SaaS Factory provisions, configures, and maintains your entire infrastructure stack automatically. GitHub, Vercel, Neon, Anthropic, MCP — wired together from day one, and kept in sync by agents that never stop working.
[ VERIFIED / PLATFORM FACTS ]
[ AI-WORKER / PIPELINE STAGES ]
SaaS Factory generates AI-first products for AI-first infrastructure. The AI Worker is the coordinated fleet of specialist agents that runs your product 24/7 — researching, building, testing, shipping, and improving without stopping.
Research agents analyse competitors, scan user feedback, and surface feature gaps. Findings feed directly into the feature queue.
Design agents spec the feature. Implementation agents write TypeScript, tests, and migrations. The CI pipeline runs automatically.
After tests pass, the release agent merges the PR, triggers a Vercel deployment, and writes release notes. Live in under 30 minutes.
Every 30 minutes the cycle restarts — new features discovered, shipped, and measured. The product gets better while you sleep.
Give it an idea. The full stack provisions itself — GitHub repo, Neon database, Vercel deployment, MCP server, REST API, and a fleet of AI agents that ships features every night.
Questions? Email us at sf-core-org-support-saas-factory@saas-factory.ai
[ CORE / INFRASTRUCTURE ]
These are not optional add-ons. They are the foundation every product gets — provisioned automatically, maintained continuously.
Agents open pull requests, merge features, and manage CI — your entire repo lifecycle is automated. Every shipped feature becomes a traceable PR.
Production deployments triggered automatically after every approved PR. Environment variables pushed, deployment URLs tracked, rollbacks available from the dashboard.
[ MCP-01 / MODEL CONTEXT PROTOCOL ]
Every product built on SaaS Factory ships with a live MCP server endpoint. Cursor, Claude Desktop, or any MCP-compatible tool can call into your product's capabilities directly — without writing a single line of integration code.
OAuth 2.0 token auth on every MCP connection
Per-tool usage tracked — query costs, call counts, error rates
SSE streaming for real-time tool responses
Project-scoped — each product has its own isolated MCP endpoint
[ API / REST + WEBHOOKS ]
SaaS Factory exposes a versioned REST API at /api/v1/* — authenticated with API keys, protected by the same rate-limiting and auth the platform uses internally. Trigger pipelines, read product status, or stream agent job logs from your own tooling.
API Keys Per-project scoped keys with revocation, expiry, and usage tracking
Webhook Outbound Delivery log, endpoint management, and retry history in the connections dashboard
Inbound GitHub Webhooks Push events and PR status updates feed directly into pipeline decisions
[ AUTH / IDENTITY ]
Sign in with GitHub, Google, or Microsoft Entra. Invite your team, assign roles, manage org-level access — all wired through the same auth layer that secures every product you build.
Sign in and connect your repos in one step. The GitHub token drives automated PR creation, CI monitoring, and secret management for deployed products.
Enterprise OAuth providers supported out of the box — Google Workspace and Azure AD. Team members can sign in with their existing SSO credentials.
[ CONNECTIONS / ENV + SECRETS ]
Environment variables are stored encrypted, validated against real APIs, and pushed to Vercel with a single action. The platform validates GitHub tokens, Vercel tokens, and Twilio credentials before accepting them — no silent misconfigurations.
AES-256 encryption at rest for all secret values
Live validation: GitHub, Vercel, and Twilio checked against real APIs on save
One-click push to Vercel environment — triggers a redeploy automatically
Required-key checks alert you before agents fail due to missing config
[ NOTIFICATIONS / CHANNELS ]
Pipeline completions, failed deployments, pending approvals, revenue drops, churn spikes. Seven event types, three channels — configured per product, dispatched instantly.
Transactional and operational emails sent via Resend. Pipeline events, dunning sequences, GDPR export confirmations, support ticket replies — all dispatched by agents.
[ COMPLIANCE / ENTERPRISE ]
GDPR Data Deletion Daily sweep processes deletion requests — users, projects, pipeline runs, features, releases all purged on schedule
GDPR Data Export JSON/CSV archive generation with signed download URLs, 7-day expiry, automated fulfilment
Audit Logging Every mutation and sensitive data access written to the audit log — SOC2 CC7.2 compatible
Row-Level Security
Serverless Postgres provisioned per product. Schema migrations applied by agents. Branching databases for safe testing before any change hits production.
The intelligence behind every agent — research, design, implementation, testing, release, marketing. Structured tool calls, full token tracking, cost visibility per agent job.
Transactional emails dispatched by agents — pipeline completion alerts, approval gate notifications, dunning sequences, support ticket replies, GDPR confirmations.
The scheduler that keeps everything running — competitor re-analysis, churn scoring, subscription renewals, GDPR sweeps, stale pipeline recovery. Cron-driven and event-driven.
Accessible from the MCP Server tab in your product dashboard

Inbound Support Webhooks Route support tickets from any source into the AI triage pipeline
Invite teammates, assign owner or member roles, manage multiple organisations. Full team audit trail — every permission change is logged.

Incoming webhook URLs per product. Post pipeline status, approval gates, and revenue alerts directly into your team's Slack channels.
The same event stream delivered to Discord. Useful for community-driven products where your users want to watch the factory floor in real time.
Encryption at Rest AES-256 for all secrets — GitHub tokens, Vercel keys, connection credentials, MCP configs
Content Security Policy Strict CSP with nonce-based script control deployed at the middleware layer
Dependency Security Automated vulnerability scanning in CI against all npm production dependencies
Security Headers HSTS, X-Frame-Options, X-Content-Type-Options applied on all responses