Sovereign network diagnosis

It reads. It never touches.

Auspex is an on-premise, read-only fault-diagnosis assistant for your network. It runs entirely inside your closed environment — air-gapped, on your own hardware — powered by Kestrel, a compact model trained in our synthetic network lab.

auspex chat
pc-ayse can't reach the file server
get_topology
get_vlans leaf2 · trunk allows 10, 30
ping pc-ayse→10.10.10.1 · 100% loss
vlan_removed_from_trunk @ leaf2
VLAN 20 dropped from leaf2 trunk · nothing was changed
kestrel:v1 · ctx ▓▓▓░░░░░ 4.2k/24.6k · 6 tools · 12s

Try it now

Two commands. Your hardware.

Install the open-source CLI, pull the model, diagnose. Everything runs locally.

Linux / macOS
curl -fsSL https://github.com/Calexis-Labs/auspex-cli/releases/latest/download/install.sh | sh
Windows
irm https://github.com/Calexis-Labs/auspex-cli/releases/latest/download/install.ps1 | iex
Model (~5 GB)
auspex setup
GitHub →Apache-2.08 GB+ VRAM GPU or 16 GB+ Apple Silicon

The problem

The networks that need help most can't phone home.

Enterprises won't expose their network configuration to an outside service — and many of the sites that need diagnosis most have no internet at all. A cloud AI assistant simply cannot run there.

Auspex answers that constraint directly. Everything — the assistant, its tools, and the model — lives on the customer's own hardware, inside the closed network. Nothing leaves the site.

How it works

A data factory, not a data grab.

Auspex learns from faults we manufacture in a virtual lab — so it never needs a single byte of your production network to get good.

01

Synthetic lab

A virtual network of multi-vendor switches and hosts. We inject thousands of realistic faults — no customer data ever required.

02

Expert distillation

A large teacher model diagnoses each fault using only read-only tools, then a deterministic verifier keeps solely the traces that are provably correct.

03

The model learns

The compact Kestrel model learns from those verified traces — distilling an expert's judgment into something small enough to run offline.

The model

Kestrel — small on purpose.

A kestrel hovers dead still, reads the ground below, then strikes with total precision. The model at the heart of Auspex is built the same way: compact enough to live inside your network, sharp enough to name a root cause on the first pass.

We didn't chase a bigger model. We trained a focused one — narrow by design, expert at a single discipline, and light enough to run where the network actually lives. That's what makes on-premise diagnosis possible at all.

Kestrel is scored against its expert teacher on a held-out exam before any performance claim is published.

Compact

Small enough to run on a single modest on-site machine — no GPU cluster, no data center.

Offline

Runs fully air-gapped. No cloud calls, no telemetry, no internet connection ever required.

Purpose-built

Trained on one job — network fault diagnosis — not a general chatbot stretched to fit.

Read-only hands

Reasons over the same read-only tools as its teacher. It can look; it can never change a thing.

Safe by design

A diagnostic that can look, but cannot break anything.

The name says it: an auspex reads the signs. Ours is guaranteed to read and nothing more.

Read-only by architecture

The model can never change a configuration. Read-only is enforced at the transport layer — a three-layer, fail-closed allowlist — not by a prompt that can be talked around.

Air-gapped by design

Auspex runs 100% inside your closed network. No cloud calls, no telemetry, no data leaving the site. Your network topology never travels.

Updated on your terms

New capabilities and vendor support ship as signed model files over USB or an internal share — no internet connection needed to stay current.

Coverage

What Auspex diagnoses today.

Adding a new vendor means adding an image to the lab and running the same pipeline — coverage grows without touching a customer network.

Interface & link failures
VLAN & trunk misconfigurations
OSPF adjacency & routing
Static routes & reachability
ACL / traffic filtering
Gateway & subnet errors
Duplicate addressing
Multi-cause incidents

Benchmark — v1 results

We graded the model. Here is the number.

Every model below sat the exact same held-out exam: live virtual networks it had never seen, one real injected fault per question, the same read-only tools, and a deterministic scorer checking fault class, device and root cause. No cherry-picking — this is the full run.

100%75%50%25%0%
11%
68%
85%
Qwen3 8B (base)
Fully local · ~5 GB17 of 150 correct
Kestrel v1
our modelFully local · ~5 GB102 of 150 correct
Claude Sonnet 5
Cloud reference model128 of 150 correct

Partial credit (right class, incomplete detail) is counted as incorrect in the headline number. · Kestrel v1 · 2026-07-23

Methodology

  • 150 questions across 51 network topologies the model never saw in training
  • Each question is a real fault injected into a live virtual network — not a quiz text
  • All models use identical read-only tools through the same Auspex harness
  • Deterministic verifier scores fault class, culprit device and root cause — no human judging, no LLM judging

An honest note on the comparison: Claude Sonnet 5 is a frontier cloud model — it needs an internet connection and per-question API cost, and its parameter count is undisclosed. Kestrel is a 5 GB model running entirely on-site. We publish the cloud number as a reference ceiling, not as a size-for-size rival.

Get in touch

Bring Auspex to your network.

Questions, feedback, or a signed offline deployment for an air-gapped enterprise site? Reach out and we'll get back to you.

hello@calexislabs.com →