FAQ

Straight answers to the hard questions.

Safety, autonomy, air-gap, false positives, deployment and licensing: the things security buyers ask before anything else.

Is it safe to run against production?
Yes, with control you set. Exploits are proven safely in isolation rather than against the host, and Nexich automatically eases off if a target service shows stress. Classic mode is fully deterministic and hands-on, so you decide how far the autonomy dial turns for any given target.
Does the AI phone home or send any data off-box?
No. Models run locally on your hardware with zero internet access, there is no telemetry or crash reporting, and no model API is ever called. Topology, credentials and findings stay in a database you control. Nexich runs on fully air-gapped networks. See the trust & sovereignty page.
Won't an autonomous AI hallucinate false positives?
The AI plans and prioritizes, but exploitation is deterministic execution: a finding is only recorded when a real payload reproduces it (a captured shell, a dumped table, a replayed credential). Unproven claims are dropped rather than padded into the report. That "proof or it isn't recorded" discipline is what separates it from a scanner's backlog of maybes.
How is this different from a vulnerability scanner?
A scanner infers risk from versions and banners and hands you a list. Nexich chains and detonates those findings into a proven exploit and builds cross-host kill chains from looted credentials. You triage exploited facts, not maybes. The full comparison breaks it down row by row.
What does deployment look like?
One binary, with the local AI included: no agents to install on targets, no cloud services, no external dependencies. It runs on Windows, Linux and macOS, and installs self-contained on air-gapped hosts.
What are the five operating modes?
An autonomy ladder. Classic is deterministic and hands-on; Smart is a fast automated sweep; AI Hybrid advises while you drive; AI Autonomous plans and runs the engagement; AI Forge is full-scope autonomous 0-day hunting across every service and credential. Turn the dial to match the engagement and the trust you want to extend. Try the dial.
What does it cover, which services and hosts?
A full 1-65535 TCP and UDP sweep per host, with service detection by protocol behavior rather than port number. Coverage spans every service class an attacker touches: web apps, databases, message queues, Active Directory, remote access, file shares, VoIP and OT/IoT, 200+ native attack modules in all. Where a known exploit exists, Nexich uses it; where no list covers the gap, it writes a custom one on the spot.
Can I re-test after we ship a fix?
Yes. Re-fire any proven finding on demand; Nexich reproduces the original exploit path and the AI returns a verdict (still vulnerable, fixed, or inconclusive with the reason) plus a plain-language note on what changed. Validation is a one-click loop, not a new engagement.
Who is authorized to use it?
Nexich is licensed for owners of the network under test and for providers running authorized engagements on behalf of clients. Evaluation builds are supervised and scoped to authorized use only.
How is it licensed and priced?
Self-hosted and licensed by in-scope IP address, from a 32-address minimum, with air-gapped / on-prem options at the enterprise tier. There's no public price list. Tell us your in-scope IP count and we size it with you. See licensing or request an evaluation.

Still have a question?

Ask us directly

Evaluation builds for authorized testing only.