AI intelligence layer for MSPs

Stop onboarding surprises. Start proactive MSP intelligence.

Wegweiser reads your client's logs like a senior engineer, surfacing hidden risks before they become tickets - the AI layer that deepens any RMM stack. When it finds something, act on the spot: a live terminal and remote control - Windows and Linux - are built in.

1,000 Wegcoins free - 100+ AI analyses Connects to any RMM Setup in minutes
Supported:Windows·Linux·macOS
app.wegweiser.tech
Wegweiser command centre - tenant health gauge and the morning's highest-impact findings
Agnostic

RMM-agnostic agent

Our lightweight agent deploys through ANY RMM platform - Windows workstations, servers, Linux, macOS and networked devices - for comprehensive insight across the estate.

Scoring

Hierarchical health scoring

Every device gets an AI-calculated health score with prioritised recommendations. Scores cascade up through groups and organisations for complete visibility.

Depth

Beyond traditional RMM

Surface critical patterns over the last 30 days that automation misses. Deep log analysis and pattern recognition that supplement your team's expertise.

Why we built this

Solving critical MSP bottlenecks

Two bottlenecks sit in every MSP's lifecycle: Client Onboarding Hell - where larger customers hide critical issues beneath the surface - and the Knowledge Gap - where nobody can know everything about every hardware type or event log. We use AI to supplement your team's expertise.

"I built the AI layer I always wished existed - one that reads logs the way an experienced engineer would, not just counts them."

- Andrei, Founder & MSP

25+ analyzers, across the stack

Security eventsUnauthorised access, privilege escalations
System eventsHardware issues, drivers, boot performance
Application crashesStability patterns, problematic apps
Driver analysisOutdated, unsigned or problematic drivers
Journal & system logsLinux systemd journals for service issues
Network analysisConnectivity, topology, traffic anomalies
Kernel & storageOS events, disk health, I/O bottlenecks
Security auditingLynis hardening + YARA malware scanning
Software inventoryInstalled programs, versions, exposure
Binary provenanceUnrecognised executables flagged against the NIST NSRL hash set
macOS intelligenceGatekeeper, SIP, FileVault, app inventory
Patch posturePending updates, EOL OS, broken update stacks - Windows, Linux, macOS
Event forecast30-day statistical prediction, zero AI cost

Inside the product

Scroll · open any screen to page through all 19

Capabilities

What Wegweiser does

Onboarding

Onboarding Assessment

The day-one report that fuses the estate's analysers into the hidden issues a new client never mentioned - compounding device risk, fleet-wide analyser failures, exposed-and-unhealthy machines - with a rolling weekly diff and compliance posture. Deterministic scoring, no LLM on the hot path.

Provenance

Unrecognised-binary detection

Executables from every install location and user profile on Windows, and the standard binary paths on Linux and macOS, hashed and checked against the NIST National Software Reference Library. The custom, in-house and novel binaries that match nothing known lead each weekly scan - the ones in user-writable paths first. A throttled agent scan; read-only intelligence, never a verdict.

Triage

Discuss-and-Override

Findings you can argue with. When a finding is benign - your own admin tool, a dev box's open ports - accept it in two clicks, one scanner detection at a time or the whole analysis, or just tell the AI in chat. The score recomputes honestly, every override is audited, a whole-analysis accept is one click to undo, and new findings still alert.

Investigation

Root-cause investigation

A finding tells you what is wrong; an investigation works out why. A tool-using AI agent walks event timelines, baselines and live osquery, then reports probable cause, evidence and the next action - one click, or automatically on fresh critical findings up to a daily cap per client.

Patching

Patch posture, every OS

Windows, Linux and macOS - pending and security updates, end-of-life operating systems, and whether the update machinery itself works. A box that can't patch is the finding, not a footnote. Read-only intel; your RMM still does the patching.

Remote control

Remote control, Windows and Linux

Full desktop control from the browser - no VPN, no inbound firewall rules at the client, no second product. Linux desktops are captured through the compositor itself, so there is no consent dialog to click on a machine nobody is sitting at. Change-driven capture stays light on the endpoint, switching between monitors is one click, and every session lands in the audit log under an always-on-top banner the user cannot close.

Terminal

Live terminal, every OS

A real PowerShell or bash session in the browser, running as SYSTEM or root on any online device running the agent - operators only. Credentials are scoped to a single session and expire on their own after 30 minutes, and every session open is audited. Investigate a finding and fix it in the same minute.

Live diagnostics

Ask a machine how it feels

Answers with charts, not essays. Ask how the CPU has behaved and the stored samples are drawn rather than described. Ask what is happening right now and the agent watches the box for ten seconds, charts CPU, memory, network or disk - throughput, IOPS and queue depth - and names the processes responsible. Ask what the link is actually doing and it measures download, upload and latency from the endpoint itself. Every one of them reads. None of them write.

AI Assistant

Live AI chat & monitoring

Ask about any device, group or organisation and get streaming AI answers over that level's full analysis history. In a device chat it can also accept findings as expected risk and recompute the health score on request. Open the live monitor and CPU, memory, disk and network stream from the agent about every two seconds; the rest of the time a lighter baseline rides the heartbeat.

Forecasting

Event forecast

Predict which Windows events fire in the next 24 hours and 7 days - pure statistical analysis of 30-day archives, zero AI cost, with confidence from scheduled to sporadic.

Deception

Honey accounts

The one finding that is not an inference. Create an account whose only purpose is never to be used - disabled, or holding a long random password - and tell Wegweiser its name. Nothing legitimate ever authenticates as it, so a logon event naming it is not a probability score, it is somebody working through credentials they should not have. The agent matches on the endpoint against the Windows security log it already reads, so nothing about your directory leaves the machine and Wegweiser has no write path into it - it never creates the account. Windows event logs are collected once every 24 hours, so a trip surfaces within a day rather than within minutes; we would rather say that than imply a speed we do not have.

Security

Autonomous AI threat detection

Every 24 hours the AI turns CISA KEV, NVD and GitHub advisories into YARA rules, validates them by compiling with YARA-X, and files them in your threat-intel pack - promote one and the next pack build carries it into the fleet sweep. Rules that fire too often are auto-demoted, so noise cannot drown the real findings.

Shadow AI

Shadow AI discovery

Find the AI tools nobody approved. Claude Code, Gemini CLI, GitHub Copilot CLI and Ollama on Windows, Linux and macOS; Claude Desktop, ChatGPT Desktop and LM Studio on Windows; Antigravity on Linux. Matched on what the tool is rather than where it sits, so it's caught wherever the scan reaches - including from a stray config file. Every hit tags the device and evidences your CIS and ISO 27001 unauthorised-software controls.

Threat intel

Community & government feeds

Your scan packs aren't only ours. YARA-Forge - which aggregates 45+ vetted public rule repositories - is pulled weekly and built straight into your packs, while CISA's Known Exploited Vulnerabilities list, NVD and GitHub advisories drive rule generation. Coverage follows what attackers are using, not what merely scored high.

Retrospective

Retrohunt

Detection that reaches backwards. When a sample is newly published as malicious, its hash is matched against the binary inventory already collected across your fleet - so a file that was unknown the day it landed is still found the day it becomes known. Hits land in the threat-hunting view like any other detection.

Data quality

It checks its own readings

A finding that fires wrongly gets noticed. A check that has quietly stopped measuring and still writes a plausible score does not, and it is the more dangerous of the two. Wegweiser audits its own numbers: a score computed from a sample of nothing, a payload stored in a shape the rest of the fleet does not use, a score that has not moved for several runs while the data underneath it has. The first pass over our own estate found eight machines carrying hardening scores between 58 and 66 whose own reports said zero tests had been performed. These never count against a device's health - a broken instrument is not a sick patient, and conflating the two is the mistake that makes the whole number worthless.

Detection triage

Explain it, then dismiss it once

Ask the AI why a rule fired and get the matched file, the rule's provenance and a plain-English read. If it's a false positive, mute it once and it applies to every device that matched in the window you're viewing - and once enough endpoints reject the rule, it's dropped from the packs entirely.

Availability

Client uptime monitoring

Watch the services a client actually notices - web, mail, VPN endpoints - with per-organisation monitors and keyword checks. Outages are re-probed independently before anyone is paged, then alert down the same Slack, Teams and webhook channels as everything else, with a recovery notice when it clears.

Access

Passkey sign-in

Phishing-resistant login with WebAuthn passkeys - Touch ID, Windows Hello or a hardware key - alongside TOTP two-factor and single-use backup codes.

Reporting

Report Centre

Generate a device, organisation or tenant PDF on demand, and have the organisation or tenant report e-mail itself weekly or monthly. Plus a plain-English client QBR, a device-inventory CSV per organisation, and a searchable archive of every PDF you produce.

Analytics

Intelligence hub

A dedicated AI command centre: health KPIs, AI-generated strategic recommendations, health trends at tenant, organisation, group and device level, and chat across the whole tenant.

Alerts

Slack / Teams / webhook alerts

Critical findings land in your workflow - Teams, Slack, e-mail, or a ticket-shaped webhook your PSA ingests. Sign generic-webhook deliveries with an HMAC secret, and test any channel in one click.

Integrations

Your helpdesk and your RMM

Zammad reads its own organisation list into Wegweiser so nobody retypes a hundred and fifty client names, then files findings back as tickets - a used honey account, a drive reporting its own failure, a malware detection the analyser agreed was real, a device falling through a health threshold. One open ticket per device per condition rather than one per event, updates appended to it only when there is something new to say, and once your people close a ticket Wegweiser never touches it again. Off for every organisation until you switch it on, with a dry run that shows what a real run would file. Kaseya VSA 10 gets the health score, status and a link back written onto each matched device.

Client comms

Share-with-client links

Hand a client a tokenised read-only health view - no login, no chat, no internal IDs - revocable any time.

Compliance

Seven frameworks, and you pick which

Findings carry the controls they materially evidence: CIS v8.1, ISO/IEC 27001:2022 Annex A, NCSC Cyber Essentials, NIST SP 800-53 Rev. 5, and - for German clients - the BSI IT-Grundschutz-Kompendium, NIS2 as § 30 Abs. 2 BSIG, and DIN SPEC 27076, the BSI CyberRisikoCheck. A German house is not shown British Cyber Essentials just because it exists; each tenant chooses its own set, seeded by the language its analyses are written in. A hand-maintained, deliberately conservative mapping, not AI guesswork - and a test fails the build if any check is neither mapped nor explicitly recorded as evidencing nothing. Orientation for an audit, not a certificate.

SOVEREIGNTYPrivacy tier

Bring your own LLM

Point the analysis pipeline and chat at your own Ollama instance - no client data goes to OpenAI, Anthropic or Azure, and chat retrieval runs on local CPU embeddings. Built for public sector, healthcare and legal. Same UI, your models.

In motion

What using it looks like

Three things an engineer does to one machine, recorded from the live product against real findings. No narration, no cuts, nothing staged.

Read what the checks found 18s · loops · click to pause

Fit

Who should try Wegweiser?

MSPs struggling with onboarding

The larger the customer, the harder it is to find the machines with critical issues lurking beneath the surface.

Teams wanting AI-assisted insight

Nobody can know everything about every hardware type or event log. Let AI supplement your team's expertise.

Forward-thinking MSPs

Anyone curious about the future of intelligent RMM supplements and centrally managed AI intelligence.

Pricing

Per endpoint, per month

Bring your own key
£2 /endpoint/mo
Your own AI provider key

You hold the API key and pay your AI provider directly; your data goes to the provider you chose. This covers the platform itself: collection, history, the scanner, remote access and reporting.

The usual choice Standard
£4 /endpoint/mo
60 Wegcoins included per endpoint

A full monthly AI analysis pass for every endpoint, plus headroom for chat and on-demand re-checks. Overage packs exist for the months an onboarding or an incident makes you dig.

Continuous
£12 /endpoint/mo
400 Wegcoins included per endpoint

Roughly weekly analysis per endpoint, for estates that genuinely move - heavy churn, strict scrutiny, or clients you are actively troubleshooting.

Prices exclude VAT. UK customers are charged VAT at the prevailing rate; EU businesses supplying a valid VAT number are zero-rated under the reverse charge. Every account starts free with 1,000 Wegcoins and no card - prove it on a real client before any plan. Billing counts only endpoints that actually checked in during the month, never a licence count.

Ready to transform your MSP operations?

Start uncovering what's really happening inside your clients' systems - in minutes, not days. Register and receive 1,000 Wegcoins - enough to run deep AI analyses across many devices. No card required.

Start free - no card required
1,000 Wegcoins free No credit card Setup in minutes

Talk to us

Contact

Questions, demos or partnership chats - we typically reply within one business day.

Address

Old Forge, Newmarket Road, United Kingdom, CB8 7PP

Phone

+44 1223 297 870

Email

info@wegweiser.tech