Security · the glass stays shut

The agent never holds your keys.

Each investigation runs in a sandbox. Credentials inject at the proxy. PII is stripped before the model. Deploy hosted, in your VPC, or self-host the open core. Write office@alertnest.skin if you need the on-prem path.

Lockout · proxy bay NO RAW CREDS
Sandbox isolated FS Proxy keys at request Redact before the LLM Audit every write

Sandboxed execution

Each investigation gets an isolated container and a fresh filesystem. The agent can write scripts and reports. It cannot reach your cluster except through the proxy.

Credential injection via proxy

API keys are injected at request time. The agent never sees raw credentials — it just makes authenticated requests.

PII redaction

Sensitive data is automatically detected and redacted before being sent to the LLM. We do not use your data to train models for other customers.

Deployment options

Recommended

SaaS (Hosted)

We host everything. Connect Slack and observability tools. Complete setup in 30 minutes.

Regulated industries

On-Prem / VPC

Deploy in your own infrastructure. Your data stays in your network. We provide support and updates.

Hackers & tinkerers

Self-Host (OSS)

Open core. Run it yourself with complete control. Community support on GitHub and Slack.

SOC 2 in progress Currently undergoing Type 2 audit. Data encrypted at rest and in transit. We do not claim the audit is complete.
RBAC Fine-grained access control for teams, tools, and data sources.
Full audit trail Every AI action, query, and decision is logged for compliance.
Human-in-the-loop All write actions require approval. You stay in control.