PageSourceSearch

https://app.melaya.org/login

html melaya.org collected 2026-10-02 01:06:58 UTC 39,251 bytes, 597 lines download raw bytes

1<!doctype html>
2<!--
3  Melaya - index.html
4
5  This file ships ONLY the cross-route SEO baseline (Organization,
6  WebSite + SearchAction, brand-level OG/Twitter, performance hints).
7  Per-route titles, descriptions, OG cards, BreadcrumbList, FAQPage,
8  and route-specific SoftwareApplication entities are rendered into
9  the head by the PageSEO component at the top of each page, leveraging
10  React 19 native metadata hoisting: the renderer promotes title, meta,
11  link, and JSON-LD script elements from anywhere in the tree to head
12  and dedupes by name|property|rel|@id.
13
14  When PageSEO renders, its title wins over the fallback title below,
15  its description override overrides this one, etc. So what is in this
16  file is what crawlers see for routes that have not rendered yet (the
17  bare 404 / error path) AND what AI ingestion bots see when they fetch
18  the bare HTML before JS executes.
19
20  Keep the JSON-LD graph minimal here:
21    - Organization (canonical entity, @id used everywhere)
22    - WebSite (SearchAction, @id used by every WebPage)
23    - SoftwareApplication aggregate (the platform-level entity; each
24      product page registers a more specific SoftwareApplication that
25      isPartOf this one)
26
27  All copy is in sync with the live landing page voice.
28
29  DO NOT add literal angle-bracketed tag names (head, meta, script,
30  body, title, link, html, PageSEO, anything inside angle brackets)
31  to any comment in this file. Yandex verification parser and some
32  primitive crawlers misread those as opening tags and silently skip
33  every meta tag that follows the comment. Cost us a Yandex
34  verification fail in 2026-06 - keep it in plain text only.
35-->
36<html lang="en" class="dark">
37    <head>
38        <meta charset="UTF-8" />
39        <!--
40          Content-Security-Policy for the public web app (added 2026-07-04).
41          The API (api.melaya.org) already ships a strict header via helmet;
42          the static app shell served through Cloudflare/nginx had none, so an
43          XSS in the SPA could exfiltrate freely. This meta policy closes that
44          gap at build time (committable, no infra change). It is deliberately
45          permissive on script-src ('unsafe-inline' is required for React 19's
46          hoisted JSON-LD and Vite's module preload) and tight on the
47          exfil-critical directives: connect-src is allow-listed to our own
48          backends + Stripe + Infisical, so injected script cannot POST stolen
49          cookies/tokens to an attacker origin, and object-src/base-uri/
50          form-action are locked down. frame-ancestors is unsupported in a
51          meta CSP and is already enforced by the X-Frame-Options: DENY
52          response header at the edge. HARDENING FOLLOW-UP: move this to a
53          response header at nginx/Cloudflare in Report-Only first, then
54          enforce with a nonce-based script-src to drop 'unsafe-inline'.
55
56          WHY CONNECTORS ARE NOT LISTED: connector API traffic (GitHub,
57          Notion, exchanges, ...) is made SERVER-SIDE by the Python tool
58          layer (requests/httpx on the server or local runner), never from
59          the browser. Connector OAuth is a server-side popup flow: the
60          browser opens the provider authorize URL as a top-level navigation
61          (not a fetch, so not connect-src governed) and the callback posts
62          back to api.melaya.org. So the browser only connects to our own
63          backends + Stripe + Google + Infisical; adding connector origins
64          would weaken the policy for no gain. Only landing/login/legal were
65          smoke-tested under this policy — validate the authenticated
66          Connectors + billing flows during the Report-Only window before
67          enforcing at the edge.
68
69          The Assistant's Whisper STT fallback (dictation for engine-less browsers
70          like Brave) runs transformers.js / onnxruntime-web, which needs three
71          network allowances:
72            • script-src  cdn.jsdelivr.net — the ONNX runtime loader ES module
73              (ort-wasm-*.jsep.mjs) is a MODULE, so it's script-src-governed.
74            • connect-src cdn.jsdelivr.net — the paired ort-wasm-*.wasm binaries.
75            • connect-src huggingface.co + *.hf.co — the model WEIGHTS.
76          Our OWN model runtime code (whisperStt) stays bundled +
77          served from 'self'; only these vendored ONNX assets + HF weights are
78          third-party. jsdelivr version-pins by URL, so the surface is a specific
79          immutable @huggingface/[email protected] build.
80        -->
81        <meta
82          http-equiv="Content-Security-Policy"
83          content="default-src 'self'; base-uri 'self';
83 object-src 'none'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' blob: https://js.stripe.com https://accounts.google.com https://apis.google.com https://cdn.jsdelivr.net https://static.cloudflareinsights.com https://www.redditstatic.com https://analytics.tiktok.com https://connect.facebook.net https://www.googletagmanager.com https://googleads.g.doubleclick.net https://track.melaya.org https://api.melaya.org https://cdn.affonso.io; worker-src 'self' blob:; child-src 'self' blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://accounts.google.com; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' blob: data: https://api.melaya.org wss://wss.melaya.org wss://*.melaya.org https://*.melaya.org https://api.stripe.com https://*.infisical.com https://accounts.google.com https://www.googleapis.com https://script.google.com https://cdn.jsdelivr.net https://huggingface.co https://*.hf.co https://static.cloudflareinsights.com https://cloudflareinsights.com https://*.reddit.com https://alb.reddit.com https://analytics.tiktok.com https://*.tiktok.com https://*.tiktokw.us https://connect.facebook.net https://www.facebook.com https://*.googletagmanager.com https://*.google-analytics.com https://www.google.com https://*.doubleclick.net https://track.melaya.org https://prod-trybe-platform-6mi3j.ondigitalocean.app https://api.affonso.io; media-src 'self' data: blob:; frame-src 'self' blob: https://js.stripe.com https://checkout.stripe.com https://accounts.google.com https://www.youtube-nocookie.com https://www.youtube.com https://www.facebook.com https://td.doubleclick.net https://api.melaya.org https://affonso.io; form-action 'self' https://checkout.stripe.com; upgrade-insecure-requests"
84        />
85        <meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover" />
86        <meta name="format-detection" content="telephone=no" />
87        <meta name="color-scheme" content="dark light" />
88
89        <!-- Anti-FOUC theme init. Runs synchronously BEFORE first paint so the
90             correct theme is applied immediately — no dark→light flash (the
91             prerendered <html> ships class="dark", and ThemeContext used to only
92             fix it in a post-mount effect). Precedence MUST match
93             ThemeContext.getInitialMode: an explicit stored choice, else dark
94             (dark is the prerender/brand default — deliberately NOT the OS
95             preference, so the dark-baked prerender never flips to light and
96             flashes for dark users). Governed by the CSP above (script-src
97             'unsafe-inline'); try/catch so a storage-blocked context can't break
98             boot. A light-preference user now paints light immediately. -->
99        
99<script>
100          (function () {
101            try {
102              var m = localStorage.getItem('mel_theme_mode');
103              if (m !== 'light' && m !== 'dark') m = 'dark';
104              var el = document.documentElement;
105              el.classList.remove('dark', 'light');
106              el.classList.add(m);
107            } catch (e) { /* keep the class="dark" fallback */ }
108          })();
109        </script>
109
110
111        <!-- ── Performance hints (paint above-the-fold faster) ────────
112             dns-prefetch + preconnect on the font CDN cuts ~200ms off
113             first font paint; `crossorigin` on preconnect is required
114             because fonts are CORS-fetched. The webm hero loop gets a
115             link rel="preload" with `as=video` so the browser starts
116             pulling it before main.tsx parses. -->
117        <link rel="preconnect" href="https://fonts.googleapis.com" />
118        <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin />
119        <link rel="dns-prefetch" href="https://fonts.googleapis.com" />
120        <link rel="dns-prefetch" href="https://fonts.gstatic.com" />
121        <!-- Brand mark: the landing hero's LCP element (and the nav logo used
122             site-wide). Preload as a high-priority image so the ~30 KB SVG is
123             ready the instant React renders the hero, instead of waiting on the
124             main.tsx bundle — was a ~4 s LCP on the landing page. -->
125        <link rel="preload" as="image" href="/brand/melaya_mark_sharp.svg" type="image/svg+xml" fetchpriority="high" />
126        <!-- Noto Sans SC added for Simplified Chinese coverage; Poppins
127             lacks CJK glyphs entirely so a /zh/ visitor on Linux/Docker
128             would otherwise see tofu boxes. font-display: swap paints
129             Latin first and swaps CJK on the second frame. -->
130        <!-- Non-render-blocking font load: preload as a stylesheet, then flip
131             rel to 'stylesheet' onload so the ~90 KB Google Fonts CSS no longer
132             blocks first paint (was ~1.8 s on the critical path). font-display:
133             swap paints the system-ui fallback immediately and swaps to Poppins
134             when ready. <noscript> keeps it working with JS disabled. Inline
135             onload is permitted by the CSP's script-src 'unsafe-inline'. -->
136        <link
137            rel="preload"
138            as="style"
139            href="https://fonts.googleapis.com/css2?family=Poppins:wght@400;500;600;700;800&family=Noto+Sans+SC:wght@400;600;700&family=JetBrains+Mono:wght@400;600&display=swap"
140            onload="this.onload=null;this.rel='stylesheet'"
141        />
142        <noscript>
143            <link
144                rel="stylesheet"
145                href="https://fonts.googleapis.com/css2?family=Poppins:wght@400;500;600;700;800&family=Noto+Sans+SC:wght@400;600;700&family=JetBrains+Mono:wght@400;600&display=swap"
146            />
147        </noscript>
148
149        <!-- Trybe creator-attribution pixel. Loaded ONLY on the marketing site
150             (melaya.org / www) — never on the authenticated app.melaya.org, which
151             shares this index.html. It captures the ?trybe=<vid> creator click id
152             and persists the ugc_vid_* cookie; that vid is later forwarded into
153             Stripe checkout and reported to Trybe server-side ONLY on a PAID
154             subscription (see server/services/marketing/trybeAttribution.ts). -->
155        
155<script>
156          (function () {
157            var h = location.hostname;
158            if (h !== 'melaya.org' && h !== 'www.melaya.org') return;
159            (function (w, d, p, s, u, pl, at) {
160              w._trybe = w._trybe || { pixelCode: p, storeId: s, platform: pl, autoTracking: at, customDomain: 'track.melaya.org', serviceUrl: 'https://prod-trybe-platform-6mi3j.ondigitalocean.app/attribution' };
161              var script = d.createElement('script');
162              script.src = u + '/pixel.js';
163              script.async = true;
164              script.setAttribute('data-pixel-code', p);
165              script.setAttribute('data-store-id', s);
166              script.setAttribute('data-platform', pl);
167              script.setAttribute('data-auto-tracking', at);
168              d.head.appendChild(script);
169            })(window, document, 'px_ca585fd67798', '4f2bb663-99f5-49d3-aa53-5bb22d6c5d98', 'https://track.melaya.org', 'CUSTOM', 'false');
170          })();
171        </script>
171
172
173        <!-- ── Favicons (covers every modern client) ────────────────── -->
174        <link rel="icon" type="image/x-icon" href="/favicon.ico" />
175        <link rel="shortcut icon" href="/favicon.ico" />
176        <link rel="apple-touch-icon" sizes="180x180" href="/icons/apple-touch-icon.png" />
177        <link rel="icon" type="image/png" sizes="32x32" href="/icons/favicon-32x32.png" />
178        <link rel="icon" type="image/png" sizes="16x16" href="/icons/favicon-16x16.png" />
179        <link rel="manifest" href="/manifest.json" />
180        <link rel="mask-icon" href="/brand/melaya_mark_sharp.svg" color="#7C6FF0" />
181
182        <!-- ── Fallback page title + description ──────────────────────
183             Multi-language i18n (Phase 1 of plan giggly-baking-octopus):
184             per-route PageSEO renders localized title/meta/JSON-LD via
185             React 19 metadata hoisting based on the active language.
186             This fallback is what crawlers see for the bare HTML before
187             JS executes — the EN copy stays here as the `x-default`
188             surface (it's also what GPTBot sees pre-hydration). Per
189             page, PageSEO emits the correct localized title + 5×
190             hreflang + per-language JSON-LD on top.
191
192             Title kept ≤40 chars for Naver SERP compliance. -->
193        <title>Melaya · AI agent platform</title>
194        <meta
195            name="description"
196            content="Melaya is a platform to build and run AI agents across your tools, browser, and Android phone. Bring your own AI and keep human approval on every action."
197        />
198        <meta
199            name="keywords"
200            content="AI agent platform, AI agents, agentic AI, visual agent builder, multi-agent orchestration, AI agent for business, enterprise AI assistant, AI browser automation, browser AI agent, mobile AI agents, AI agent for Android, MCP server, model context protocol, AI marketing, AI SEO audit, bring your own AI, local LLM agent, human in the loop AI, agentic workflows, Melaya"
201        />
202        <meta name="author" content="Antoine Roche" />
203        <meta name="publisher" content="Melaya" />
204        <meta name="robots" content="index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1" />
205        <meta name="googlebot" content="index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1" />
206        <meta name="bingbot" content="index, follow, max-snippet:-1, max-image-preview:large" />
207
208        <!-- Site verification (meta-tag method).
209             Yandex HTML-file verification fails on Cloudflare-fronted
210             sites because Cloudflares Web Analytics auto-injects a
211             beacon script into the body, breaking Yandex strict body
212             parser. The meta-tag method bypasses that — Cloudflare
213             never touches the head. Naver supports both methods; the
214             HTML file at /naverxxx.html is the primary, this meta is a
215             backup.
216             Do not put literal angle brackets in this comment.
217             Yandex parser misreads them as opening tags and silently
218             skips every meta tag that follows. -->
219        <meta name="yandex-verification" content="ca8003cc88ecb1e9" />
220        <meta name="naver-site-verification" content="e4feabffb0c30c65ac0332af95a7be3c" />
221        <meta name="theme-color" content="#0A0A0F" media="(prefers-color-scheme: dark)" />
222        <meta name="theme-color" content="#FFFFFF" media="(prefers-color-scheme: light)" />
223        <meta name="application-name" content="Melaya" />
224        <meta name="apple-mobile-web-app-title" content="Melaya" />
225        <meta name="mobile-web-app-capable" content="yes" />
226        <meta name="apple-mobile-web-app-capable" content="yes" />
227        <meta name="apple-mobile-web-app-status-bar-style" content="black-translucent" />
228
229        <!-- ── Open Graph (Facebook, LinkedIn, Slack, iMessage, WhatsApp, Discord) -->
230        <meta property="og:type" content="website" />
231        <meta property="og:site_name" content="Melaya" />
232        <meta property="og:title" content="Melaya · Build and run AI agents across your business" />
233        <meta
234            property="og:description"
235            content="Melaya is a platform to build and run AI agents across your tools, browser, and Android ph
235one. Six connected products, your own AI, and human approval on every action."
236        />
237        <!-- og:url is set per-route by PageSEO (React 19 hoisting appends, so
238             a static one here would duplicate on every non-home route). -->
239        <meta property="og:image" content="https://melaya.org/og-socials.png" />
240        <meta property="og:image:secure_url" content="https://melaya.org/og-socials.png" />
241        <meta property="og:image:type" content="image/png" />
242        <meta property="og:image:width" content="1731" />
243        <meta property="og:image:height" content="909" />
244        <meta property="og:image:alt" content="Melaya, the platform for building and running AI agents across your tools, browser, and phone" />
245        <meta property="og:locale" content="en_US" />
246        <meta property="og:see_also" content="https://discord.gg/2BBMUUdnkj" />
247        <meta property="og:see_also" content="https://www.linkedin.com/company/melaya/" />
248        <meta property="og:see_also" content="https://x.com/melayaorg" />
249
250        <!-- ── Twitter / X card (also consumed by Brave, DuckDuckGo, Yandex) -->
251        <meta name="twitter:card" content="summary_large_image" />
252        <meta name="twitter:site" content="@melayaorg" />
253        <meta name="twitter:creator" content="@melayaorg" />
254        <meta name="twitter:title" content="Melaya · Build and run AI agents across your business" />
255        <meta
256            name="twitter:description"
257            content="Melaya is a platform to build and run AI agents across your tools, browser, and Android phone. Six connected products, your own AI, and human approval on every action."
258        />
259        <meta name="twitter:image" content="https://melaya.org/og-socials.png" />
260        <meta name="twitter:image:alt" content="Melaya, the AI agent platform for tools, browser, and phone" />
261
262        <!-- ── Canonical + locale alternates ──────────────────────────
263             Owned per-route by PageSEO (seoConfig has a canonical for every
264             route, home included). No static tags here: React 19 metadata
265             hoisting APPENDS rather than replaces, so a static canonical /
266             alternate would leave two on every non-home page, and Google
267             ignores all canonicals when there is more than one. -->
268
269        <!-- ── Cross-protocol discovery ───────────────────────────────
270             - llms.txt: AI ingestion bots (GPTBot, ClaudeBot,
271               PerplexityBot, Google-Extended, Applebot-Extended) read
272               this for a markdown summary of the platform.
273             - rel="me": identity binding to the Discord vanity link.
274             - sitemap: pointer for crawlers that ignore robots.txt
275               (some AI bots do). -->
276        <link rel="alternate" type="text/markdown" href="/llms.txt" title="Melaya summary for AI crawlers" />
277        <link rel="me" href="https://discord.gg/2BBMUUdnkj" />
278        <link rel="me" href="https://www.linkedin.com/company/melaya/" />
279        <link rel="sitemap" type="application/xml" href="/sitemap.xml" />
280        <link
281            rel="search"
282            type="application/opensearchdescription+xml"
283            title="Melaya"
284            href="/opensearch.xml"
285        />
286        <link rel="author" href="/humans.txt" type="text/plain" />
287
288        <!-- ── Schema.org structured data — base graph ────────────────
289             Three top-level entities:
290
291               1. Organization — the company, single canonical @id
292                  referenced by every product entity.
293               2. WebSite — enables Google's "in-SERP search box" via
294                  potentialAction → SearchAction.
295               3. SoftwareApplication (platform aggregate) — the
296                  parent entity; each /product/* page registers a more
297                  specific SoftwareApplication that `isPartOf` this one.
298
299             Per-route entities (FAQPage, BreadcrumbList, product
300             SoftwareApplication) are rendered by `<PageSEO />`. -->
301        
301<script type="application/ld+json">
302            {
303                "@context": "https://schema.org",
304                "@graph": [
305                    {
306                        "@type": "Organization",
307                        "@id": "https://melaya.org/#organization",
308                        "name": "Melaya",
309                        "legalName": "Melaya",
310                        "url": "https://melaya.org",
311                        "logo": {
312                            "@type": "ImageObject",
313                            "url": "https://melaya.org/melaya_mark_dark_1024.png",
314                            "width": 1024,
315                            "height": 1024
316                        },
317                        "image": "https://melaya.org/og-socials.png",
318                        "description": "Melaya is a platform for building and running AI agents across your business tools, browser, and Android apps. Six connected products share one governed foundation: Agents (a visual builder for multi-agent workflows), Assistant (one conversational workspace across your systems), Device Control (agents that operate real Android apps), Browser Control (agents that act inside your browser), an MCP Server (connect Claude, ChatGPT, or Cursor), and Marketing (AI SEO audits, backlink building, and a marketing copilot). Bring your own cloud or local AI, keep human approval on every consequential action, and inspect every run. Trading products follow later under Melaya Labs.",
319                        "foundingDate": "2026-04-01",
320                        "founder": {
321                            "@type": "Person",
322                            "name": "Antoine Roche",
323                            "jobTitle": "Founder",
324                            "url": "https://melaya.org/#team",
325                            "sameAs": ["https://www.linkedin.com/in/antoine-roche/"]
326                        },
327                        "contactPoint": [
328                            {
329                                "@type": "ContactPoint",
330                                "email": "[email protected]",
331                                "contactType": "customer support",
332                                "availableLanguage": ["English", "French"]
333                            }
334                        ],
335                        "knowsAbout": [
336                            "AI agents",
337                            "AI agent platform",
338                            "agentic AI",
339                            "agentic framework",
340                            "visual agent builder",
341                            "no-code AI agent builder",
342                            "multi-agent orchestration",
343                            "multi-agent systems",
344                            "AI workflow automation",
345                            "agentic workflows",
346                            "enterprise AI agents",
347                            "enterprise AI assistant",
348                            "AI assistant for business",
349                            "conversational AI workspace",
350                            "AI copilot",
351                            "AI browser automation",
352                            "browser AI agents",
353                            "AI web agent",
354                            "computer use for the browser",
355                            "web automation without an API",
356                            "Chrome automation with AI",
357                            "mobile AI agents",
358                            "AI agent for Android",
359                            "AI phone control",
360                            "Android app automation",
361                            "Android accessibility automation",
362                            "computer use for mobile",
363                            "app automation without an API",
364                            "MCP server",
365                            "Model Context Protocol",
366                            "remote MCP server",
367                            "MCP for Claude, ChatGPT, and Cursor",
368                            "AI marketing",
369                            "AI marketing copilot",
370                            "AI SEO audit",
371                            "agentic backlink building",
372                            "cross-platform advertising automation",
373                            "bring your own AI",
374                            "local LLM agents",
375                            "Ollama and LM Studio agents",
376                            "open-weight model automation",
377                            "no provider lock-in",
378                            "human-in-the-loop AI",
379                            "AI agent governance",
380                            "AI agent security",
381                            "agent observability",
382                            "agent run replay",
383                            "tool-call audit logs",
384                            "AI agent evaluation",
385                            "AI tool calling",
386                            "scoped tools",
387                            "retrieval-augmented generation",
388                            "cross-run agent memory"
389                        ],
390                        "sameAs": [
391                            "https://github.com/melaya-labs/melaya",
392                            "https://www.linkedin.com/company/melaya/",
393                            "https://x.com/melayaorg",
394                            "https://discord.gg/2BBMUUdnkj"
395                        ]
396                    },
397                    {
398                        "@type": "WebSite",
399                        "@id": "https://melaya.org/#website",
400                        "url": "https://melaya.org",
401                        "name": "Melaya",
402                        "alternateName": "Melaya Agentic Platform",
403                        "publisher": { "@id": "https://melaya.org/#organization" },
404                        "inLanguage": "en-US",
405                        "potentialAction": {
406                            "@type": "SearchAction",
407                            "target": {
408                                "@type": "EntryPoint",
409                                "urlTemplate": "https://melaya.org/documentation?q={search_term_string}"
410                            },
411                            "query-input": "required name=search_term_string"
412                        }
413                    },
414                    {
415                        "@type": "SoftwareApplication",
416                        "@id": "https://melaya.org/#software",
417                        "name": "Melaya",
418                        "alternateName": "Melaya Agentic Platform",
419                        "operatingSystem": "Web, Android, macOS, Linux, Windows",
420                        "applicationCategory": "BusinessApplication",
421                        "applicationSubCategory": "AI Agent Platform",
422                        "description": "Melaya is a platform for building and running AI agents across business tools, browsers, and Android apps, with six connected products: Agents (a visual builder for multi-agent workflows), Assistant (one workspace across your connected systems), Device Control (agents that operate real Android apps), Browser Control (agents that act inside your browser), an MCP Server (connect Claude, ChatGPT, or Cursor), and Marketing (AI SEO audits, backlink building, and a marketing copilot). Bring your own cloud or local AI, combine 8,380+ scoped tools and 111+ subagent templates, and keep human approval on every consequential action. Trading products follow later under Melaya Labs.",
423                        "url": "https://melaya.org",
424                        "image": "https://melaya.org/og-socials.png",
425                        "softwareVersion": "2026.06",
426                        "datePublished": "2026-04-01",
427                        "publisher": { "@id": "https://melaya.org/#organization" },
428                        "offers": [
429                            {
430                                "@type": "Offer",
431                                "name": "Sandbox",
432                                "price": "0",
433                                "priceCurrency": "USD",
434                                "category": "Free",
435                                "availability": "https://schema.org/InStock",
436                                "url": "https://melaya.org/register"
437                            },
438                            {
439                                "@type": "Offer",
440                                "name": "Outpost",
441                                "price": "20",
442                                "priceCurrency": "USD",
443                                "category": "Subscription",
444                                "availability": "https://schema.org/InStock",
445                                "url": "https://melaya.org/register?plan=outpost"
446                            },
447                            {
448                                "@type": "Offer",
449                                "name": "Forge",
450                                "price": "49",
451                                "priceCurrency": "USD",
452                                "category": "Subscription",
453                                "availability": "https://schema.org/InStock",
454                                "url": "https://melaya.org/register"
455                            },
456                            {
457                                "@type": "Offer",
458                                "name": "Bastion",
459                                "price": "129",
460                                "priceCurrency": "USD",
461                                "category": "Subscription",
462                                "availability": "https://schema.org/InStock",
463                                "url": "https://melaya.org/register"
464                            },
465                            {
466                                "@type": "Offer",
467                                "name": "Citadel",
468                                "priceSpecification": {
469                                    "@type": "PriceSpecification",
470                                    "minPrice": "490",
471                                    "priceCurrency": "USD",
472                                    "description": "Starts at $490/mo · contact sales for custom multi-tenant pricing"
473                                },
474                                "category": "Enterprise",
475                                "availability": "https://schema.org/InStock",
476                                "url": "https://melaya.org/register"
477                            }
478                        ],
479                        "featureList": [
480                            "Device Control: AI agents operate real Android apps through Accessibility, per-app allowlist, human approval on every write",
481                            "Bring-your-own model: Claude, GPT, Gemini, DeepSeek, Mistral, Qwen, Ollama, LM Studio",
482                            "8,380+ agentic tools across web, code, data, ops, trading, communication",
483                            "111+ specialized subagents with prebuilt crews",
484                            "Per-workflow RAG with vector + static context + cross runs memory",
485                            "Human-in-the-loop approval on every write, full replay, audit log",
486                            "Secure connector vault with Infisical-managed secrets",
487                            "Cron, webhook, API, SSO, and MCP triggers",
488                            "Multi-tenant with project-scoped RBAC",
489                            "Trading (coming later, by Melaya Labs): Rust-native engine at 310 ns ticker-cache write",
490                            "Trading (coming later, by Melaya Labs): 70+ venues, 65 CEX plus 6 prediction markets (Polymarket, Kalshi, Drift, SX Bet, Azuro, Overtime)",
491                            "Trading (coming later, by Melaya Labs): seven-persona crew (Macro, TA, Quant, Sentiment, Risk, Portfolio, Execution)",
492                            "Trading (coming later, by Melaya Labs): ten safety rails plus paper trading soak; research and backtests today, live execution later"
493                        ]
494                    }
495                ]
496            }
497        </script>
497
498
499        <!-- Affonso affiliate pixel (Accounts - Affiliate program). Records
500             affiliate-link visits (via=, ref=, ...) and writes the affonso_referral
501             cookie on the registrable domain melaya.org (the pixel resolves it with
502             the Public Suffix List), so the landing on melaya.org and the register
503             and checkout flows on app.melaya.org share one referral cookie. Both
504             origins boot from THIS file, so this single tag covers both. Creates
505             window.Affonso; signups call window.Affonso.signup (src/utils/affonso.ts)
506             and checkout forwards the cookie to Stripe metadata.affonso_referral.
507             The program id is public. First-party delivery: the script, its PSL
508             helper, /track and /signups are served by api.melaya.org/r/* (see
509             server/src/routes/affonsoProxy.ts) so Brave Shields / uBlock, which
510             block *.affonso.io as affiliate tracking, no longer lose the referral.
511             data-api-base tells the pixel where /track and /signups live. CSP:
512             script-src + connect-src api.melaya.org, frame-src api.melaya.org
513             (embedded dashboard at /r/embed). The affonso.io entries stay for
514             the hosted fallback (VITE_AFFONSO_EMBED_ORIGIN). -->
515        
515<script async defer src="https://api.melaya.org/r/pixel.js" data-affonso="cmu6ozx6z000utzeakvshn0x6" data-cookie_duration="30" data-api-base="https://api.melaya.org/r"></script>
515
516        <!-- Google tag (gtag.js) — Google Ads AW-18345031327 -->
vendor: 72 bytes, lines 516-517
516
517        <script async src="https://www.googletagmanager.com/gtag/js?id=
517AW-18345031327
vendor: 20 bytes, lines 517-518
517"></script>
518        
518<script>
519          
vendor: 157 bytes, lines 519-522
519window.dataLayer = window.dataLayer || [];
520          function gtag(){dataLayer.push(arguments);}
521          gtag('js', new Date());
522          gtag('config', '
522AW-18345031327
vendor: 12 bytes, lines 522-523
522');
523        
523</script>
523
524      
524<script type="module" crossorigin src="/assets/index-X2xlMaga.js"></script>
524
525      <link rel="modulepreload" crossorigin href="/assets/react-B8xo0EiF.js">
526    </head>
527    <body>
528        <!--
529          Static, always-in-raw-HTML h1 for crawlers that only do a
530          bare HTML scan and never execute the SPA bundle. Bing
531          Webmaster flagged "h1 tag missing" because their static
532          analyser doesnt traverse the noscript fallback below, and
533          the visible h1 lives inside React (HeroSection) so it only
534          appears after the JS bundle runs.
535
536          The h1 is positioned offscreen via the inline style (NOT
537          display:none, which Google penalises as hidden-for-SEO).
538          Offscreen-with-keyboard-tabbable is the standard
539          screen-reader-only pattern and is treated as legitimate
540          accessible content by every crawler.
541
542          Keywords are aligned with the title + meta description so
543          the bare HTML reads as a coherent SEO unit even before any
544          JS runs.
545        -->
546        <h1
547            data-mel-prerender-strip
548            style="position: absolute; width: 1px; height: 1px; padding: 0; margin: -1px; overflow: hidden; clip: rect(0,0,0,0); white-space: nowrap; border: 0;"
549        >
550            Melaya · Build and run AI agents across your business tools, browser, and Android phone. Six connected products on one governed platform: Agents, Assistant, Device Control, Browser Control, MCP Server, and Marketing. Bring your own AI and keep human approval on every consequential action.
551        </h1>
552        <div id="root"></div>
553        <noscript data-mel-prerender-strip>
554            <div style="padding: 24px; font-family: system-ui, sans-serif; line-height: 1.6;">
555                <h1>Melaya · The AI agent platform for tools, browser, and phone</h1>
556                <p>
557                    Melaya is a platform for building and running AI agents across your
558                    business tools, browser, and Android apps, with six connected products:
559                    Agents (a visual builder for multi-agent workflows), Assistant (one
560                    workspace across your connected systems), Device Control (operate real
561                    Android apps), Browser Control (act inside your browser), an MCP Server
562                    (connect Claude, ChatGPT, or Cursor), and Marketing (AI SEO audits,
563                    backlink building, and a marketing copilot). Bring your own cloud or
564                    local AI, combine 8,380+ scoped tools and 111+ subagents, and keep human
565                    approval on every consequential action.
566                </p>
567                <p>
568                    JavaScript is required to use Melaya. For a quick overview, see our public
569                    <a href="/documentation">documentation</a> or join the
570                    <a href="https://discord.gg/2BBMUUdnkj">Discord community</a>.
571                </p>
572                <ul>
573                    <li><a href="/product/agentic-framework">Melaya Agents (visual agent builder)</a></li>
574                    <li><a href="/product/assistant">Melaya Assistant (one workspace across your tools)</a></li>
575                    <li><a href="/product/agentic-device-control">Melaya Device Control (mobile agents for Android)</a></li>
576                    <li><a href="/product/agentic-browser-control">Melaya Browser Control (agents inside your browser)</a></li>
577                    <li><a href="/product/mcp">Melaya MCP Server (connect Claude, ChatGPT, or Cursor)</a></li>
578                    <li><a href="/product/marketing">Melaya Marketing (AI SEO, backlinks, and a copilot)</a></li>
579                    <li><a href="/use-cases">Use cases</a></li>
580                </ul>
581            </div>
582        </noscript>
583        
583<script>
584            (function () {
585                var host = window.location.hostname;
586                var isMelayaAppHost =
587                    host === 'melaya.local' ||
588                    host === 'app.melaya.org' ||
589                    window.location.protocol === 'capacitor:';
590                if (!isMelayaAppHost) return;
591                window.__API_BASE__ = window.__API_BASE__ || 'https://api.melaya.org';
592                window.__WS_BASE__ = window.__WS_BASE__ || 'wss://wss.melaya.org';
593            })();
594        </script>
594
595    
595<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495" integrity="sha512-iIg7k2xntmwu6/uSb5tpc/hySgZc4eoL31yB29W6tJFo2akwjPWcEqnCEdJvGexCL0KEQwVYv5BlowfhVz26hg==" data-cf-beacon='{"version":"2024.11.0","token":"24e0377865764b9885305dac4edc0017","r":1,"spa":2}' crossorigin="anonymous"></script>
595
596</body>
597</html>

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.