NetAI Group · Autonomous network engineering

The AI engineer that finds the root cause before your on-call engineer wakes up.

NetAI watches your network around the clock. When something breaks, it opens the incident, collects evidence from your devices under a strict command policy and gives your team a root cause they can check — all on your own hardware. Fewer people on call. Fewer night shifts. Shorter incidents.

Your network. Your knowledge. Your AI.

NetAI incident card for INC-2430: root cause with cited evidence and ruled-out hypothesesRecorded lab demo · INC-2430
Recorded lab incident INC-2430 · product event log · no engineer involved
12 sfrom the first syslog line to an open incident
45 sto 21 artifacts collected from three devices
6 min 48 sto the root cause, cited to the evidence
0engineers involved — collect steps pre-approved in the lab plan
What changes for your team

Run more infrastructure with fewer people — and sleep through the night.

Lower cost of running the infrastructure

Detection, evidence collection, analysis and the verdict are done by NetAI. Your engineers review and decide. Fewer people on call, and senior expertise spent only where it is needed.

Fewer night shifts

At 3 AM the autopilot opens the incident, gathers the evidence and writes the verdict. Your on-call engineer wakes up to a finished investigation, not a raw alert — and is not woken at all when it can wait until morning.

Less dependence on one expert

Procedures, vendor knowledge and measured verdicts live in the system, not in one person's head. The same quality at midnight, on holiday, after that engineer leaves.

Shorter incidents

Reaction in seconds and a cited root cause in minutes in the recorded run, with next steps already listed. Your engineers start at the fix, not at the search.

Verifiable, not plausible

Every conclusion cites measured evidence, names what was ruled out and shows the exact commands. A completion gate marks anything unverified — no confident guesses.

Private by design

Local inference on your hardware, services bound to 127.0.0.1, hash-chained audit logs, a read / collect / deny command policy with approvals. In the default air-gapped profile, nothing leaves your perimeter.

Staffing and cost effects are the intended outcome of removing the first- and second-line work from people; they are not a measured customer result. Timings are from the recorded lab run.

Two ways to put NetAI to work

In your NOC, and in your support queue.

01 · On site

A 24/7 engineer inside your monitoring

Signal → incident → plan → collection → analysis → verdict → report. The autopilot opens the incident from syslog or SNMP, collects under the command policy, concludes with evidence and resolves the incident when the recovery signal arrives.

  • Opens incidents without an engineer (recorded: +12 s)
  • Collect-tier commands wait for an approval; read-only runs immediately
  • Incident card: what, where, when — and the next steps
  • Markdown, HTML and PDF report for every incident
C-INC-01 · C-INC-03 · C-INC-06 · C-REP-01
02 · Support

First and second line for your vendor case queue

Hand NetAI the customer's diagnostic bundle — cpinfo, logs, pcaps, screenshots. Code parses and reduces it before the model sees a line; procedures declare the mandatory measurements; the vendor knowledge base is consulted with receipts.

  • Case report: verdict · proven · hypothesis · evidence · ruled out · plan, cited file:line
  • Graded by code against 30 written reference answers, run after run
  • Subnet containment, missing files and per-node signatures computed, not guessed
  • Customer data stays on your machine
C-CASE-01 · C-CASE-02 · C-CASE-04 · C-CASE-05
How it works

From the first signal to a verdict you can check.

STEP 1

A signal becomes an incident

The syslog line lands; twelve seconds later the incident is open with a bounded investigation plan. Priority, device, site and the original alert are on the board before anyone notices.

NetAI incidents board with INC-2430 opened automatically from the syslog signalRecorded lab demonstration
STEP 2

Evidence is collected under policy

Every command is classified read, collect or deny before a connection opens. Read commands run at once; bounded log snapshots wait for approval; configuration changes are refused with an alternative.

Incident card while device output streams in during collectionRecorded lab demonstration
STEP 3

Analysis runs inside your perimeter

The NetAI model reasons over reduced evidence on your own hardware. Office Live shows the analysis as it happens, and 'Same time in the system' aligns every device's logs on the incident moment.

Office Live rendering the live analysis traceRecorded lab demonstration
STEP 4

A verdict with the receipts

The card states the cause, cites the evidence lines, lists what was ruled out by measurement and ends with the next steps. The report is one click away in Markdown, HTML or PDF.

INC-2430 incident card: cause, ruled-out hypotheses, timelineRecorded lab demonstration
Same time in the system — every participating device's logs aligned on the incident moment, with line and error counts.Recorded lab demonstration
Same time in the system — every participating device's logs aligned on the incident moment, with line and error counts.
Network atlas — four sites, 35 objects, every recorded relationship, in 3D and in plan view.Recorded lab demonstration
Network atlas — four sites, 35 objects, every recorded relationship, in 3D and in plan view.
The engineering report — verdict, observed facts, what was ruled out, next steps.Recorded lab demonstration
The engineering report — verdict, observed facts, what was ruled out, next steps.
Evidence-backed verdicts

Not an AI explanation. A root cause you can check, line by line.

No link on sync interface edge-fw-02/eth3: admin up but link down (NO-CARRIER), while edge-fw-01/eth3 has link (LOWER_UP).
INC-2430 · verdict · cited evidence e7, e8, e4, e5, e11, e10

Ruled out by measurement: cluster failover — every snapshot after the signal names edge-fw-01 ACTIVE, failover counter unchanged.

INC-2434

VPN tunnel down between two vendors

WAN interface of the OPNsense branch gateway set down; the IPsec tunnel to the Check Point cluster drops. NetAI collected from both vendors and traced the path to a dead WAN interface — citing the gateway's own ifconfig and the state-change log line. Ruled out: cluster failover and an IKE parameter or key mismatch.

C-INC-12
INC-2432

Traffic silently lost on the active firewall

100 % packet loss on the active member's inside interface. The verdict is a measured contrast: the request is seen on the monitor, nothing arrives on the firewall's interface — one-way ARP, one-way cluster traffic. What cannot be proven is stated as a hypothesis for the engineer.

C-INC-11
INC-2430

Cluster sync link goes down on the standby member

The standby member reports the sync interface down. NetAI compares both members' link states, interface tables and sync status, rules out a failover and names the exact interface. The verdict came 6 min 48 s after the signal, with no engineer at the keyboard.

C-RC-01
Built for the hard ones

The hard part is rarely reading the log.

It is the silence nobody logged, the subnet hiding inside another one, the file that is gone and used to be here, the count that only makes sense per virtual system. NetAI computes those — it does not guess them. These are real support-work problem classes, anonymized, and every one has a written reference answer the product is graded against. We publish our misses too.

The IPsec tunnel is up and stable, but nothing passes inside it.

One third-party peer never answers Quick Mode: our side keeps initiating and no SA with a non-zero SPI is ever created — silence counted per peer and per side.

After upgrading only the management server, VPN to one peer stopped passing traffic.

A definition file is ignored by the policy compiler after the upgrade, so the gateway proposes its whole /18 where the peer expects a /22 — containment computed, not eyeballed.

The gateway stopped writing logs.

The log field-dictionary files are gone from the configuration directory; reference copies on the same box still have them — the directory listing turned into data and diffed.

Our chassis cluster went down overnight, members dropped one by one.

One node's messaging daemon cannot initialize its trust channel, repeating per virtual system on that node only — the signature found by counting per node.

A large-memory gateway froze silently and came back with 'reboot from unknown reason'.

A timeline gap followed by a cold-boot banner and no panic signature anywhere — the silence itself is the finding.

Vendor knowledge, with receipts

A curated vendor knowledge base that lives on your machine.

150,582records
817,357indexed chunks
19vendors

Deepest on Check Point, with coverage across 18 more vendors. Keyword and vector search combined, exact article, CVE and RFC ids pinned, and a receipt on every citation that the completion gate checks before an answer is allowed to claim it. Procedures, playbooks and baselines are plain Markdown and YAML your own engineers can edit.

C-KB-01 · C-KB-02 · C-AI-03

Vendors page of the NetAI knowledge base showing coverage per vendorRecorded lab demonstration
Your AI, your data

Every company has a different network. Why depend on the same generic AI?

The NetAI model runs locally on your hardware with a 262,144-token context window. It is adapted to your environment through your own knowledge base, procedures and policies today — and, in our lab, through fine-tuning on the engineering tasks that matter: choosing the right diagnostic tool, answering from received evidence, writing parsers for your log formats.

LAB RESULT · REAL ARTEFACT

Measured on held-out tasks — not the training set

Lab run 2026-10-08 · 4B test model, not the production NetAI model · LoRA adapter · acceptance: not passed

modelright tool (180)answers without a tool (97)web lookups (40)schema valid (180)
NetAI test model (4B) · base63/180 (35.0 %)11/97 (11.3 %)23/40 (57.5 %)125/180 (69.4 %)
NetAI test model (4B) + LoRA (lab)137/180 (76.1 %)4/97 (4.1 %)35/40 (87.5 %)176/180 (97.8 %)

Not accepted: answers without a tool regressed — the acceptance gate requires every slice to hold. Every candidate is measured on held-out tasks and we publish the misses. The production NetAI model runs unadapted today; customer-specific models are the next step.

ROADMAP · adaptation on your own hardware — inference is local today

Data that can never leave

Adapt the NetAI model to your tasks — on data you cannot send outside.

Network operationsincidents · configurations · logs
Regulated documentsinternal · restricted · classified
Payment dataPCI DSS scope
Banking & official secrecybank · service · police
Your perimeter · the NetAI model
State secrecysovereign deployments

Trained inside. Served inside. Nothing goes out.

Security and customer control

Intelligence inside your perimeter.

Local inference

llama.cpp on your own hardware, an open-weight model, no cloud APIs.

Services on 127.0.0.1

Core services bind to 127.0.0.1 by default. Nothing is exposed until you decide how your team reaches it; portal authentication is on the roadmap.

Hash-chained audit

Compliance, device, web and vendor logs are SHA-256 chained — edits are detectable.

Governed access

Command policy read / collect / deny; collect-tier commands wait for an engineer's approval.

Secrets never indexed

Passwords and keys are replaced with <REDACTED> before any log line is indexed or embedded.

Isolation profiles

Air-gapped, allow-listed or connected — PDF rendering and embeddings run without network access.

C-SEC-01 · C-SEC-02 · C-SEC-03 · C-SEC-04 · C-POL-01 · C-POL-02

Roadmap

Where NetAI goes next.

ROADMAP

The vendor case, end to end

Today NetAI reads the vendor knowledge base and analyses your case data. Next it works the vendor case itself — attaches what is requested, replies in the thread, escalates — like an engineer, under your approval policy.

R-VND-01
ROADMAP

Customer-specific models

Adapters trained on your approved data, loaded into the local runtime only after they pass acceptance — and your decision.

R-FT-01
ROADMAP

Adaptation on your own hardware

Training inside the perimeter for data that can never leave: regulated documents, payment data, banking, police and state secrecy.

R-FT-02
ROADMAP

Air-gap profile at a customer site

The isolated deployment profile validated end to end on a customer's own infrastructure, with authentication on the portal.

R-DEP-01 · R-SEC-01
Netaia, the NetAI avatar
Meet Netaia

The face of NetAI — a live, local AI engineer you can talk to.

Netaia answers through the product in her own voice: local speech recognition, local text-to-speech, lip-synced, running on the same machine as the investigation. Ask her what happened in an incident, or where your data goes.

The films

See it work — four minutes, recorded on our lab network.

Next step

See NetAI on your own incidents.

A live walkthrough on our lab network, or a pilot on your own diagnostic bundles, run on your hardware. Your data never leaves your machines.

The request form is being connected — we reply within one business day. NetAI Group · netai-group.com