Active development · Early Stage

Stop managing
infrastructure.
Start controlling it.

OpsControl brings together secure vault-based access management, real-time service monitoring, and an AI assistant that understands your infrastructure — all in one platform.

HashiCorp Vault Whisper ASR SetFit ML n8n Docker
opscontrol — live session connected
# Engineer query received via Telegram
[🎤 11s] "prod-db-01 is not responding, something looks broken"
→ [Whisper large-v3] transcribed for routing
# Agent Router: classifying support context...
[SetFit] tier: medium · confidence: 0.89 · 18ms
→ routing to analysis workflow /medium
# InfraConnect: checking prod-db-01 SSH port status
port 5432/postgres ✓ online
port 22/ssh ✗ offline ← SSH port unavailable
# Suggested response sent to Telegram
[AI] SSH on prod-db-01 is unreachable. Suggested checks: service status, firewall, host access.

Ops teams drown in tools,
not results.

Every team above 5 servers hits the same wall. The tools don't talk to each other. The AI doesn't know your infra. And the on-call engineer still wakes up at 3am.

🔑

Password sprawl

Dozens of servers, SSH keys, DB credentials — scattered across Keepass, shared docs, and someone's memory.

🔇

Silent failures

A port closes, a service crashes. Nobody knows until a user reports it — or worse, a customer does.

🤖

Generic AI assistants

General-purpose assistants can explain commands, but they should not hold root access or execute changes. They need controlled context, not infrastructure keys.

📋

No audit trail

Who accessed what server, when, with whose credentials? "I think it was Alexey" is not a security posture.


Two modules. One platform.

Each module solves a distinct problem. Together, they cover the full ops loop — from access to analysis.

Stable

InfraConnect

Vault-backed access and secrets layer with infrastructure monitoring. Centralize SSH workflows without giving AI privileged infrastructure control.

  • HashiCorp Vault integration for centralized secret storage
  • Temporary credentials with automatic rotation
  • Real-time port monitoring across all servers
  • SSH credential rotate via live connection
  • Full audit log: who, what, when, from where
  • Login throttle — brute-force protection built in
In Progress

Workflow-AI

AI ops layer that classifies intent, routes to the right model, and answers from your own docs — via voice or text in Telegram.

  • Whisper large-v3 — multilingual transcription for engineer queries
  • SetFit classifier: simple → medium → complex → reasoning
  • Smart routing: cheap model for FAQ, powerful for architecture
  • Force-routing with prefixes (sim@, med@, com@)
  • RAG over your internal documentation (planned)
  • All via Telegram — no new apps to install

From voice to action in seconds.

The full loop: you speak, the platform classifies, routes, checks infrastructure, and answers — all before you finish your coffee.

01
🎤

Voice or text

Send a voice message or text query to your Telegram bot — in any language, any format

02
🧠

AI classifies

Whisper transcribes audio, SetFit classifies complexity in ~20ms, routes to the right model

03
🔍

Infra check

If needed, InfraConnect scans relevant servers and ports — real data, not guesses

04
💬

Answer delivered

Response lands in Telegram with context, server status, and suggested action

The classifier separates "what time is it?" from "design a fault-tolerant database cluster" — so simple queries don't cost you GPT-4 tokens.


Built on industry standards.

No reinventing the wheel. Every component is production-tested open source — assembled into a coherent platform.

V
HashiCorp Vault

Secrets engine, dynamic credentials, AppRole auth

W
Whisper large-v3

OpenAI's ASR model — GPU-accelerated, multilingual

SF
SetFit

Few-shot sentence classifier — trained on custom ops data

n8n
n8n

Workflow orchestration — routes between models and services

FA
FastAPI

Backend API layer — typed, async, production-ready

R
Redis

Job queue for async audio processing, retry logic

PG
PostgreSQL

Server registry, port config, credential metadata

D
Docker Compose

Full stack in one command — self-hosted, on-premise


Built for the team
without a dedicated SRE.

Small and mid-size engineering teams who run real infrastructure but can't afford enterprise tooling — or the overhead that comes with it.

10–100
servers under management
2–15
engineers in the ops team
0
dedicated security engineers
SysAdmin

Stop memorizing 50 passwords. One master key, auto-rotating credentials, SSH in 3 seconds.

DevOps Engineer

Ask "why is staging slow?" by voice at 2am. Get an actual answer with port data, not a generic tutorial.

CTO / Tech Lead

Full audit log of who accessed what. Credential rotation on demand. Compliance-ready from day one.


Platform Architecture

Two modules, one data flow.

Workflow-AI handles intent — InfraConnect handles action. They share context through the OpsControl core.

📱
Telegram
voice / text
🎤
Whisper
transcription
🧠
Agent Router
SetFit · 18ms
⚙️
n8n
orchestration
ops query
🔐
InfraConnect
Vault · ports · SSH
knowledge query
📚
RAG Engine
docs · context (Q3)

Where we are. Where we're going.

Transparent by default. Here's the honest state of the project.

Phase 1

InfraConnect core

HashiCorp Vault integration, credential storage, SSH rotation, port monitoring, audit logging, brute-force protection.

Shipped
Phase 2

Workflow-AI layer

Whisper transcription, SetFit classifier, Agent Router, n8n orchestration, Telegram voice interface.

In Progress
Phase 3

Unified platform

InfraConnect + Workflow-AI connected: assistant queries can use approved infrastructure signals and return recommendations for engineers.

Planned
Phase 4

RAG + Knowledge base

Search your runbooks, incident history, architecture docs. Contextual answers grounded in your own data.

Planned
Phase 5

Web UI dashboard

Browser-based control panel: server tree, live port status, audit timeline, credential management.

Planned
Phase 6

Proactive alerting

AI-driven anomaly detection — the platform alerts you before the user does.

Planned

Early Access

We're building this
in the open.

OpsControl is early-stage. We're looking for infrastructure and security teams to pilot controlled access workflows, Vault integration, auditability, and AI-assisted operational analysis.

Based in the Philippines · Self-hosted · On-premise first · Early-stage product