Lower cost of running the infrastructure
Detection, evidence collection, analysis and the verdict are done by NetAI. Your engineers review and decide. Fewer people on call, and senior expertise spent only where it is needed.
NetAI watches your network around the clock. When something breaks, it opens the incident, collects evidence from your devices under a strict command policy and gives your team a root cause they can check — all on your own hardware. Fewer people on call. Fewer night shifts. Shorter incidents.
Your network. Your knowledge. Your AI.
Recorded lab demo · INC-2430Detection, evidence collection, analysis and the verdict are done by NetAI. Your engineers review and decide. Fewer people on call, and senior expertise spent only where it is needed.
At 3 AM the autopilot opens the incident, gathers the evidence and writes the verdict. Your on-call engineer wakes up to a finished investigation, not a raw alert — and is not woken at all when it can wait until morning.
Procedures, vendor knowledge and measured verdicts live in the system, not in one person's head. The same quality at midnight, on holiday, after that engineer leaves.
Reaction in seconds and a cited root cause in minutes in the recorded run, with next steps already listed. Your engineers start at the fix, not at the search.
Every conclusion cites measured evidence, names what was ruled out and shows the exact commands. A completion gate marks anything unverified — no confident guesses.
Local inference on your hardware, services bound to 127.0.0.1, hash-chained audit logs, a read / collect / deny command policy with approvals. In the default air-gapped profile, nothing leaves your perimeter.
Staffing and cost effects are the intended outcome of removing the first- and second-line work from people; they are not a measured customer result. Timings are from the recorded lab run.
Signal → incident → plan → collection → analysis → verdict → report. The autopilot opens the incident from syslog or SNMP, collects under the command policy, concludes with evidence and resolves the incident when the recovery signal arrives.
Hand NetAI the customer's diagnostic bundle — cpinfo, logs, pcaps, screenshots. Code parses and reduces it before the model sees a line; procedures declare the mandatory measurements; the vendor knowledge base is consulted with receipts.
The syslog line lands; twelve seconds later the incident is open with a bounded investigation plan. Priority, device, site and the original alert are on the board before anyone notices.
Recorded lab demonstrationEvery command is classified read, collect or deny before a connection opens. Read commands run at once; bounded log snapshots wait for approval; configuration changes are refused with an alternative.
Recorded lab demonstrationThe NetAI model reasons over reduced evidence on your own hardware. Office Live shows the analysis as it happens, and 'Same time in the system' aligns every device's logs on the incident moment.
Recorded lab demonstrationThe card states the cause, cites the evidence lines, lists what was ruled out by measurement and ends with the next steps. The report is one click away in Markdown, HTML or PDF.
Recorded lab demonstration
Recorded lab demonstration
Recorded lab demonstration
Recorded lab demonstrationNo link on sync interface edge-fw-02/eth3: admin up but link down (NO-CARRIER), while edge-fw-01/eth3 has link (LOWER_UP).INC-2430 · verdict · cited evidence e7, e8, e4, e5, e11, e10
Ruled out by measurement: cluster failover — every snapshot after the signal names edge-fw-01 ACTIVE, failover counter unchanged.
WAN interface of the OPNsense branch gateway set down; the IPsec tunnel to the Check Point cluster drops. NetAI collected from both vendors and traced the path to a dead WAN interface — citing the gateway's own ifconfig and the state-change log line. Ruled out: cluster failover and an IKE parameter or key mismatch.
C-INC-12100 % packet loss on the active member's inside interface. The verdict is a measured contrast: the request is seen on the monitor, nothing arrives on the firewall's interface — one-way ARP, one-way cluster traffic. What cannot be proven is stated as a hypothesis for the engineer.
C-INC-11The standby member reports the sync interface down. NetAI compares both members' link states, interface tables and sync status, rules out a failover and names the exact interface. The verdict came 6 min 48 s after the signal, with no engineer at the keyboard.
C-RC-01It is the silence nobody logged, the subnet hiding inside another one, the file that is gone and used to be here, the count that only makes sense per virtual system. NetAI computes those — it does not guess them. These are real support-work problem classes, anonymized, and every one has a written reference answer the product is graded against. We publish our misses too.
The IPsec tunnel is up and stable, but nothing passes inside it.
One third-party peer never answers Quick Mode: our side keeps initiating and no SA with a non-zero SPI is ever created — silence counted per peer and per side.
After upgrading only the management server, VPN to one peer stopped passing traffic.
A definition file is ignored by the policy compiler after the upgrade, so the gateway proposes its whole /18 where the peer expects a /22 — containment computed, not eyeballed.
The gateway stopped writing logs.
The log field-dictionary files are gone from the configuration directory; reference copies on the same box still have them — the directory listing turned into data and diffed.
Our chassis cluster went down overnight, members dropped one by one.
One node's messaging daemon cannot initialize its trust channel, repeating per virtual system on that node only — the signature found by counting per node.
A large-memory gateway froze silently and came back with 'reboot from unknown reason'.
A timeline gap followed by a cold-boot banner and no panic signature anywhere — the silence itself is the finding.
Deepest on Check Point, with coverage across 18 more vendors. Keyword and vector search combined, exact article, CVE and RFC ids pinned, and a receipt on every citation that the completion gate checks before an answer is allowed to claim it. Procedures, playbooks and baselines are plain Markdown and YAML your own engineers can edit.
C-KB-01 · C-KB-02 · C-AI-03
Recorded lab demonstrationThe NetAI model runs locally on your hardware with a 262,144-token context window. It is adapted to your environment through your own knowledge base, procedures and policies today — and, in our lab, through fine-tuning on the engineering tasks that matter: choosing the right diagnostic tool, answering from received evidence, writing parsers for your log formats.
Lab run 2026-10-08 · 4B test model, not the production NetAI model · LoRA adapter · acceptance: not passed
| model | right tool (180) | answers without a tool (97) | web lookups (40) | schema valid (180) |
|---|---|---|---|---|
| NetAI test model (4B) · base | 63/180 (35.0 %) | 11/97 (11.3 %) | 23/40 (57.5 %) | 125/180 (69.4 %) |
| NetAI test model (4B) + LoRA (lab) | 137/180 (76.1 %) | 4/97 (4.1 %) | 35/40 (87.5 %) | 176/180 (97.8 %) |
Not accepted: answers without a tool regressed — the acceptance gate requires every slice to hold. Every candidate is measured on held-out tasks and we publish the misses. The production NetAI model runs unadapted today; customer-specific models are the next step.
Adapt the NetAI model to your tasks — on data you cannot send outside.
Trained inside. Served inside. Nothing goes out.
llama.cpp on your own hardware, an open-weight model, no cloud APIs.
Core services bind to 127.0.0.1 by default. Nothing is exposed until you decide how your team reaches it; portal authentication is on the roadmap.
Compliance, device, web and vendor logs are SHA-256 chained — edits are detectable.
Command policy read / collect / deny; collect-tier commands wait for an engineer's approval.
Passwords and keys are replaced with <REDACTED> before any log line is indexed or embedded.
Air-gapped, allow-listed or connected — PDF rendering and embeddings run without network access.
C-SEC-01 · C-SEC-02 · C-SEC-03 · C-SEC-04 · C-POL-01 · C-POL-02
Today NetAI reads the vendor knowledge base and analyses your case data. Next it works the vendor case itself — attaches what is requested, replies in the thread, escalates — like an engineer, under your approval policy.
R-VND-01Adapters trained on your approved data, loaded into the local runtime only after they pass acceptance — and your decision.
R-FT-01Training inside the perimeter for data that can never leave: regulated documents, payment data, banking, police and state secrecy.
R-FT-02The isolated deployment profile validated end to end on a customer's own infrastructure, with authentication on the portal.
R-DEP-01 · R-SEC-01
Netaia answers through the product in her own voice: local speech recognition, local text-to-speech, lip-synced, running on the same machine as the investigation. Ask her what happened in an incident, or where your data goes.
A live walkthrough on our lab network, or a pilot on your own diagnostic bundles, run on your hardware. Your data never leaves your machines.
Request a demoThe request form is being connected — we reply within one business day. NetAI Group · netai-group.com