Melaya Review: Governed AI Agents for Tools, Browser & Android (2026)
Melaya is a multi-product AI agent platform—Agents, Assistant, Device Control, Browser Control, MCP, and Marketing—built around BYO models, scoped tools, and…

Opening
Most “AI agent” demos die the same way: the model can talk, but the work still lives in a portal with no API, a phone app with no SDK, or a write action nobody should fire unsupervised. Chatbots paper over that gap with copy-paste. Operators need hands—and a kill switch.
Melaya is Melaya Labs LLC’s bet that those hands should sit behind one governed stack. You build agent pipelines on a visual canvas, chat across approved business systems, drive a real browser tab, operate allowed Android apps through accessibility, expose the same surfaces to Claude / ChatGPT / Cursor via MCP, and optionally run marketing workflows that pause before spend. The public pitch is blunt: Choose your AI. Automate the work. Accelerate your growth.
This review is based on melaya.org product pages, pricing, documentation, the Security Overview (last updated 2026-07-13), and the Launchpadly listing Melaya (slug melaya, listed 2026-09-14, Week 38 / 2026). Product URLs are the source of truth for what ships; counts and plan limits move—confirm live before you pay.
Key takeaways
- Melaya is one platform with six connected products: Agents (visual builder), Assistant, Device Control (Android), Browser Control, MCP Server, and Marketing—not six unrelated apps glued with marketing copy.
- Control thesis is explicit: bring your own model (site claims 28 cloud/local providers), scoped tools (home/marketing cite 7,265+ tools and 111 subagent templates / 13 prebuilt crews), human-in-the-loop before posts, sends, payments, and other consequential writes, plus replayable runs and tool-call traces.
- Device Control operates real Android apps via accessibility—no root, no dedicated API, per-app allowlist, live watch/approve/stop. Melaya’s own mobile-agents page states no iPhone control today.
- Browser Control drives Chrome / Edge / Brave (and an extension path covering Firefox and several Chromium forks). You pick engine/tab/profile in trusted UI; site allowlists and approval gates cover submits, uploads, downloads, and new origins.
- Pricing ladder during research: Sandbox $0, Outpost $20/mo, Forge $49/mo ($469/yr), Bastion $129/mo ($1,239/yr), Citadel from $490/mo (sales). Sandbox is framed as open-beta evaluation. Marketing command-center features appear from Forge upward on the public matrix.
- Security copy is unusually candid: TLS + application envelope encryption for secrets; full-volume disk encryption not yet enabled; no SOC 2 / ISO 27001 attestation as of the July 2026 overview. Treat that as buyer diligence, not a press-release footnote.
What is Melaya?
Melaya is a workspace for building and running AI agents that can act through:
- API/tool connectors and a large tool catalog inside agent pipelines
- A governed browser on your machine (or Melaya-launched controllable browser)
- A paired Android phone for apps that never grew an integration
- An MCP endpoint so assistants you already pay for can call those surfaces
- A marketing cockpit that reads connected ad/search/analytics data and stages spend/edits for approval
Legal entity on the Terms / Security pages: Melaya Labs LLC. Contact surfaces on-site include [email protected] (and enterprise inquiry mailto patterns on Citadel). Founder named on the home “Founding team” block: Antoine Roche, with prior roles called out at BNP Paribas CIB (equity derivatives tooling), SingularityDAO, and Singularity Venture Hub—positioning Melaya as built by someone who has watched production desks break when automation is clever but ungoverned.
It is not a single-model chatbot subscription, not an iOS phone-control product, and not (today) a finished “Trading Crew / Trading Engine” ship—those appear under Coming later → Melaya Labs in the product footer.
Evaluation methodology
Reviewed September 2026 against public materials only:
- Home and product pages: Agentic Framework, Assistant, Device Control, Browser Control, MCP, Marketing
- Pricing tier cards + capability matrix (client-rendered limits)
- Documentation tree (Agent Builder, Device Agents, Browser Control / Extension, Models & Local Runner, Assistant, MCP, Marketing, Trust & safety)
- Mobile AI agents and Browser AI agents explainer pages
- Security Overview (2026-07-13)
- Launchpadly
/startup/melaya— Featured/Verified SaaS listing by founder account info9
We did not instrument a Local Runner lab, measure real agent success rates, or verify every matrix cell against a live account. Competitive notes below are category positioning, not claims Melaya made about named rivals.
Product overview
The shared operating loop
Across products Melaya repeats the same operator pattern: pick a model, grant only the tools/apps/sites needed, run, pause for approval on consequential actions, then inspect the trace. Documentation frames a finished automation as a pipeline (single agent or crew) living in a project, with runs, traces, and evaluations for iteration.
Home “manifesto” tenets match that loop: model freedom, scoped tools, human-in-the-loop, visual compose, team-scoped connectors, full replay. Whether you enter via the canvas, the Assistant chat, a phone pair, a browser attach, or MCP, you are supposed to land on the same permission and audit story.
Six products, one rail
| Product | Job (as published) |
|---|---|
| Melaya Agents | Visual builder: models, tools, memory, schedules, HITL, replayable graphs; 111+ persona/subagent templates |
| Melaya Assistant | Conversational work across approved connectors (examples cite Odoo, Stripe, Google, Zoho, Slack); modes including Safe, Payments only, Autonomy |
| Device Control | Android accessibility agent: observe → act → verify; allowlist + live revoke |
| Browser Control | Real browser automation with structural element refs, live mirror, emergency stop |
| MCP Server | https://api.melaya.org/mcp — site cites 76 tools and 8 OAuth scopes granted one at a time |
| Melaya Marketing | Ads/SEO/analytics cockpit, keyless SEO + PageSpeed audits, Quests, backlinks, socials; approval before spend or live-site edits |
Who operates what
You own model bills (BYO / local), which apps and origins are allowed, and every approval click. Melaya owns the orchestration UI, runner/extension/phone client, connector vault patterns, and audit surfaces. That split matters: a failed supplier-portal run is often a UI-state problem or an over-narrow allowlist—not “the model is dumb.”
Key features
Visual agent builder (Agents)
Drag tools and subagents onto a canvas, pin a model per step, wire edges, add static context / per-workflow RAG / cross-run memory, and drop HITL shields on write tools. Triggers called out on-site: cron, webhooks, API, SSO (SSO appears as a Citadel matrix row). Templates and “Build with AI” paths exist in docs for first pipelines. Practical upside for founders: non-engineers can ship a first crew; practical tax: you still design permissions and failure handling like an ops person, not like a chat toy.
Assistant as operating layer
Assistant positioning is explicit versus provider chatbots: selected live systems instead of pasted files only; enforced modes and editable approval gates instead of prompt hopes; cloud/local/CLI/enterprise routing; round-level cost visibility. Connector examples (Odoo invoices + Zoho Mail follow-ups) show the intended buyer—someone drowning in tab-hopping across finance/ops SaaS.
Device Control (flagship differentiator)
If Melaya has a sharp wedge, this is it. Pair Android via Melaya app + QR, grant Accessibility (user must enable it—OS gated), allow apps one by one, then let agents tap/type/swipe with observe-act-verify loops. Server and phone both check allowlists before execution. Publishing and other protected writes stage for human review. Mobile explainer is clear about poor fits: unsupervised finance, safety-critical control, CAPTCHA bypass, or anything that violates app rules or consent.
Limitation with consequence: Android only. iOS teams should not budget Melaya as phone automation today—you will still be the hands on iPhone workflows.
Browser Control + extension
Agents read a compact structural snapshot with stable element refs (not “fragile pixel guesses,” per product copy), act one step at a time, and re-check. Approvals gate consequential moves; humans handle sign-in, CAPTCHA, and payment, then agents resume. Extension availability is advertised for Chrome Web Store / Edge Add-ons / Firefox Add-ons / Opera build, plus Chromium forks. Some UI affordances on the product page still mark Coming soon (e.g. attaching already-open tabs / real profile paths in one control panel)—verify the exact attach mode you need before promising a rollout.
MCP: paste one endpoint
MCP page pitch: stop being the mouse for Claude, ChatGPT, Cursor, and a long client list. One HTTP MCP URL, OAuth scopes (melaya:read, melaya:phone, melaya:browser, melaya:pipelines, etc.), tool list filtered to grants. Example prompts cover Product Hunt pipelines, Instagram DM triage (no auto-reply), supplier portal invoice tables, and Monday failure digests. The hard rule Melaya repeats: the agent can narrow grants during a run; it cannot widen them.
Melaya Marketing
Separate growth cockpit: blended ad views, SEO specialists board, Quests with estimated “money on the table,” backlink submissions, social command center, marketing assistant. First SEO / page-speed audit is free after signup (BYO model). Pricing matrix shows marketing surfaces starting at Forge; public backlink API sample showed Forge 10 posts/day and Bastion 100/day (Citadel uncapped)—treat as live entitlements that can change.
Models, Local Runner, hybrid
Site and docs emphasize Ollama / LM Studio local paths beside Claude, GPT, Gemini, and CLI subscriptions you already pay for. Melaya’s commercial pitch is platform seats + governance, not metering every token itself—provider usage may still be billed by the provider. For recurring browser/phone jobs, local inference is how they argue marginal cost collapses to hardware and electricity.
Pricing and value
Published ladder (pricing page, research snapshot)
| Tier | List price | Role (as framed) |
|---|---|---|
| Sandbox | $0 / mo | Evaluate during open beta; no card required for that path |
| Outpost | $20 / mo | Individual paid tier (“Popular” on marketing) |
| Forge | $49 / mo or $469 / yr (~20% save) | Build tier; marketing features unlock here |
| Bastion | $129 / mo or $1,239 / yr | Operate / team-ish limits |
| Citadel | From $490 / mo | Team, scale, private deployment, SLA discussions |
Matrix limits worth budgeting against
Public capability matrix (rendered values during research; confirm in-account):
- Projects: 1 / 1 / 3 / 3 / Unlimited across Sandbox → Citadel
- Pipelines: 2 / 5 / 15 / 100 / Unlimited
- Runs: 10 / 50 / 120 / 500 / “5k – Uncapped”
- Concurrent: 1 / 2 / 3 / 5 / “15 – 100”
- Assistant messages: Sandbox 30 total; then 10 / 20 / 50 / 200 per day
- RAG: none on Sandbox; Outpost 1 store / 50 MB → Citadel Unlimited / up to custom
- Retention: 7 / 14 / 30 / 90 / 365 days
- Seats: 1 / 1 / 1 / 3 / “10 – Unlimited”
- Device Control, BYOK, local, CLI runners, cloud models, crews: shown included across tiers
- Cloud execution, ads cockpit, SEO audit, pagespeed, marketing AI copilot: Forge+
- SSO, private deployment, SLA, multi-entity: Citadel
Value judgment: Outpost at $20 is cheap for a serious browser+phone experiment if Sandbox limits choke you. Forge becomes the real “I’m running marketing + more pipelines” entry. Bastion’s seat and run headroom matter once more than one operator shares projects. Citadel is not self-serve SaaS math—expect architecture and support scoping.
Honest cost caveat: platform fee ≠ total cost of ownership. Model APIs, failed agent retries, and human approval time dominate if you wire agents into revenue workflows without redesigning the approval queue.
How Melaya compares
| Need | Lean Melaya | Lean single-vendor browser agent | Lean Zapier/Make-style API automation | Lean raw Playwright + scripts |
|---|---|---|---|---|
| API + browser + Android under one HITL/audit story | Core pitch | Browser-strong, phone usually absent | API-strong, UI apps weak | DIY everything |
| BYO / local models | Explicit | Often locked to one model brand | Model-optional / separate | Your code |
| Visual multi-agent crews | First-class | Rare | Partial (flows, not crews) | None |
| Marketing ops cockpit | Built-in product | Usually separate tools | Partial | Build yourself |
| Attested compliance pack today | Not yet (per Security Overview) | Varies | Often stronger at enterprise SKUs | Your responsibility |
Use Melaya when the scarce asset is governed multi-surface agency. Skip category comparisons that pretend every agent product solves phone + browser + MCP + marketing equally—most do not claim that combination.
Who should use Melaya
- Founders and ops leads who already drown in portals and mobile apps without APIs, and will actually sit the approval queue.
- Small technical teams that want one audit/HITL language across assistants, scheduled crews, and MCP clients (Claude Code, Cursor, ChatGPT, etc.).
- Growth operators who want SEO/ads actions staged behind approvals, not another read-only dashboard.
- Privacy-sensitive workflows that prefer local models for some steps while keeping cloud models for others inside the same pipeline.
- Agencies building client automations who need project-scoped connectors and replay when something misbehaves.
Who should wait
- Teams that need iPhone / iOS device control now.
- Buyers whose procurement gate is SOC 2 Type II or ISO 27001 today—Melaya states those attestations are not held as of the July 2026 Security Overview.
- Orgs that need disk-volume encryption as a hard control before any pilot; Melaya discloses production block devices are presently unencrypted at disk level, with LUKS on the roadmap.
- Buyers who only wanted a thin chat UI and will ignore allowlists, traces, and approval design—the product surface will feel oversized.
- Anyone counting on Trading Crew / Trading Engine features that are still marked coming later.
Editorial ratings
Launchpadly editorial judgment from public materials—not a lab reliability scorecard.
| Category | Score (/10) |
|---|---|
| Builder, Assistant & onboarding | 7 |
| Sandbox-to-Citadel pricing ladder | 7 |
| BYO models, tools & MCP | 9 |
| Phone, browser & pipelines | 9 |
| Six products under one rail | 8 |
Ease (7): Docs and product narrative are strong; breadth means first-week setup is still an operator project (phone permissions, extension, connectors, approval policy). Value (7): Transparent ladder and a real free Sandbox; matrix complexity and BYO model bills keep “cheap” relative. AI capability (9): Multi-provider + MCP + tool depth is the point of the platform. Automation (9): Browser + Android + scheduled pipelines is rare as one governed story. Depth (8): Six products is ambitious; Labs trading surfaces and some matrix “coming soon” cells show unfinished edges.
Pros and cons
Pros
- Coherent governance story: scoped tools, HITL, traces/replay across surfaces
- Real Android Device Control without per-app API projects
- Browser automation with structural refs, live observation, and emergency stop
- MCP endpoint that reuses assistants teams already pay for
- BYO cloud/local/CLI model routing without rebuilding workflows per vendor
- Marketing product that stages spend and site edits behind approval cards
- Unusually specific Security Overview (what is live vs roadmap)
Cons
- Android-only phone story; no claimed iOS control
- No SOC 2 / ISO attestation yet; volume encryption still roadmap
- Broad surface area—easy to buy the platform and under-implement approvals
- Plan matrix is dense; marketing and higher automation clocks gate at Forge+
- Some browser attach/profile paths still marked coming soon on product UI
- Trading Labs products are not shipping features for this review
Real use cases
Ops lead + supplier portals. Use Browser Control on allowlisted origins to pull invoices or stage purchase orders, with submit gated. Keep a human on CAPTCHA and payment. Replay the run when the portal markup shifts.
Founder without a mobile SDK budget. Pair an Android work phone, allowlist only LinkedIn / Gmail / Slack (example pattern from Melaya’s own allowlist UI), draft engagement in-app, require approval before send. Do not allowlist banking.
Cursor / Claude Code power user. Add https://api.melaya.org/mcp, grant phone + browser + pipelines scopes narrowly, and ask the assistant to build a scheduled Melaya pipeline instead of clicking the builder for every experiment.
Solo SaaS marketer. Start Sandbox → Outpost, run the free SEO audit path, upgrade to Forge when you need the marketing cockpit and higher pipeline/run limits, and keep every spend action on approval cards until the false-positive rate is boring.
Team sharing connectors. Move to Bastion when three seats and higher run/retention limits matter; treat Citadel as the conversation for SSO, private deployment, and SLA—not a self-serve checkbox.
Verdict
Melaya is a governed agent operating system for work that still happens in browsers and Android apps—as well as in normal SaaS APIs—under one approval and audit language. The buy case is strongest when Device Control and Browser Control are load-bearing, MCP fits how your team already works, and you accept BYO model economics plus an early-stage compliance posture.
Buy if you will configure allowlists and HITL seriously, need Android + browser agency now, and Outpost/Forge limits match your run volume.
Skip if you need iOS phone control, a completed SOC 2 report before pilot, or only wanted a chatbot with a prettier UI.
Start at melaya.org on Sandbox, pair one throwaway Android device and one low-risk browser origin, force an approval on a write action, read a full trace end-to-end, then climb the pricing ladder only after that loop feels trustworthy.
FAQ
What is Melaya best for?
Building and running AI agent pipelines that can use business tools, a real browser, and Android apps, with human approval before consequential actions—and optionally wiring those same surfaces into assistants via MCP.
How much does Melaya cost?
Public pricing during research: Sandbox $0, Outpost $20/mo, Forge $49/mo ($469/yr), Bastion $129/mo ($1,239/yr), Citadel from $490/mo. Confirm live on melaya.org/en/pricing; model providers may bill separately.
Does Melaya control iPhones?
No. Device Control is documented as Android. Melaya’s mobile AI agents page states it should not be evaluated as an iPhone-control product.
What is the MCP endpoint?
Melaya publishes a remote MCP server at https://api.melaya.org/mcp. Product copy cites 76 tools filtered by 8 OAuth scopes you grant explicitly.
Is there a free plan?
Yes. Sandbox is $0/mo and described as an open-beta evaluation plan. Assistant message and run limits are tight—use it to test the control loop, not to run production volume.
How does Melaya handle security and compliance?
The Security Overview describes TLS, CSP, tenant isolation, envelope encryption for credentials, Device Control deny-by-default allowlists, and logging. It also states Melaya does not currently hold SOC 2 or ISO 27001 attestations and that full-volume disk encryption is not yet enabled. Read that page before enterprise pilots.
Who builds Melaya?
Public founding-team copy names Antoine Roche (Melaya Labs LLC). The Launchpadly listing is attributed to founder account info9.