Ask
"Which accounts failed to sign in from outside the country this week?" "What does this GPO actually do?" "Is anything exposed to the internet that shouldn't be?" One question, and it queries every relevant system.
IT Sentinel
IT Sentinel is an AI assistant that runs on your own server, reads your SIEM, endpoint protection, firewall, Active Directory, Microsoft 365 and ticketing, and answers in plain language, with the evidence.
The problem
Small IT teams run the same tools as large ones (a SIEM, EDR, firewall, directory, cloud, backup, ticketing) without the people to watch them. Each tool has its own console and its own language. The answer to "did anything bad happen last night?" is spread across six of them, and the question nobody asked is the one that matters.
What it does
"Which accounts failed to sign in from outside the country this week?" "What does this GPO actually do?" "Is anything exposed to the internet that shouldn't be?" One question, and it queries every relevant system.
Alerts arrive in Microsoft Teams already investigated: who, what, where, and what to check next. A daily briefing and a findings list, each with a one-click ticket and an Investigate button.
Findings include directory risks nobody checks by hand: accounts that can copy every password hash, Kerberoastable service accounts, unconstrained delegation, an old krbtgt password.
One button produces a fresh report: unused Group Policy, risky firewall rules, audit-policy problems, stale devices, idle mailboxes, unused licenses, guests who never accepted, expired app secrets.
After you change something, ask "did my fix work?" and it re-runs that check live, then tells you what's fixed, what's still there and what's new.
How it works
Private and verifiable
Fully on-premises: the model, the data, the logs and every answer stay in-house, on your network. No prompts or results are sent to an AI service, or to us.
Its tools only read your systems. The one thing it writes is a help-desk ticket, when you ask for one.
It recommends, drafts tickets and writes the exact commands; it doesn't run them.
Addresses, rule and policy numbers, CVEs, compliance control IDs, host names, identifiers and dates must come from the data, or the answer is corrected or marked "not confirmed".
Sign-in uses your own accounts, limited to a group you choose; roles can give managers and help desk staff different tools and data.
A watchdog checks the SIEM, the language model and its GPU, and posts to Teams when one of them stops, so a quiet assistant is never mistaken for a quiet network.
What it connects to
Not on the list? Integrations are modular; tell us what you run.
Questions it answers
Things it found that nobody was looking for
A server group had stopped sending a whole category of Windows logs for weeks; every dashboard looked fine because no alert fires on silence. The daily "questions worth asking" now flags data that should arrive but doesn't.
Two kinds of audit policy were overriding each other, turning sign-in auditing off and on every few minutes. It surfaced as a flood of one event, which the review now checks for.
The cloud usage reports were anonymised by a tenant setting, which would have turned one departed user's files into dozens. The review refuses to guess and names the setting to change.
The scheduled directory audit found an account with the right to copy every password hash in the domain. Investigate explained the risk and the fix; after the admin removed it, "did it work?" re-ran the check live and confirmed it.
The threat-intelligence feed flagged firewall sessions to a known command-and-control server from the guest Wi-Fi, whose shared address moved between access points as if it were three machines. Lining the hit times up with the connected clients pointed to one phone; it was blocked, and the feed has shown no attempts since.
What you get
FAQ
No. IT Sentinel is fully on-premises: everything it collects, stores and writes stays on your server. Nothing goes to an AI service, and nothing comes to us. Integrations that are themselves cloud services (Microsoft 365, a cloud EDR) are read through their APIs into your server, as your admins already do.
An open-weight model that runs locally; the exact model depends on your hardware.
A server or workstation with a recent NVIDIA GPU (16 GB of VRAM is a good start). Exact sizing depends on your environment.
No. It's read-only. It drafts tickets and exact steps for a person.
It depends on how many systems you connect. First answers usually come within days, tuning over the first weeks.
No, it works next to it. It can forward the logs your SOC needs in real time, and it answers the questions a SOC doesn't: what's in your directory, your Microsoft 365 tenant and your Group Policy.
Both: the software plus the work of connecting and tuning it.
Contact
Which tools you run, how big the team is, what you'd ask it first. We read every message and reply within two working days. No newsletter, no sales sequence.
We'll reply within two working days.