
  • It never draws a year nobody published. A gap in the series stays a gap; nothing is interpolated, averaged or projected by Forge.
  • It never turns a growing market into a verdict on your app. That question is Signal’s, answered from what the companies say and what your own code evidences.

The sector, category and company pages are inside the product. Placing your description costs no credits and reads nothing from the web — the catalog already holds what it needs.

The launch check

It found its own gap first.

The first deployed application Forge read was Forge. Five of five headers were missing. The same read, the same evening, after the fix — that is what a reading looks like when nothing is left to report.

before
launch check forge.ambera.app
read 21 of 21 same-origin scripts and 6 inline blocks
4 of 5 checks that ran reported nothing.
medium Add the baseline security headers [missing-security-headers]
5 of 5 baseline security headers absent on the page response.
Server-side code is invisible to this read by design.
after
launch check forge.ambera.app (same evening)
read 21 of 21 same-origin scripts and 6 inline blocks
5 of 5 checks that ran reported nothing.
No browser database client was seen in the scripts read.

The five checks

  • urgent

    bundle-service-role-key

    A JWT whose payload says role "service_role" in any shipped script — every visitor’s key to the whole database. The anon key is public by design and is never a finding.

  • urgent

    bundle-provider-secret

    A string literal shaped like an AWS, GitHub, Stripe live, OpenAI, Anthropic or other provider credential, after the same placeholder gate the code read uses.

  • high

    insecure-transport

    The page served over http after redirects.

  • medium

    missing-security-headers

    Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, a frame policy and, over https, HSTS — counted per header.

  • low

    bundle-source-maps

    A source map the shipped scripts name that actually answers — the original source, downloadable by anyone.

What it cannot see, said first

  • Server-side code. A key that never reaches the browser cannot appear here — and a key that does is the finding.
  • Whether your database tables have row-level security. That lives in the migrations; connecting the repository reads it.
  • Third-party scripts. Analytics vendors’ bundles are counted and skipped — they are not yours.

It requests only what the page hands out. No guessed paths, no API probing, no login.

Or check one URL without an account first — nothing is stored.

Fix it for me

The fix arrives as a pull request, not as a ticket.

You do not have a Linear and you are not getting one. Forge opens the change in your own repository, and a detector — not an opinion — decides whether it was a fix.

  1. 01

    The finding names the files

    Every code finding carries the paths and lines it was counted at — the fix starts from those, on the default branch’s HEAD right now.

  2. 02

    Deterministic where the facts decide

    A committed .env: delete it, make .gitignore refuse it, and say first that the values must rotate because history still holds them. Exposed tables: one migration enabling row-level security on exactly the tables the detector counted — and no policies, because which rows a visitor may read is your product decision.

  3. 03

    Verified where a model edits

    For everything else the model proposes whole-file replacements, and the same deterministic detector re-runs over the files before and after. The pull request opens only if the count fell and no urgent count rose. Otherwise nothing opens, the credits refund, and the attempt is recorded with the detector’s own sentence.

  4. 04

    Never a push to main

    A branch and a pull request, with what was measured and what clears the finding in the body — the same acceptance criterion the exported issue carries, so a reviewer knows what the next reading will check.

Deterministic fixes are free. An agent-assisted fix costs 10 credits, refunded when the detector refuses the edit. Prefer a ticket? Every finding still files into Linear, Jira, GitHub Issues or ClickUp.

The pull request, as Forge writes it

> Review before merging. This change is correct as a starting point and changes behaviour.

Opened by Ambera Forge for the finding `tables-without-row-level-security` (high).

### What this change does
- Adds `supabase/migrations/…_forge_enable_row_level_security.sql` enabling RLS on: public.documents, public.profiles.
- With RLS enabled and no policies, every row is denied to the anon key — the correct starting point, and also one that makes the app show nothing until policies exist. Forge writes no policies.

### Verification
The edit follows from the finding’s own facts; no model authored it. The next full reading of the repository is what clears the finding on the board.

The body template the product ships, with a finding filled in. Table names come from the migration the detector read; nothing here is invented.

Pricing

Free to start. A flat monthly when it earns it.

A solo builder pays one monthly with a credit allowance for the model work. A team pays for coverage — the engineers whose pull requests Forge actually reads. Nothing deterministic is ever metered.

Forge Free

$0forever

Sign in, no card

Get the answer before you pay for anything.

  • One idea read in Signal on the house: fifteen credits, a seed and a first brief
  • The launch check on any deployed URL — what a visitor’s browser receives, read for shipped keys and headers
  • The ownership audit on any public repository, and a shareable report

Forge Solo

$29/ month

60 credits a month · every repository you connect

The technical co-founder and the business co-founder a solo builder does not have.

For the builder shipping alone
  • Signal: a weekly market brief per idea or app, your bets moved by the market, the decisions log
  • Your repositories read nightly — every source file, workflow, lockfile and agent instruction — with every finding as a card
  • Fixes opened as pull requests in your repository; deterministic ones free, agent-assisted ones 10 credits
  • 60 credits a month; top up 20 for $9 or 100 for $29. Re-reads, the pull-request check and the market-fit reading are never metered

Forge Team

$69/ month

5 contributors included, then $9 each

Every repository, continuously — read by everyone.

Founding price for the first 100 workspaces — $99 after
  • Everything in Solo, for the whole team, with the fixes filed into your tracker or opened as pull requests
  • The PR check: new findings only, so pre-existing ones never block a merge
  • Signal on every repository, 200 credits a month
  • Review concentration as a distribution — never a per-person ranking

Prefer to pay once? The Launch Audit connects one repository for 90 days with 40 credits — $69 at launch, $99 after. Sign in to start one.

Answering for a whole organization? Premium, $299 a month, adds org-wide rollups, the audit trail, the PR bot and the MCP connector. Talk to us.

A covered contributor authored or reviewed a pull request in the last 30 days — bots and quiet months do not count, and the billing read returns a number, never the list of people behind it. The code read covers React, TypeScript and JavaScript (Vue and Svelte included) (deepest); Python, Go, Ruby, Java, Kotlin, C#, Swift, PHP, Rust and Dart (language checks); Scala, C/C++, Objective-C, Groovy and the other brace languages (structure and hygiene); Elixir, Clojure, Haskell, Erlang, Lua and the rest (tree level); Workflows, Dockerfiles, lockfiles and agent instruction files (configuration read). Hosted reads cover GitHub today; GitLab, Bitbucket and GitHub Enterprise Server are not yet supported.

Before you sign in

The questions builders ask first.

Answered in the product’s own words. Where the honest answer is “it cannot see that”, the answer says so.

Does it matter whether I used Lovable, Bolt, v0, Replit, Cursor or Claude Code?
No. The launch check reads what a visitor’s browser receives from the deployed URL, and the code read reads the repository — neither asks which tool typed it. Two apps that differ only in who generated them read the same.
Can I validate the idea before I build anything?
Yes. Signal starts from a written description: it proposes who to watch and the bets the idea rests on, you confirm both, and a brief arrives every week with each claim tagged FACT, COMPANY CLAIM, USER OPINION or INFERENCE. The market-fit number waits until a repository is linked and the floors are met — it never invents one from silence.
Can Forge tell me whether the market I am building into is growing?
It shows you what the market’s publishers state — six years of history and their own outlook for the category, each figure with the sentence it was copied from and who published it — plus what the sector’s companies did this week and the rounds they raised by quarter. Forge computes none of those figures and averages none of them; a gap stays a gap. Whether this application has customers is a different question, and Signal’s.
Is my Supabase anon key a problem?
No — the anon key is the correct way to configure a browser client, and Forge never counts it. The finding is a service-role key: a JWT whose payload says role "service_role", which is the key to the whole database. It is decided by that claim, never by the shape of the string.
What happens to my URL or my code?
The launch check stores nothing: it requests only what the page hands out — the page, its own scripts, its headers — and probes no paths, no API and no login. A credential value never leaves the read; findings carry the script path and a count. A connected repository is read through its own GitHub App installation, and nothing is copied out of it.
Can Forge build the feature the market is asking for?
It opens a scaffold, not the feature. When your market declares a capability your repository does not carry, Forge asks you for a decision; once you log it and name the capability, a model proposes the dependencies and entry points, and the same deterministic capability read that reads your repository every night decides whether the pull request opens — it must evidence the capability, and no urgent count may rise. Your own agent finishes it, starting from the brief Forge hands it over MCP, and the next nightly reading is what stamps the decision landed.
Does Forge push to my repository?
Never to main. A fix is a branch and a pull request in your own repository, with what was measured and what clears the finding in the body. A committed .env or tables without row-level security are fixed deterministically for free; anything a model edits opens only if the same detector counts fewer findings afterwards.
What does free actually include?
An account with fifteen credits and no card: one idea read in Signal — the seed and a first brief — the launch check on any deployed URL, and the ownership audit on any public repository. Solo, at a flat monthly, adds the weekly brief, nightly re-reads of your own repositories and the fix pull requests.

Start free

Find out whether anyone wants what you built.

Sign in with Google, GitHub or an email. Fifteen credits, no card: describe the idea, confirm who to watch, and the first brief runs. Nothing here ends in a score you have to trust.

Never a ranking of your engineers — the org sees counts, never logins.