Talk to your servers.
Like a senior SRE sits next to you.
The AI Assistant turns chat messages into typed, parameter-validated, audit-logged operations across your fleet. Every mutation gates on your click. The model can't invent shell commands — only the registered tool surface is callable.
Let me check what's happening on web-01 — pulling metrics, the process list, and recent error log entries.
get_metrics(agent_id, range=5m)list_processes(sort=cpu, top=10)read_log(path=/var/log/nginx/error.log, tail=100)Found it — 1,412 stuck PHP-FPM connections, all waiting on slow MySQL queries. The error log shows max_user_connections warnings starting 14 minutes ago. Want me to restart php-fpm to clear the stuck connections, then investigate the slow query log?
How it works
Six gates between your chat message and a running command.
- 01
You ask in plain English
"Why is nginx using 80% CPU on web-01?" — no syntax to remember, no man pages to read.
- 02
AI picks the right tools
The model selects from 84+ typed tools. It can't invent shell commands — only the registered tool surface is callable.
- 03
Risk tier gates the action
Reads auto-run. Writes prompt for Approve / Deny. Destructive ops require a PIN. The HTTP layer enforces every gate.
- 04
Agent executes
The on-server agent receives a typed RPC over mTLS, runs the validated command, streams output back.
- 05
AI explains the result
The model summarises what the tool returned in human terms — "load is high because PHP-FPM has 1,400 stuck connections" — and proposes the next step.
- 06
Audit log captures everything
Every invocation persists with conversation ID, params, status, and output. Replay any session months later for compliance.
Risk model
Three tiers, hard-coded into the protocol.
The model can categorise tools however it wants in chat. The HTTP layer is the source of truth — and it doesn't budge.
Read-only & safe
Reads, lookups, diagnostics. Same blast radius as a SELECT — runs instantly without prompting.
Mutating — your call
Anything that writes. AI prepares the call, you click Approve / Deny. No quiet mutations, ever.
PIN-gated
Destructive operations require a second factor on top of approval — or are flagged not-yet-supported.
Tool surface
84+ production tools across 12 categories.
Each tool is parameter-validated, audit-logged, and risk-tiered. Add new tools by registering them in the open-source agent — no LLM fine-tuning required.
Read-only diagnostics
18 tools — see the full list on the homepage.
Deploy from GitHub
5 tools — see the full list on the homepage.
Databases (PG / MySQL / Redis)
9 tools — see the full list on the homepage.
Security audit & scan
8 tools — see the full list on the homepage.
Network & firewall
5 tools — see the full list on the homepage.
Apps & frameworks
5 tools — see the full list on the homepage.
Process control
6 tools — see the full list on the homepage.
Maintenance & updates
6 tools — see the full list on the homepage.
Mail / extras / control plane
22 tools — see the full list on the homepage.
Architecture
The AI lives in our control plane. Your server only runs typed commands.
Server-resident AI agents are easy to build and dangerous to run. We split the brain out so the box never sees an LLM, an API key, or an unbounded shell.
AI lives here
control plane
- · LLM API keys
- · Risk-tier gating
- · Approval flow
- · Credit accounting
- · Audit log
Agent on your server
open source
- · Executes typed commands
- · Command blocklist
- · Outbound-only — no LLM
- · No API keys on box
You
browser · panel
- · See every action
- · Approve mutations
- · Roll back if needed
- · Audit trail forever
Defense in depth
Six layers between chat and root.
Tool registry, not shell
AI calls registered tools only. No raw shell. No bash escape hatch.
Param validation
Every tool has a typed schema. Invalid params reject before the agent ever sees them.
Command blocklist
Agent vetoes rm -rf /, dd, mkfs even when generated. Defense in depth.
Audit log
Every invocation persists with conversation ID + user ID. Replayable forever.
Credit + rate limits
Per-message credit deduction caps cost. No runaway billing from a stuck loop.
Open-source agent
Read every command path on GitHub before installing. No closed binary.
FAQ
Things people ask before turning it on.
Which LLM does Cloudnan use?
Can the AI access servers from a different organisation?
What happens if the LLM hallucinates a destructive command?
Does the AI have access to my application data?
How much does each AI message cost?
Can I disable the AI Assistant entirely?
Your fleet deserves better.
Get started in minutes.
Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.
- 7-day free trial
- No credit card
- Cancel anytime
