ForgeStack Hosted gives you CFDI 4.0, multi-gateway payments, and subscription billing as a fully managed service — use our dashboard directly or connect your existing system via REST API. No servers to run. No SAT catalog updates to chase. No gateway API changes to absorb.
New product service codes, updated tax rates, deprecated CFDI versions — SAT publishes when they're ready. Every update is unplanned work for your team, or a silent compliance violation your clients find before you do.
MercadoPago, Conekta, and Pagar.me update APIs, change webhook schemas, and break sandbox environments on independent schedules. One silent change means dropped payments until someone drops everything to fix it.
CSD private keys in the filesystem — or worse, in a repository — are one breach away from forcing a full SAT recertification process. Weeks of compliance work, not a password reset. SAT does not issue emergency replacements.
Both paths share the same infrastructure, the same key vault, and the same security posture. The difference is only in how you interact with it.
Log in, upload your SAT certificate and keys, connect your payment gateways, and start issuing CFDI invoices and processing payments — entirely from the browser. No code, no deployment, no ops.
Keep your existing system exactly as it is. Point specific operations at our API — CFDI stamping, payment initiation, status queries. We handle the compliance, you keep the control.
Register your RFC and upload your SAT-issued CSD certificate and private key. We import them into OVH KMS — they sign there and never leave as raw bytes. Configure your PAC (Facturapi or Finkok), or use ours.
Add your MercadoPago, Conekta, or Pagar.me credentials. Provide a webhook relay URL if you're using the API path. Signature verification, replay protection, and gateway normalization are configured automatically.
Issue CFDI invoices, process payments, manage subscriptions. SAT catalog updates and gateway API changes are our problem now, not yours. We push patches before they affect your operations.
All ForgeStack modules are available in the hosted platform. Your plan covers the full stack — CFDI, payments, billing, SAT tools, WhatsApp, and MX Geo.
Running a hosted platform means we are the custodians of your most sensitive business data — SAT signing keys, payment gateway credentials, and customer RFC records. We treat this with the security posture it deserves: OWASP Top 10 enforced architecturally, non-extractable KMS key storage, hard tenant isolation at the data layer, and 25 years of security-reviewed engineering behind every decision.
Your SAT private keys are imported into OVH KMS and sign there — they never leave the vault as raw bytes. A breach of the application layer gains zero access to your signing material. Envelope encryption for all gateway credentials.
Every database query is scoped by tenant_id at the repository layer — not filtered at the view layer. Your RFC, invoices, and payment records are structurally inaccessible to other tenants. The boundary is in the data access, not the UI.
Doctrine ORM parameterized queries throughout — zero raw SQL anywhere in the platform. PHPStan level 8 catches injection-prone type flows at static analysis time. Your data is not reachable through SQL injection.
Each tenant gets a dedicated Bearer token scoped to their resources only. Compromised? Revoke instantly — no shared secrets, no cascading blast radius. All API requests are authenticated with the same rigor as internal service calls.
PciGuard::scrub() runs on every log write path — card numbers and API keys never appear in logs or traces. HTTPS-only enforced at the infrastructure and driver level. Your payment data doesn't leak into log aggregators or error tracking.
Injection (A03), cryptographic failures (A02), insecure design (A04), broken access control (A01), and SSRF (A10) — all addressed architecturally across every endpoint. Not a compliance checklist. A security foundation.
When you hand us your CFDI signing keys and payment credentials, you need more than "it works in our tests." Every line of ForgeStack Hosted was written by Claude Opus — Anthropic's most capable model — running structured subagent-driven development with PHPStan level 8, test-first discipline, and PSR-12 on every file. The architecture, security model, and infrastructure decisions are designed and supervised by Ruben E. — a PHP-Symfony engineer with 25+ years building production systems.
For a hosted platform that custodies your keys and processes your payments, that combination is the foundation of trust — not a marketing point. AI-generated velocity and consistency at scale, grounded by senior engineering judgment that knows exactly where the hidden risks are before they become your 2 AM incident.
Get Early Access →Join the waitlist for ForgeStack Hosted. Early access pricing, dashboard access, REST API credentials, and dedicated onboarding. We reach out before launch — no spam, unsubscribe anytime.