[ Privacy-Focused Terminal ]

THE SSH CLIENT THAT KNOWS YOUR NETWORK

AI-powered terminal workspace for network engineers. Connect, profile, and manage your infrastructure with hallucination-resistant intelligence, grounded in 35,000+ curated CLI commands.

Pair Claude Code, Codex or Cursor and let it read your live network. Read-only by design, through your own credentials on your machine, and device output is sanitized before the agent sees it. ▸ MCP Server

lock_open Be first in line at launch. Starts free. No credit card, no spam.

35,000+

Curated Commands

20+

Network OS Types

Privacy

Focused Architecture

RTRGRD terminal interface with the AI copilot answering a network question
// Core Modules

Built for Network Engineers

AI-powered terminal workspace. Every feature built for hallucination-resistant intelligence.

neurology

Learns Your Network

Connect and RTRGRD auto-profiles your device: VLANs, routing, interfaces, ACLs. Ghost Text suggests commands you've actually used before, filtered by device and OS.

shield

Secrets Stay Local

30+ credential patterns automatically stripped before any cloud AI request. Passwords, SNMP strings, keys, and certificates are stripped before any cloud request, and Privacy Mode keeps everything on your machine.

upload_file

Your Docs, Your AI

Upload CLI guides, deployment docs, and walkthrough PDFs into your local knowledge base. AI responses are grounded in your standards, not generic vendor docs.

smart_toy

AI Copilot

Ask questions inline with @ai or in the sidebar. Get grounded commands, device-specific context, and drag-and-drop code blocks, all backed by your local RAG database.

account_tree

Multi-Device Command Deck NEW

Plan, scope, and execute changes across multiple devices in parallel. Per-device scaffolds with SCOPE TOKEN guards, AMENDMENT MODE for safe edits, AI Best-Guess prefix, and per-OS syntax grounding to block hallucinations before they reach the wire.

hub

Map Your Topology

Auto-discover LLDP neighbors across vendors. Ask "What's the path from Core1 to Access4?" and get real answers calculated from live graph data.

// MCP Server · Beta

Let Your Agent Read The Live Network

RTRGRD's terminal can act as a local MCP server. Pair an AI agent you already use, Claude Code, Codex, Cursor, Claude Desktop, any MCP client, and it reads the SSH sessions you choose to share: in your terminal, through your credentials, on your machine. It listens only on 127.0.0.1, nothing is visible until you share a tab or a group, every call is logged with the decision and the reason, and you can revoke with one click. The agent never holds a device password or key.

lan

Diagnose A Fabric From Your Editor

"Look at spine-1, spine-2 and leaf-1 and tell me why OSPF is not forming." The agent reads LLDP, interface state, neighbor tables and logs across all three and answers with the layer that failed, from live state, not from a pasted screenshot.

groups

Ask A Whole Group At Once

Share a site or a tier and ask across it: which access switches have interface errors climbing, how NTP and logging compare across the campus core, which devices still run the old image. One read, run on every shared device, returned as a fleet-wide diff.

gpp_maybe

Designed To Be Read-Only

The agent gets show and display commands, ping, traceroute, topology and RTRGRD's knowledge base. Configuration dumps, credentials, command history and diagnostic bundles are refused by design, and output passes the sanitizer before it reaches the agent.

arrow_forward How RTRGRD MCP Works
// See It In Action

Inside the Terminal

// Grounded Python Automation

Describe the Change. Get Curated Python.

The Apex-Py tier turns plain-English intent into runnable, self-verifying automation for your whole fleet, grounded in real parser data and your devices' live config, never guessed.

Plain English In, Runnable Python Out

"Add VLAN 200 to every access switch and confirm it's up." The AI writes the complete script: no boilerplate, no SDK wrangling, no netmiko / paramiko glue to maintain.

Grounded, Not Guessed

Every command resolves against a curated parser corpus, NTC + Genie, 7,400+ parsers across 56 platforms, plus your device's live running-config. Canonical syntax and the right field names, not hallucinated ones.

It Knows the Build Order

New Architecture Principles grounding teaches the AI the correct order and verification for multi-step builds: OSPF, BGP, VXLAN/EVPN, MLAG, STP, FHRP, 802.1X. Parameters matched on both ends, adjacencies verified in sequence.

Self-Verifying & Reversible

Dry-run first, execute across the fleet, then read the result back from each device to confirm the change landed. Every write auto-checkpoints for one-click rollback.

PLAIN ENGLISH → VERIFIED FLEET CHANGE Curated CLI Syntax 35,000+ commands · 30+ OS Parser Corpus NTC + Genie · 7,400+ parsers Your Docs + Device Config live running-config · local NEW Architecture Principles build order + verification GROUNDED RETRIEVAL: per-device, per-OS context assembled AI PYTHON BUILDER Gemini · temperature 0 · deterministic codegen secrets stay local banned libs blocked structure vetted PY generated.py SEND TO WORKSPACE ▸ # "deploy the OSPF + iBGP underlay across the cx group" import rtrgrd proposed = {h: plan(h) for h in rtrgrd.fleet.targets()} rtrgrd.fleet.config_apply(proposed, commit_mode="review_at_end") # → dry-run · per-device diff · verify-readback · rollback DRY-RUN simulate: zero changes EXECUTE per-device bridge auto-checkpoint each write VERIFY-READBACK re-read every device ✓ CONFIRMED change landed readback ≠ intent? ↺ ONE-CLICK ROLLBACK: checkpoint restores prior config Grounded generation → dry-run → fleet execute → verify-readback → confirmed, or rolled back in one click.
// Network-Engineered RAG

Your Docs. Your AI. Grounded Intelligence.

Generic AI tools hallucinate commands. RTRGRD's RAG engine is purpose-built for network engineering. Every layer retrieves exact CLI syntax, not approximate answers.

Hybrid FTS + Vector Search

Exact keyword matches for show ip ospf neighbor plus semantic similarity for "how do I see OSPF peers," merged with reciprocal rank fusion. Highly accurate retrieval with <100ms query time.

Upload Your CLI Guides

CLI References: commands are auto-extracted, parsed, and indexed. Conceptual Guides: deployment walkthroughs and config templates become AI context. General Docs: SOPs, runbooks, vendor bulletins. All stored locally on your machine.

OS-Filtered Results

Query for "BGP neighbors" returns Aruba CX syntax on an Aruba switch, not Cisco IOS. Parent-child chunks return the command and the surrounding context, no guessing.

Local Embeddings

Powered by Nomic Embed v1.5 with 384-dimension vectors in LanceDB. No cloud round-trip for lookups. Your knowledge base stays on your device; only the snippets a question retrieves travel with a cloud request, and none in Privacy Mode.

🧠 SYSTEM BRAIN IMMUTABLE · READ-ONLY Multi-Vendor CLI Syntax Cisco · Aruba · Juniper · 30+ platforms AI-Generated Descriptions Human-readable summaries for every command Context Hierarchy Tags exec · config · ospf · bgp · evpn · vsx Shipped with the app Updates never touch your data OS-Filtered Retrieval Results scoped to the active platform 🧠 USER BRAIN PRIVATE · LOCAL · EVOLVING 📄 Your Uploaded Docs CLI guides · SOPs · Runbooks · Vendor PDFs ⌨️ Learn As You Go Watches what you type · Learns what works 🔍 Device Profiles Live running-config → AI-indexed context 100% Local Embeddings Your docs and configs stay on your machine 👻 Ghost Text Autocomplete Instant suggestions from your history QUERY WATERFALL P1 Device Configs Ground truth for THIS device P2 Your Documents Uploaded PDFs · SOPs · Guides P3 Learned Commands Your habits · Frequency-ranked P4 System Syntax Curated vendor CLI · Baseline Hybrid Search Engine Keyword FTS + Semantic Vectors Rank Fusion · Context Boosting · <100ms AI Response Grounded · Curated · Exact
// Security & Privacy

Built to Keep Your Secrets on Your Machine

shield

30+ Patterns Sanitized

Passwords, keys, SNMP strings, TACACS/RADIUS, certificates are stripped before any cloud request. The Guardian Orb shows exactly how many secrets were protected per request.

lock

Data Stays on Your Device

Embeddings processed locally via Nomic v1.5. RAG database in your AppData. Credentials encrypted via OS keychain (DPAPI / Keychain / libsecret). Enable Privacy Mode to keep all AI queries local too.

cloud_done

Vertex AI: No Training

Cloud AI uses Google Vertex AI, with no training on customer data. Your prompts and responses are never used to improve models.

visibility

Guardian Orb

Real-time indicator showing "X secrets protected" per request. Full transparency on what's sanitized before data leaves your machine.

wifi_off

Privacy Mode

Full offline operation with a local Google Gemma 4 model, sized automatically to your hardware (E2B, E4B, or 26B MoE). Zero network calls for AI. Perfect for air-gapped environments and classified networks.

key

Credential Vault

SSH keys, enable passwords, and certificates stored in your OS's native encrypted keychain. Never written to disk in plaintext.

// Access Levels

Start Free. Upgrade When Ready.

Every account starts with a 15-day full-AI trial. No credit card to begin. Keep the free tier forever or scale up when your fleet does.

rtr-core
Free terminal + network copilot
$0 forever

A fast, multi-vendor SSH terminal with an AI network copilot built in. Run commands and get straight answers on Cisco, Arista, Juniper, Aruba and more. No subscription.

  • check Full SSH client + session manager, all vendors
  • check AI Copilot: 15 queries/day
  • check Command Deck multi-device Q&A: 10/mo
  • check Device profiling + RAG syntax lookup
  • check 15-day full-AI trial included
  • lock Python Builder: preview (upgrade to unlock)

Free at launch · no credit card

Fleet Automation
rtr-apex-py
Copilot + fleet automation
$35 / month

Describe the change; get runnable, self-verifying Python for your whole fleet. The AI writes scripts that apply your change across every device and read the result back to confirm it landed, with dry-run and one-click rollback.

  • check Everything in Apex
  • check Fleet-scale Python Builder: no single-device limit (~200+/mo)
  • check Runnable Python with verify-readback
  • check Dry-run simulation before you touch the wire
  • check Per-device checkpoint + one-click rollback
  • check Fleet audit across every device
  • check MCP Connectors: bring your own external MCP servers into Copilot
  • check MCP Server: no shared-device limit

Connector use is metered: external tool turns are capped per day, and each turn may call a small number of tools. Limits are shown in the app and may change as the feature leaves beta.

Cancel anytime

Init Session

Authenticate to manage your subscription and enable cloud features.