Cloud LLMs cannot see your network, and you cannot send OT configs to them. We advise on where AI actually helps network and security work, then build and run it inside your own perimeter: local models, an open MCP (Model Context Protocol) tool layer, grounded in your real data.
Buying a pair of GPU nodes and downloading an open model gets you nothing that works with your systems. The hard part is the wiring.
Topologies, configs and host inventories carry security relevance. In critical or regulated environments, sending that to an external AI service is not an option.
Downloading the model is the easy part. Getting it to read your real network and answer from facts, not guesses, is the work.
Most "AI strategy" stops at the workshop. We build on-prem network AI as a product, so the advice comes from working systems.
Keeping data and inference in-house reduces breach and leakage risk and makes compliance with GDPR and NIS2 easier to defend.
Start with the question of whether and where AI is worth it for your network and security work. End with a working system inside your perimeter, or a clear answer that it is not yet worth building.
Vendor-neutral. We look at your operations, your data and your constraints, and tell you what is worth doing now, what to wait on, and what is hype.
When it is worth building, we deliver the on-prem stack and wire it to the systems you already run. This is where the narrowin AI Stack product gets implemented for you.
Five steps. The engineering most teams cannot staff is the middle three, and it is the work we have already done and packaged.
The questions your team actually needs answered, in security, compliance and day-to-day operations.
Open models tested for tool-calling and structured output, sized to hardware you can run on site.
The tool layer that lets the model retrieve facts from each system rather than inventing them.
Network data, logs, IPAM and your existing operational systems, connected through the open layer.
Deployed on your GPU cluster inside your perimeter, air-gap capable, handed to your team.
The inference stack runs on energy-efficient mini PCs with AI accelerators, right next to your existing infrastructure. Two nodes are enough for load balancing and model routing, and more are added as demand grows. For the strictest requirements the stack runs fully air-gapped.
Fig. — a scaled-out on-prem cluster: eight nodes. Deployments start at two.
On site: the entire inference stack, no cloud.
The design rationale behind on-premises AI for sovereign network analysis was presented by Dr. Tim Senn as a conference paper and talk at the BSI IT-Sicherheitskongress.
The work is real and running: fourteen MCP tools are active today across narrowin Explorer and Log Analytics, with monitoring, automation and ticketing connectors on the same open layer next.
Conference programme →Both connect. This service is the advisory and the build. The narrowin AI Stack is the packaged outcome the build delivers. You can start with advice and decide on the product later.
No. The advisory half is vendor-neutral. If the honest answer is "not worth building yet", that is the answer you get.
Open models tested for local network analysis. Qwen 3 and GLM-4 are the current recommendations for production; Nemotron is promising. Tool-calling quality matters more than raw size.
Compact mini PCs with integrated AI accelerators and a GPU. You can start with two nodes and add more as demand grows. CPU-only is possible with quantised models but slower. Sizing is part of the advisory.
The model is grounded through MCP tools: it queries real configs, topology and logs, and answers cite concrete device names, ports and timestamps. Because every answer ties back to real data, you can check it rather than trust it.
Explorer and Log Analytics today. Anything that exposes an API through the same MCP layer next: CMDB, SIEM, monitoring, ticketing, automation.
Two deep dives on the engineering, and the product the implementation delivers.

The four-layer stack: assistant, local models, the MCP tool layer and the data it grounds on.
Read →
Using AI language models safely: what cloud LLMs put at risk, and what on-prem protects.
Read →
The packaged on-prem AI the implementation delivers: tuned model, GPU cluster, open MCP layer and agent.
See the product →Tell us what you want to ask your network. We will tell you whether AI can answer it today, and what it takes to run that inside your perimeter.
Talk to us about AI