interfaceful
www.interfaceful.com
Customer Brochure

Sovereign Network
Automation.
AI you own.

AI-driven network automation for multi-vendor environments — running entirely inside your perimeter. No cloud dependency. Ever.

Scroll to explore

Your network.
Your AI.
Zero cloud egress.

One bootable ISO appliance that turns any server into a multi-vendor, AI-driven network automation platform — running entirely inside your perimeter. No cloud dependency. No data egress. Ever.

Start 90-day free trial → See capabilities
20
Vendor connectors
$48–204
Per device / year
90×
Faster incident response
FABRIC™ LIVE Cisco GCP Arista NetBox Palo Alto Fortinet Juniper Cloudflare F5 Azure AWS INTERFACEFUL FABRIC™ · live topology LIVE devices 312 synced 312 drift 0 last recon 0s
Air-gap ready
20 connectors · one SDK
THE CHALLENGE

Manual networks are
a liability you can't afford.

The most complex multi-vendor estates belong to the organisations least able to accept cloud-based AI. The gap between operational risk and available tooling has never been wider.

73%
of network outages trace to human config error
Every manual CLI change is an unvalidated bet on production stability.
287d
average time to identify & contain a breach
Without continuous drift detection, misconfigs erode security for months.
6 wks
average audit preparation time per compliance cycle
Manual evidence collection from multi-vendor estates is expensive and error-prone.
"Cloud giants cannot deliver sovereignty. Single-vendor tools cannot deliver breadth. Legacy NMS has no AI. DIY open source has no connective tissue. Interfaceful sits precisely where all four fail."
THE PLATFORM

One appliance.
Everything your network needs.

Interfaceful is a bootable ISO that turns any server — bare-metal, VM, or cloud image — into a fully self-contained network automation platform. Flash it, boot it, and your entire multi-vendor estate is visible in under 5 minutes.

No cloud dependency — AI models run locally. Network telemetry never leaves your perimeter.
Multi-vendor from day one — 20 connectors across Cisco, Arista, Juniper, Palo Alto, Fortinet, cloud, and more.
Air-gapped by design — immutable OS, signed updates, delta-ISO delivery to completely disconnected sites.
Compliance-by-evidence — every action hash-chained and audit-ready for SOC 2, HIPAA, PCI-DSS, CMMC, and more.
Deployment targets
Bare-metal (UEFI) VMware ESXi KVM / Proxmox Hyper-V AWS AMI GCP / Azure Air-gapped ✓
Service-level objectives
API availability 99.9% monthly
API p99 latency <250ms
LLM first-token p95 <1.5s
Full discovery from boot <5 min
HOW IT WORKS

From boot to autonomous ops
in four steps.

01
Boot & Connect
Flash the ISO to bare-metal or import as a VM. Connect to your network management plane. No agents required on devices.
02
Discover & Map
The Interfaceful Fabric™ auto-discovers your entire multi-vendor estate and builds a live topology graph in minutes.
03
Monitor & Alert
Continuous drift detection compares declared intent vs. observed state. AI identifies anomalies and maps root cause to topology.
04
Automate & Comply
Describe intent in natural language. AI proposes changes, dry-runs, seeks approval, executes — and logs every action as compliance evidence.
The AI proposes — a deterministic execution boundary acts. Network devices are never touched directly by the AI layer. Every action requires approval, is logged, and can be rolled back.
CAPABILITIES

The full operational lifecycle,
in one platform.

Every capability tier is a strict superset of the one below — start with visibility, expand to autonomous operations as confidence grows.

Continuous Discovery

Auto-ingests topology across all vendors in <5 minutes. One vendor-neutral graph that stays live as your network evolves.

Drift Detection & Remediation

Diffs declared intent vs. observed state continuously. When drift surfaces, AI proposes an approval-gated fix — staged for change control before any device is touched.

AI Change Management

Describe intent in natural language, Terraform, or Ansible. AI translates to vendor-specific commands across all affected devices and dry-runs before execution.

Compliance Evidence

Every action timestamped, hash-chained, and auto-mapped to SOC 2, HIPAA, PCI-DSS, CMMC. Audit prep: 6 weeks → 30-second export with cryptographic proof.

Incident Response

Falco, Wazuh, and OpenVAS alerts triaged by AI. Root cause mapped to topology. Isolation actions staged for one-click approval. 90× faster than manual triage.

Air-Gapped Operations

Signed delta-ISO bundles deliver updates to completely disconnected sites — defence, OT floors, substations — with atomic A/B rollback and SLSA provenance.

CONNECTOR ECOSYSTEM

20 connectors.
One SDK contract.

Every connector ships as two containers — read-only and write. Read cannot escalate to write. Dynamic 1-hour credentials. Hot-swappable without platform downtime.

Standard connectors — included by tier
Cisco IOS-XE/NX-OS Arista EOS Palo Alto PAN-OS Fortinet FortiOS AWS VPC/SG NetBox CMDB Cloudflare WAF/DNS Azure VNet/NSG Juniper Junos Google Cloud VPC OpenVAS / GVM Generic REST adapter
Premium connectors — +$12/device/yr each
F5 BIG-IP LTM/GTM Legacy Cisco IOS Check Point Avocent / Vertiv Aruba / HP ProCurve Extreme Networks Brocade / Ruckus Custom bespoke
SDK contract (all connectors)
Cosign-signed capability manifest
Normalised to Interfaceful Fabric™ graph
Circuit breaker + exponential backoff
Independent semver + cassette tests
Dynamic 1-hour OpenBao credentials
Hot-swappable — zero platform downtime
–82%
Config change error rate
30s
Compliance audit export
SECURITY ARCHITECTURE

Zero-trust from kernel up.
AI that never touches devices directly.

Deny-all by default. mTLS everywhere. SPIFFE identity on every workload. The AI proposes — a deterministic boundary executes.

Deny-all · mTLS · SPIFFE identity

No component trusts another. All internal traffic mTLS via Cilium eBPF. Every service carries a SPIFFE workload identity.

Dynamic credentials — 1-hour TTL

OpenBao issues short-lived vendor credentials scoped to the approved plan. A stolen credential expires in minutes.

Read / write container split

Every connector ships as two containers. A read query physically cannot escalate into a write — architectural, not policy-enforced.

SLSA L3 + Cosign supply chain

Every ISO and container image is Cosign-signed with full SBOM. Trivy gates every build. No unsigned artefact reaches a customer.

Immutable hash-chained audit log

Every MCP tool call hash-chained, SIEM-exportable, 7-year retained. "What did the AI do?" has exactly one auditable answer.

AI safety — PyRIT / Garak gate

Structured inputs · signed prompts · second-LLM guard · canary tokens · MCP session TTL. Red-team suite blocks every failing release.

Compliance — Auto-collected evidence
SOC 2ISO 27001 PCI-DSSHIPAA CMMC L2NIST 800-53 EU AI ActFedRAMP Ready

Always current · one-click export · 7-year retention

Immutable host OS
Ubuntu 24.04 LTS · squashfs immutable root · CIS Level 2 hardening · AppArmor · auditd · seccomp · A/B partition rollback for atomic updates.
TARGET INDUSTRIES

Built for industries that can't
compromise on sovereignty.

Defence & Intelligence

Air-gapped, sovereign, CMMC-ready. Works in classified environments with zero external egress.

Healthcare

HIPAA evidence collection, on-prem PHI safety. Automated audit exports for every network change.

Finance & Banking

PCI-DSS, SOC 2, zero-egress. Closed-loop automation with full change-control audit trails.

Government

FedRAMP path, data sovereignty, NIS2 alignment. On-prem AI inference with no vendor cloud dependency.

Critical Infrastructure

OT/ICS isolation, air-gap native. Separate read/write containers ensure operational technology is never exposed.

Sovereign Cloud

Multi-vendor, local AI inference. For cloud operators who must keep network intelligence inside national borders.

USE CASES

Real outcomes,
measurable impact.

Change management

Eliminating config-driven outages at a regional bank

A 400-device multi-vendor estate spanning Cisco, Arista, and Fortinet. Interfaceful's AI change management replaced manual CLI change windows — every intent described in plain language, dry-run validated, change-control approved, and executed with full rollback capability.

Config error rate: –82% · Mean change time: –65%
Compliance automation

From 6-week audit cycles to 30-second exports at a hospital network

A healthcare operator running 200+ devices across three sites needed continuous HIPAA evidence without sending any data to the cloud. Interfaceful deployed air-gapped, auto-collected evidence for every network change, and reduced audit preparation from six weeks to a single export.

Audit prep: 6 weeks → 30 seconds · 100% evidence coverage
Sovereign AI operations

Autonomous network ops at a defence contractor

A defence prime needed AI-assisted network operations inside a classified, fully air-gapped environment. Interfaceful's ISO was delivered via signed delta bundle, models run on local GPU, and all 7 AI agents operate without any external network access — ever.

Zero cloud egress · Response: 90× faster · CMMC L2 ready
LICENSING & PRICING

Land free.
Expand naturally.

Per-device pricing — same unit economics as Cisco DNA Center and SolarWinds. 90-day free trial, no card required. Volume discounts: –15% at 500 devices, –25% at 1,000+.

Free Trial
90 days · 50 devices · no card
$0
  • Full topology snapshot
  • Compliance summary reports
  • AI Q&A on topology
  • Automation locked
Visibility
5 standard connectors
$48/device/yr
  • Unlimited devices
  • Detailed compliance reports
  • Daily vulnerability scans
  • Full AI chat + Q&A
Most popular
Governance
8 standard connectors
$120/device/yr
  • Everything in Visibility
  • Approval-gated automation
  • GitOps + drift remediation
  • Ansible & Terraform execution
Autonomous
All 10 standard connectors
$204/device/yr
  • Everything in Governance
  • 7-agent AI roster
  • Closed-loop autonomous ops
  • Full compliance evidence export
Premium connectors — +$12/device/yr each
F5, legacy Cisco IOS, Check Point, Avocent, Aruba, Extreme, Brocade, custom. Priced only on devices using that connector.
Managed SaaS — +$24/device/yr surcharge
Fully hosted, managed, auto-updated, multi-tenant isolation. Available as an add-on to any tier.
GET STARTED

Ready to take back control
of your network?

Start with a free 90-day trial on up to 50 devices. No credit card required. Boot the ISO, connect your devices, and see your entire estate in under 5 minutes.

Talk to our team — schedule a demo →