Able is one system that runs on a computer you already own: the Able Agent works alongside your IT person, and Able Experts are there for it to call on without leaving the session. It gives you a grounded second opinion before you act, and a clear record of what was done and why. We can't be on hand for every call - Able can. It runs offline, inside your own building, so it keeps working even when the network is isolated and cloud tools go dark.
The hardest moments aren't always the dramatic ones. They're the high-consequence calls made under time pressure, on your own, that get examined closely afterwards - a breach, yes, but also a lockout at the worst possible time, an outage, a change that didn't go to plan. The instinct is usually sound; what's missing is a way to sanity-check it in the moment, and a way to show afterwards that you acted correctly.
That's the real gap. It isn't a lack of willingness, or even a lack of outside help - your cloud, application and comms providers will often get involved and can do a great deal. What stalls things is structure: without a methodical way to analyse what happened, work out the diagnosis and document it, the response is improvised, those providers can't be given what they need to help, and the cost quietly climbs long after the event itself.
Able fills that gap. It gives you a structured way to work: a grounded second opinion that validates or rules out a course of action before you commit to it, diagnostics run against your actual systems, and a clear, source-cited record of what was decided and why. You can hand your providers exactly the information they need, and when the questions turn to IT afterwards - as they always do - you have a documented, auditable account rather than a best recollection. It's the difference between a reasonable decision that's defensible and one you simply have to hope is taken on trust.
The heart of it is the Able Agent - a response agent that works the incident alongside your IT person. It looks at what's actually happening on your systems and suggests the next step, one at a time, over the connections your machines already have. It installs nothing, leaves nothing behind, and nothing runs until a person approves it.
What makes it more than a clever terminal is that the Agent can call on Able Experts the moment a question moves into their territory. Load the STIG expert, the GDPR expert, the incident-response playbook, and the agent will consult the right one itself, in the same conversation, the way it decides to run a command. You can take what's live on the screen right now and have an expert weigh in on your actual system, not the theory. Answers come back with their source attached, so your team can check them.
Each side stands on its own - use it purely as a gated response agent, or simply consult the experts - but the point is that they're one loop, started once. It all runs on your own hardware: nothing goes to the cloud, nothing leaves your network, and it keeps working even when you've taken the network offline.
Core Capabilities
This is the part that matters: the response agent and the expert advisors are the same tool, started from one prompt, running in one session. The agent doesn't hand off to a separate app - it calls on an expert itself, mid-task, the way it decides to run a command, and carries the answer straight back into what it suggests next. With a click you can feed live terminal output into an expert, so it judges the machine in front of you rather than the theory. That live link is built in, not a bridge between two standalone tools.
An AI agent that sits alongside your IT person and works the incident with them. It reads what is actually happening on your systems and proposes the next action - one step at a time - over the connections your machines already have (SSH and Windows remoting), installing nothing and leaving nothing behind. Because it runs locally, isolating the network to contain a breach doesn't stop it working.
The safety lives in the code itself, not in an instruction the AI is politely asked to follow. It refuses any command it isn't certain about. It backs things up before they change. It won't leave your operator stranded, and it never records passwords or anything else typed in. When it can't be sure a command is safe, it stops and asks rather than guessing.
Under the bonnet: the command guard splits compound commands and checks every part, inspects nested bash -c/su -c payloads, normalises newlines so nothing can hide across lines, and fails closed on anything it can't parse. Roughly 300 automated tests, including real-terminal checks, hold those guarantees in place.
Ordinary AI asks you to take its word for things. An Able Expert shows you where every answer came from, and checks it against that source before you ever see it, so your team can confirm it for themselves. If it can't back something up with the source, it tells you.
Under the bonnet: every citation is verified against what was actually retrieved, down to numbered sub-steps, and exact identifiers (requirement numbers, CVE IDs) are matched exactly rather than by rough similarity.
It comes with a ready set of experts - Incident Response, MITRE ATT&CK, Ubuntu STIG, PCI DSS, UK GDPR, Cyber Essentials and the NCSC CAF. But the real product is the expert built for you: we can take the same approach as far into a niche or legacy system as your business needs. If it can be written down, we can build an expert for it. Ask it in plain English - and every answer shows its source.
Able runs across a broad range of hardware - from a small dedicated box to a rack server with a GPU - and makes use of the compute you already have rather than demanding a particular setup. The more capable the machine, the larger the models it can run and the more it can do. Prefer not to run it yourself? We can spec, configure and supply a dedicated box as part of the service. Either way it stays on your hardware, under your control.
Under the surface, both tools are driven by an AI model running on a small server inside your network. We don't just reach for whichever model is fashionable - we test candidates against the actual work, measure how each one performs, and pick the one that gives the best, most reliable results for your use. The model is matched to the task, so you get a system tuned for what you actually do rather than a one-size-fits-all.
We measure whether it actually finds the right answer - using questions phrased the way a stressed person really asks them, and a held-out set that asks the same things in different words to prove it isn't memorising. And we're honest about the edges: a person approves every action, and on the rare, unusual case it tells you to bring in a human rather than guess.
Technically minded? The technical detail further down sets out exactly how the safety, grounding and offline operation are enforced.
Architecture
Local Incident Response Flow
SSH · WinRM · nothing installed
AGENTLESSEvents · alerts · artefacts
ON-PREMISESPlain language · no query syntax
HUMAN IN CHARGERuns on your own hardware
No API calls · no telemetry
Right expert loaded one at a time
Room kept for the answer
Frameworks · playbooks · internal procedures
Plain-language questions in
Verified against what was actually retrieved
IDs checked literally, not by similarity
Real PTY · existing SSH / WinRM
Nothing installed, nothing left behind
What happened, what to do next, and where every answer came from
AUDITABLEOn-premises · Air-gapped · No cloud egress · Built to defer: if it's unusual, it says escalate
Bespoke Deployment
The seven experts it comes with are there to show what the approach can do. The real value is the expert built for you. Using the same process, we take your own procedures, the way your company works, and the know-how specific to your trade, and turn them into an expert that belongs to your business rather than a generic tool pointed at your network.
It goes as specialist as you need. If it can be written down, it can become an expert - and new experts are simply added, with no change to the system you're already running.
Your internal procedures, playbooks, the regulations you work under and the standards you're audited against become the expert - asked about in plain English, answered with the source attached and checked against it before anyone acts on it. However specialist or old the system, if it can be written down it can have its own expert.
Each expert is built for you - scoped to your material, checked, and added to the system you're already running. Need several? The process is the same every time: a repeatable service tailored to each job, not a fresh project built from scratch each time.
Each expert is a small, self-contained file - only a few megabytes - and is called on one at a time, so nothing competes for the system's attention. You can build up as large a library of experts as your own storage will hold, and whichever one you ask gets the system's full focus.
Deployment Options
Why It Fits Your Business
A grounded second opinion for the high-pressure decisions, a reliable adviser for the everyday things you have to get right, and a documented account you can stand behind afterwards. It runs on your own hardware, keeps working when everything else is down, and always keeps a person in charge - so the expertise and the evidence stay yours, wherever the questions come from later.
Everything runs on your own hardware. Nothing goes to the cloud, nothing is handed to a big US tech firm - not during an incident, not ever. Exactly what your insurer, your auditor and your customers want to hear.
From a small box to a server with a GPU, Able uses the compute you have rather than requiring a specific setup - and scales as you add more. Or we supply a dedicated box as part of the service. Everything stays on your hardware, offline, under your control.
Every answer traces back to its source, and every session is saved as an After Action Report - a clear record of what happened, what was approved and what each step returned. When a regulator, insurer or auditor asks, you can show your working rather than take a machine's word for it.
Most incidents are versions of the same handful of problems, and that's exactly what this is built to be sharp on - drawn from real-world incidents, not just the textbook. On the rare, unusual case it's honest enough to tell you to bring in a human.
Under the Bonnet
Everything above is written to be read without a security background. This part isn't - it's for IT leads, MSP engineers and auditors who want to see how the safety, the grounding and the offline operation are actually enforced before trusting them. We describe what the system does and how it behaves, not the internal methods that build the experts.
Every proposed action is shown in full and held until a person approves, edits or refuses it - one step at a time. A stray keypress can't approve or skip a step; anything unrecognised re-asks. No setting or mode bypasses it.
Before anything reaches the gate, each command is analysed. The guard:
bash -c and su -c rather than treating them as opaque.$(…), backticks) isn't recursed into, and writes made inside a running program are invisible to the string guard by design. The threat model is accidental model mistakes, not a determined adversary - and the human gate shows every command before it runs regardless.Two kinds of injection are worth separating. The first is a crafted input trying to make the agent run something it shouldn't. The second is hostile content - a log line or a file on a compromised machine - crafted to manipulate the model into suggesting something it shouldn't.
Able's answer to both is the same, and it's deliberately not "our parser catches everything", because complete command parsing is a losing game. Instead: no command runs until a person has seen the exact command and approved it. Neither a crafted input nor a poisoned file can cause an action on your systems on its own - the worst either can do is put a proposal in front of a human, who reads it and declines. The command guard reduces what reaches that point and fails closed on anything it can't parse; the human gate is what actually prevents execution.
Anything that would change a file visible in the command - redirects, tee, sed -i, dd and the like, including inside nested payloads - is backed up first with a timestamped copy. If a backup can't be made, even with elevated rights, the command is refused rather than run with a warning.
The Agent won't leave the operator stranded in an interactive session it can't drive. Commands run over a real terminal, so password and sign-in prompts behave normally. On-screen output is captured; typed input and credentials are never recorded.
Each session is recorded as an AAR - an After Action Report of what was asked, what was proposed, what the operator approved, and what each command returned (with credentials redacted). Because every answer carried its source and every action passed a human gate, the AAR is a clean, defensible account of the incident - the kind an insurer, auditor or regulator asks for afterwards.
Target machines are reached over the connections they already have - SSH and Windows remoting - with nothing installed on them and nothing left behind. No resident agent means no new attack surface and no leftovers to clean up.
Consulting an expert isn't a separate app or a copy-paste between windows. An expert is loaded into the live session, and from then on the agent can query it as one of its own actions - the same gated loop it uses to run a command - then fold the grounded, source-checked answer into what it proposes next. Live command output from the box can be passed into an expert on demand, so it assesses your actual system state against the framework rather than answering in the abstract.
Roughly 300 automated tests lock these behaviours in place, including real-terminal integration tests that prove the teardown, the input routing and the "typed input is never logged" guarantee against the actual modules - not mocks.
Every citation is checked against the material actually retrieved and marked accordingly - verified, or flagged where it can't be confirmed - down to individual numbered sub-steps. A claim that cites something that wasn't retrieved is caught, not shown as fact.
Where the source uses precise identifiers - requirement numbers, control references, CVE IDs - these are matched exactly, not by rough similarity. That's the difference between pointing you at the right clause and pointing you at a plausible neighbour.
Before each answer the system measures how much it can fit and reserves room for the reply. If everything won't fit, it drops the least-relevant material first and tells you what it dropped - there's no silent truncation that quietly removes the part that mattered.
Each expert is a small, self-contained profile, consulted one at a time on purpose: a focused expert the model can fully attend to beats several competing for its attention. Experts are added as data - nothing is retrained - so the engine, model and deployment stay exactly as they are as the library grows.
If the source doesn't support an answer, the system says so rather than inventing one. Ask it about compatibility, a product, or a compliance point and it reports what the material actually states, with the source attached. What it won't do is reason its way to a confident answer the data doesn't contain.
Each knowledge store records how it was built, and refuses to answer in a way that would return silently-wrong results. If there's a mismatch it raises an error rather than quietly degrading. We'd rather it fail loudly than mislead you.
The language model, the embedding model and the knowledge stores all ship inside the deployment. At run time the system makes no calls off the machine - no cloud APIs, no telemetry, no model downloads. A missing local resource fails loudly rather than silently reaching out.
The build gate runs the full evaluation with the network physically disconnected and confirms the results are identical to the connected baseline. In plain terms: disconnect it and watch it keep working - which is exactly the test to run before trusting the claim.
Able runs across a wide range of hardware - a small box with modest compute will run a focused expert at usable speed, while a server with a capable GPU runs larger models at longer context. Performance scales with the hardware: the more you give it, the more it can do. The model and configuration are matched to the machine and the task, so a given box is used well rather than left waiting on raw compute it doesn't need. Everything stays on-premises, with no change to the deployment when you upgrade.
Both tools talk to an AI model served locally through a standard model server inside your network - no external API, no model downloads at run time. The model itself isn't a default we settle for. We trial candidate models against the real task, score them on how accurately and reliably they perform, and curate the choice from those results, matching the model to the job and the hardware rather than assuming bigger is better.
Each expert is scored on whether it surfaces the right material - using questions phrased the way a stressed user actually asks them, plus a held-out set that asks the same underlying questions in different words to confirm it generalises rather than memorises. Hit-rate and rank are tracked over time, and a full-library evaluation is the regression gate after any change.
Some experts are built from official machine-readable sources; others are assembled from authoritative material and spot-checked against the source. Each records which it is. Where an expert is a thorough, source-checked summary, it points you to the source to confirm - a fast route to the right place, not a substitute for the regulation or professional judgement.
Two boundaries we state plainly rather than paper over. First, the evaluation measures whether the right material is retrieved and whether every claim is grounded - it doesn't yet measure end-to-end answer correctness graded by a practitioner on unseen incidents. That's the next step, and it's the honest line between strong retrieval and trusted-in-a-live-incident.
Second, the system is built to be deep on the common cases - most incidents are variations on the same core - and to defer on the rare, unusual ones. On anything outside the familiar pattern it's built to say "this is unusual, bring in a human" rather than improvise. Knowing when not to rely on it is part of the design.