Install

Up and proposing in under 30 minutes.

One command or one Helm chart, a guided setup, shadow mode by default, and an air-gap bundle when the network is closed.

Install in minutes. Ship nothing out.

The out-of-the-box flow, in full: install, connect through the guided setup, watch it propose in shadow mode, then approve per service. The target: a clean VM goes from install to first shadow-mode proposal in under 30 minutes.

INSTALL1
helm install 3am oci://…/3am · 3am install

One chart, or one command on a single VM. Preflight checks cover CPU/RAM/GPU, disk, egress to the chosen tools, and the licence. An air-gapped bundle ships for offline installs.

CONNECT2
guided setup · no config files

The wizard wires the tools you choose through connectors: source repos, monitoring and alert sources, action targets, ticketing and CMDB. No inbound ports. No integration project.

WATCH (SHADOW MODE)3
proposes · logs · touches nothing

The agent runs against live incidents and produces digests while every action stays a proposal. A week of shadow mode is the normal switch-on path.

APPROVE (L1)4
one-tap, per service

Flip a service to L1 when you're ready, not the whole estate. Every approval round-trips through Slack, Symphony, PagerDuty, xMatters, Twilio IVR or e-mail, and lands in the ledger with the approver's identity.

An engineer working directly on a server rack in a data centre
Photo: Derrick Coetzee, NERSC (CC0)
IP protection: on-prem without handing over the product
Build

Python services compiled to native executables with Nuitka, so no .py or .pyc ships. Console as a minified bundle. Minimal distroless images, signed with cosign, with an SBOM.

Sealed packs

Check classes, remediation recipes, prompts, chunker configs and evaluation cases encrypted with AES-GCM and signed with Ed25519. Keys derived from the licence, decrypted only in memory, each pack watermarked with the customer ID.

Licence

Offline signed JSON: customer, install fingerprint (cluster UID or host ID), expiry, features, limits. Verified against a public key embedded in the binaries, with a grace period and no phone-home requirement.

Contract

EULA with no reverse engineering, audit rights and support tied to the licence. Binaries check their own integrity.

The honest limit

Code running on a client’s hardware can’t be made unreadable. These measures make copying slow, costly and legally exposed, and the sealed packs are the expensive part to rebuild.

End to end, or it doesn’t count.

Every claim on this page maps to a test we run before shipping. Plug-and-play is not a slogan: two estates, different stacks, one unchanged product, and if a single harmful action ever gets through, the release doesn't ship.

Fresh-install test

A clean VM gets the Compose bundle; a fresh kind/k3s cluster gets the Helm chart. Run the wizard against Pinata and time it from install to the first shadow proposal.

Plug-and-play proof

Pinata's Fineract estate and the second estate both work with no product code changes. Swapping Prometheus for Splunk data gives the same verdict on the same incident.

Approval channels

Sandbox accounts for every channel: Slack test workspace, Symphony dev pod, PagerDuty developer account, xMatters trial, Twilio test credentials. Approve, reject and time-out are scripted, and the escalation chain is checked.

Decision ledger

The verify tool detects a modified, deleted or re-ordered event. Replaying an incident from the ledger reproduces the agent's decisions.

IP protection

No source files in the images. An expired, tampered or wrong-fingerprint licence is refused. Packs can't be decrypted outside the running process.

Agent quality

Pinata's scorer, held-out comparison and collateral checks are carried over, with harmful = 0 as a release gate.

The release gate

harmful = 0. Not an average. Not a target. Every evaluation suite (smoke, fast and nightly) ends with collateral damage checked against business invariants: unbalanced transactions, trial-balance drift, duplicate journal lines.

Early access

Point it at a monolith that scares you.

We’re onboarding a small number of teams running legacy core systems we can’t rewrite. The install runs on your hardware, behind your firewall, connected through a guided setup. So if you’ve got a service where the on-call rotation has learned to dread the pager, we want to see it.

Shadow mode by default: proposes and logs, touches nothing until you approve it.