IT-AI is self-hosted, AI-powered remote IT support for your own fleet — an AI that diagnoses the problem and fixes it, once you approve. Run one hub, drop a lightweight agent on each Windows, macOS or Linux machine, and from a single dashboard — or straight from your AI — you get live screen and remote control, an interactive shell, secure file transfer, and live device health. The assistant inspects read-only, explains what's wrong in plain language, and proposes a curated fix. Nothing runs until you click Apply. Your hub, your machines — screen, shell, files and telemetry never leave your infrastructure.
Stand it up in minutes, enroll each machine with a personal token, and the AI becomes a first responder that proposes — never imposes. Every change waits for your Apply.
it-ai <hub> --relay-token htok_… on the machine. The device dials out over an HTTPS relay — no inbound ports, no NAT holes.Live control, a real shell, secure file transfer and device health — the RMM basics done properly — plus an AI that diagnoses and proposes approval-gated fixes, all driveable from your own AI over MCP. Self-hosted, open source, nothing routed through a vendor cloud.
The same self-hosted engine, scoped to whoever's running it. In every case the hub is yours — screens, shells, files and telemetry stay on your infrastructure, and every fix waits for a human to approve it.
No. IT-AI is read-only by default. The assistant inspects a machine, explains the problem, and proposes a curated fix — but every change waits for a human to click Apply. Nothing runs on its own, and every applied action is audited.
Nowhere you don't own. The hub is yours, so screen, shell, files and telemetry stay on your infrastructure. The AI's API key lives on your hub — the endpoints never see it — and there is no vendor cloud in the path.
Windows, macOS and Linux, on both x86-64 and arm64. The agent is a single lightweight binary per device.
No. Each device dials out to your hub over an HTTPS relay, so there are no inbound ports and no NAT holes to punch. You can reach machines well beyond the LAN without exposing them.
Yes — the agent, MCP server and CLI are open source under AGPL-3.0, signed and attested. You self-host the hub. The code is on GitHub.
Three things. It's self-hosted, so nothing routes through a vendor cloud. It has a built-in AI that diagnoses problems and proposes approval-gated fixes, with a human in the loop on every change. And it's MCP-native, so your own AI can drive the whole fleet — list devices, screenshot, run commands, push files, ask the assistant.
Self-hosted, AI-powered remote IT support — your hub, your machines, a human in the loop.