products/AI Stack

An AI you can ask anything about your network, on-prem.

The agent reasons, the flexible context integration layer reaches your systems, and every answer is grounded in the data you actually run. It runs on your own hardware; nothing leaves the building.

narrowin AI Stack — on-prem agent CONNECTED
ON-PREM · a GPU cluster sized to youdesigned to your requirements: starts dual-node, scales as you grow
narrowin Explorer
topology · devices · configs
narrowin Log Analytics
events · syslog
Your CMDB
asset register
Your SIEM
alerts & cases
◇ INTEGRATION LAYER
[ Walkthrough ]

Watch the agent work an incident.

[ The reality ]

Cloud AI can't see your network. Your network can't go to the cloud.

An AI that understood your topology, configs and logs would turn hours of CLI work into minutes. The catch: that data can't leave the building, and rolling your own is a project most teams can't staff.

  • Cloud LLMs have no view of your topology, configs or logs
  • OT data can't leave the perimeter: NIS2, IEC 62443, air-gap policy
  • A downloaded model on a GPU box still connects to nothing
  • Model tuning, data wiring and an agent layer is a project that stalls
[ Use cases ]

Where the AI Stack fits.

One agent, one data foundation: deep project work and fast operational answers, both entirely on-prem.

01

Security assessments

Segmentation reviews, port-security and hardening checks across 50 multivendor switches: network-wide, report-ready, in minutes.

02

Incident triage

"Which PLCs share a VLAN with the compromised HMI?" Blast radius and lateral-movement context for the SOC, without a CLI session per device.

03

Segmentation & compliance

Audit IT↔OT boundaries against IEC 62443 zones; validate against NIS2 and KRITIS hardening baselines.

04

Change detection

"What changed at the substation in the last 24 hours?" Snapshot diffs and forensic timelines, ranked by severity.

05

OT asset visibility

Find every Siemens, Schneider and Moxa device by vendor and map it to its network location and zone.

06

Day-to-day troubleshooting

Fast, targeted answers about devices, hosts and events: consolidated context instead of manual correlation across tools.

[ Capabilities ]

What the AI Stack does.

An agent that reasons, an open layer that connects, and a stack that runs entirely on your hardware.

Reasonthe agent
Natural-language agent
Which devices share a VLAN with 10.1.5.22?
⚙ explorer · get_vlan_members
Six devices on VLAN 40 — two HMIs, three PLCs and the cell switch. Want the list?
Ask in plain language. No scripting, no CLI expertise. NOC and SOC analysts query network state directly.
Grounded, not guessing
live data
every answer from your real systems
data-driven answers, grounded in your real configs
The agent doesn't store your network; it retrieves it on demand through tools. Answers cite real configs, real topology.
Assess or triage
PROJECT MODE
Deep, network-wide assessments: structured, report-ready findings.
OPERATIONAL MODE
Fast, targeted lookups when something is on fire.
One agent, one data foundation: deep audits and fast incident answers, the same systems behind both.
Connectthe context integration layer
The context integration layer
AGENT tool tool tool CONTEXT INTEGRATION LAYER
This is the integration layer. Tool design is the craft: the agent reaches each system through a defined tool, not a scraper. Role-based access control (RBAC) keeps each user to the systems they are already allowed to access, so the agent never widens their access.
Live integrations
narrowin Explorer● live
narrowin Log Analytics● live
Your CMDBopen
Your SIEMopen
Two narrowin integrations are connected today: Explorer's digital twin and Log Analytics' events.
Open to your stack
SIEM / SOCFirewallMonitoring TicketingSCADA / HistorianAnsible Asset / CMDB+ more
Add a log source, a monitoring system or an automation tool through the integration layer, without changing the core.
Run on-premthe local stack
Open models, tuned
GLM-4Qwen 3Devstral NemotronLlama 4+ evaluated
Open-source models, selected and tuned to the hardware. What matters is tool-calling, not raw model size.
Sized to your network
start · dual-node scale · as you grow
We design the cluster with you: most start dual-node and scale as use cases and users are added.
Nothing leaves
YOUR PERIMETER agent model your data no cloud calls · offline-capable
The model, the agent and your data stay inside the perimeter: full data sovereignty, offline-capable.
Standalone & open

The AI Stack is a standalone product, not an add-on. It talks to Explorer and Log Analytics today through the integration layer, and reaches third-party systems through the very same open layer.

[ How it works ]

The hard parts, already built.

The on-prem AI that works from day one, because the engineering most teams can't staff is done and packaged.

1

We size the stack with you

A GPU cluster designed to your requirements, the tuned open model, the context integration layer and the agent, built and calibrated together.

2

Connect your data

Through the flexible integration layer, you can connect your own systems, as well as Explorer and Log Analytics.

3

Ask in plain language

Assessments or incident questions: the agent calls the tools and grounds every answer in real data.

4

Nothing leaves

The model and the agent run on your hardware, inside your perimeter. No data goes to a cloud.

[ Details ]

The specifics.

Technical specifications
DeploymentOn-premises: a GPU cluster designed to your requirements; typically dual-node and scalable
ModelsOpen-source: GLM-4, Qwen 3, Devstral, Nemotron and others, tuned to the cluster
IntegrationFlexible context integration layer
Live todaynarrowin Explorer (digital twin), narrowin Log Analytics
Extensible toYour CMDB and SIEM, monitoring, ticketing, SCADA/historian, firewall, via the integration layer
InterfaceChat, web client, API
DataNothing leaves your infrastructure: no cloud calls, offline-capable
StatusBeta: Explorer + Log Analytics integrations live
Frequently asked

Is my network data sent to a cloud LLM?

No. The model and the agent run on your own GPU cluster, inside your perimeter. There are no API calls to a cloud provider; the system is offline-capable.

What is the context integration layer?

The integration layer between the agent and your systems. Each system is reached through a defined set of tools. Role-based access control (RBAC) keeps each user to what they are already allowed to access, so the agent never widens it. The layer is open: more systems can be added without changing the core.

Which models does it run?

Open-source models: GLM-4, Qwen 3, Devstral, Nemotron and others, selected and tuned to the on-prem hardware. Tool-calling quality matters more than raw size.

Won't an AI just hallucinate?

Knowledge questions can. Data-driven questions answered through the integration layer's tools stay grounded in your real configs, topology and logs, so every answer can be checked against the source.

Can it connect to my own systems?

That is the point of the open layer. Explorer and Log Analytics are live today; your CMDB, SIEM, monitoring and ticketing connect through the same integration layer.

Is it an add-on to Explorer?

No, it is a standalone product. It is a full, open on-prem AI in its own right, usually integrated with a customer's own systems. Standard integrations for Explorer, IPAM and Log Analytics are available out of the box.

[ Related work ]

Deep dives into on-prem AI.

Bring the intelligence on-prem.

Your network finally has something that can read all of it, reason over it, and never leave the building.

Talk to us about the AI Stack