AI Labs  /  NetCentral
AI Labs · NetCentral

One screen.
Every signal. Explained.

NetCentral is the network and security operations console built for a Chicago trading brokerage — one place to see everything seven separate tools used to show, joined into incidents that actually mean something.

Talk to us: 312-432-4480Email us
88estate health
Core link degradedDISASTER
WAN latency risingWARNING
Maintenance window activeSUPPRESSED
Backups verifiedOK
8live monitoring & infrastructure sources
10correlation rules, each event counted once
44CCIE-style configuration review rules
3,000+automated tests before anything ships
The problem

Seven consoles, one engineer, and a trading day that can't wait

Monitoring, logs, firewalls, wireless, storage and uptime tools each told part of the story. NetCentral reads them all, matches every device to a single identity, and turns thousands of raw signals into a short list of incidents with a clear reason for each.

  • Every device matched across all sources to one identity
  • Devices removed automatically when they leave every source's inventory
  • Read-only by design — it never writes to a network device
  • Vulnerability and end-of-life feeds checked against the software actually running
  • Configuration backups stored read-only with diffs and 'what changed'
# how an outage becomes ONE incident
rule R0 merge 'device down' reported by several sources
suppress children behind a failed uplink → one uplink, one incident
classify flapping vs. failing (a rebooting PC is not a fault)
score weight by severity × device class, diminishing per class
result 1 incident · reason shown · health ledger updated
Inside the engine

The smarts

Correlation engine

Ten rules — from cross-source device-down merges to trading-path degradation, optic decline, port flaps and fleet-wide log patterns. Most specific rule wins; every event is charged to exactly one incident.

Health score with a ledger

A score out of 100 computed from its own explanation. Deductions weighted by severity and device class — the fifth tunnel down counts less than the first.

Alert decision engine

Routes by severity, device class, site, source, trading venue and trading hours. Knows new from escalation, reopen, recovery and closed — and records why anything was held.

Market-aware time logic

Exchange session clocks including sessions that cross midnight and weekends, with daylight-saving and holiday awareness, plus maintenance windows and quiet hours.

Grounded AI analyst

A 'State of the Network' brief, per-incident AI Explain, log diagnosis and 'Ask NetCentral' — the model only chooses from read-only questions; real code fetches the rows and shows them as evidence.

Privacy guardrails

Addresses, hardware IDs, usernames and secrets are replaced with tokens before anything leaves the box. Prompt-injection fencing and a daily AI cost cap.

Live topology map

Built from the devices' own neighbour tables. Every cable repainted from live port state every 60 seconds — red when down, amber when flapping.

Ten-channel ops wall

Operations, trading, capacity, hardware, voice, planned work and more — each monitor on its own channel, and the wall says so if it ever stops updating.

AI CCIE config review

44 rules measure every device against the estate's own majority standard, with evidence, the exact fix, and how to verify it.

Time-sensitive by design

It knows what time it is — and what that means

For a trading firm, 'down for five minutes' means something very different at 9:31 am than at 2 am on a Sunday.

Poll

Core sources every 60 s; others every 2–5 minutes.

Correlate

Signals folded into incidents, most specific rule first.

Decide

Severity, venue, trading hours and windows weigh in.

Hold or send

Rate limits, quiet hours, storm digests: 8+ incidents in 15 min → one message.

Explain

Every decision recorded — including why something was held.

Built to be trusted

Engineering you can audit

  • 3,000+ automated tests and an 80% coverage floor that can only go up
  • Safety checks are deliberately broken in testing to prove they fire
  • Browser-driven click-path verifiers on every release
  • Nightly verified off-host backups, restore rehearsed with a dry run
  • One-command deploy: snapshot, push, build, health-check
  • Operators, not code, change intervals and rules — from the app
  • Every operator action attributed and audited
  • Role-based access with login lockout
  • A token-gated read API and metrics endpoint
  • Email, Teams, Slack and SMS transports built and policy-configurable
  • Configuration changes to devices stay with humans — enforced by a test
  • Released continually — around 160 improvements in two weeks
More from AI Labs

Explore the family

Let’s talk

Want this kind of visibility for your network?

Call or email and a Haventech engineer will walk you through what AI can do for your business. Mon – Fri, 6:30 am – 5:00 pm.