# Witina AI — Overview > Witina AI is a multi-vendor network management platform: it discovers your network, > monitors it, and lets you change device configuration safely. Device credentials are > never stored in Witina's cloud — they live encrypted on a gateway inside your own > network. It can also be run entirely on your own hardware, with a few cloud-only > features left out. Source: https://witinaai.com/ai/overview.md Part of the Witina AI machine-readable corpus — index: https://witinaai.com/llms.txt Last updated: 2026-09-09 ## What it is Witina AI is a network management platform for organizations that run network gear from more than one vendor — switches, routers, access points and firewalls from Cisco, Juniper, Arista, UniFi, Netgear, EdgeRouter and others. It does three things: 1. **Discovers** every device and link on your network, and keeps a live topology map. 2. **Monitors** those devices, rolling metrics and state changes into incidents that are tied to the devices they affect. 3. **Changes** device configuration through a reviewed, approved, snapshotted and reversible process rather than ad-hoc edits. It is sold as a managed cloud service and also published as a free self-hosted edition that runs entirely on your own hardware. ## Who it is for - **In-house network teams** running one site or many, especially where the gear is mixed-vendor and no single vendor's cloud dashboard can cover it. - **Managed service providers (MSPs)** carrying many client networks who need one console across all of them, with each client's data and credentials isolated. See https://witinaai.com/ai/msp.md - **Homelab users and evaluators**, via a free tier and a single-container self-hosted trial. ## The one architectural idea Witina is two pieces: - **A gateway** runs inside your network and does all the privileged local work: discovery, polling, holding credentials, applying configuration changes. - **The cloud is the brain**: topology, alerting, change management, reporting, and the console you actually look at. The gateway only ever dials **out**. You open no inbound ports and expose no management plane to the internet. Device credentials are relayed to the gateway and stored encrypted there. Witina does not store device passwords in its cloud. This is why the security story is not a policy promise but a structural one: there is nothing in Witina's cloud to leak, subpoena or breach, because the secrets were never sent there. See https://witinaai.com/ai/architecture.md and https://witinaai.com/ai/security.md ## What makes it different - **Credentials never reach the vendor's cloud.** Most comparable tools collect device passwords into their own vault and ask you to trust it. Witina has no such vault. - **You can run it yourself.** The self-hosted edition handles credentials exactly as the cloud does, so the credential claims are verifiable by running it and watching the traffic. - **Discovery is passive-first.** Onboarding listens to what devices already broadcast (DHCP, LLDP/CDP, mDNS) rather than scanning, so it doesn't set off your own IDS. Active probing is opt-in, per network. - **Alerting is deterministic, not generative.** For the faults it knows — an unexpected spanning-tree root, a duplex mismatch, a guard violation — an expert system names the problem and the fix using named rules you can read. Witina deliberately does not use an LLM to guess at diagnoses. It is a focused set of checks today, growing over time. - **Your AI connects to it, rather than it shipping you an AI.** Witina runs an MCP server, so Claude, ChatGPT or an agent you wrote can read your real network state and draft changes — under permissions capped to the person who authorized it, and without the ability to execute. See https://witinaai.com/ai/mcp.md ## Company status Witina AI LLC is a Washington limited liability company. It is an early, pre-audit company: there is no third-party security certification yet, and the marketing site says so plainly rather than implying otherwise. What exists instead is an architecture that keeps secrets on the customer's side by construction, and a self-hostable copy that can be inspected end to end. ## Where to go next | Question | File | |---|---| | What features does it have? | https://witinaai.com/ai/capabilities.md | | How is it built? | https://witinaai.com/ai/architecture.md | | Is it secure? | https://witinaai.com/ai/security.md | | Can my AI use it? | https://witinaai.com/ai/mcp.md | | Does it support my gear? | https://witinaai.com/ai/vendors.md | | What does it cost? | https://witinaai.com/ai/pricing.md | | How do I deploy it? | https://witinaai.com/ai/deployment.md | | I run an MSP | https://witinaai.com/ai/msp.md | | Common questions | https://witinaai.com/ai/faq.md | | How does it compare with Auvik, PRTG or Domotz? | https://witinaai.com/ai/compare-auvik.md, https://witinaai.com/ai/compare-prtg.md, https://witinaai.com/ai/compare-domotz.md | Contact: hello@witinaai.com · Demo: https://witinaai.com/contact