Phoenix / Products / Core
Sovereign AI security platform · API + MCP

Phoenix Core

Bring your own model. Keep your own data. Build your own agents.

Can we run our own? Core is the platform that makes the answer yes — the sovereign AI control plane underneath Phoenix. An OpenAI-compatible API and Model Context Protocol server that turns your security estate into a set of tools a local model can reason over, with identity, authorization, and audit built in from the start.

external model endpoints required0
15
specialized security agents
50+
real security tools
2
interfaces — API + MCP
0
bytes leave the building
What it is

OpenAI-compatible on the outside. Fully on-premises on the inside.

An OpenAI-compatible API

Standard /v1/chat/completions and /v1/models endpoints. Every client that speaks the OpenAI protocol works against your local models, unchanged.

A Model Context Protocol server

Direct tool access for MCP-compatible clients — query the estate from a phone, with customer telemetry staying on your network.

Multi-provider by design

Ollama runs locally today; the architecture is built to add vLLM, llama.cpp and LM Studio (also local) and hosted options like AWS Bedrock. Local is the default — a hosted provider is an explicit operator choice.

Security-native

Real-time integration with Wazuh and OpenSearch — not a generic chat wrapper bolted onto your logs.

15 specialized security agents

Each with a narrow job and the tools to do it.

AgentJob
Alert SelectorFilters and ranks alerts by relevance
CVE CleanerDeduplicates and contextualizes vulnerability data
Statistics SelectorAggregates and analyzes security metrics
DiagnosticComprehensive security-posture assessment
Threat HuntingSearches for indicators of compromise
Threat IntelligenceEnriches threats with external context
Anomaly DetectionIdentifies unusual system activity
RemediationRecommends corrective actions
Report GeneratorProduces security & compliance reports
InventoryMaintains an inventory of systems and software
ComplianceAssesses regulatory compliance status
Risk ScoringCalculates risk using CVSS and EPSS
CorrelationCorrelates related security events
Incident ResponseOrchestrates response procedures
Rule / DecoderAuthors and tests detection rules and decoders
50+ tools the model can call

Agents answer from what the tools return, not from memory — every answer rests on real tool calls against your estate.

Fleet & agents
  • List monitored agents · fleet-wide summaries
  • Find by IP · group · tag
Status & diagnostics
  • Fast cached security checks
  • Full multi-minute deep-dive analysis · system info
Vulnerabilities & CVEs
  • Per-agent CVEs · detailed lookups · fleet overview
  • Live OpenSearch queries · risky-package detection
Configuration & compliance
  • Security Configuration Assessment · failed CIS benchmarks
  • CIS-CAT data · compliance assessment
System inventory
  • Packages · processes · open ports · network
  • Hardware · OS · hotfixes
Alerts & events
  • Recent alerts · live queries · event correlation
  • Indicator analysis
Advanced analysis
  • Anomaly detection · IOC hunting · enrichment
  • MITRE ATT&CK data · risk scoring · remediation
Operational
  • Active-response status · data sync · manager status
  • Incident playbooks · rule/decoder authoring · reports
How teams use it

Point any compatible client at Core and ask real questions.

The model sees the tools, calls the right one, and answers from what the tool returned, not from memory — and the answer shows which tool calls it rests on.

# A security copilot over your own fleet — nothing leaves the building > "What's the security status of agent 039?" → model calls get_security_status(agent_id="039") → reads live Wazuh data → answers with real posture, CVEs and failed CIS checks
Identity, authorization & audit — built in

Sovereign doesn't just mean on-premises. It means every action is attributable.

Deployment-scoped identity

On a trusted network, users are matched to their monitoring agent by source IP — a fast default for on-prem rollouts, meant to sit behind your own IdP, not replace it. SSO is on the roadmap.

Group-based authorization

Users reach exactly the agents their group membership permits, across three access tiers. Localhost is treated as admin for local administration — scope it down in multi-user deployments.

Secure credential storage

Sensitive values kept in the system keyring, never in plaintext config.

Comprehensive audit logging

A queryable trail of who asked what, and what the tools returned. Plus scheduled daily/weekly/monthly reports and component health monitoring.

What's live today

Shipped, and what's on the roadmap — stated plainly.

CapabilityStatus
OpenAI-compatible API (/v1/chat/completions, /v1/models)Available
MCP server for MCP-compatible clientsAvailable
15 specialized agents · 50+ toolsAvailable
Local provider (Ollama) · streaming · tool callingAvailable
Wazuh + OpenSearch integrationAvailable
IP-based identity (deployment-scoped default)Available — pair with your IdP
vLLM · llama.cpp · LM Studio · AWS Bedrock providersOn the roadmap
SSO / stronger authenticationOn the roadmap
Where Core fits

The "build & operate" lens of the loop.

        Your models (Ollama · vLLM · llama.cpp · Bedrock · …)
                              │
                    ┌─────────┴──────────┐
                    │    Phoenix Core     │   OpenAI-compatible API + MCP
                    │ 15 agents · 50+ tools │
                    └─────────┬──────────┘
              ┌───────────────┼────────────────┐
              ▼               ▼                 ▼
           Wazuh         OpenSearch        Nest · Crucible
        (telemetry)     (search/index)     (built on Core)

Own your AI security stack end to end.