How It Works Preview Security Pricing Plugins Blog Contact
Sign In Get Started
EN FR DE

Server management assisted by AI.

By RCDevs S.A. · 15 years in cybersecurity

The complete platform for your server fleet: system admin, security, compliance, monitoring, PKI, backups, credential rotation and much more. Drive it in natural language with your preferred AI: assisted in the console, or fully agentic. Execution stays on a privately-hosted LLM. No SSH. No scripts. No blind trust.

Before ManageLMAfter ManageLM
Goto Channel

Built on trusted foundations

Anthropic MCPClaudeOllamaWebAuthn / FIDO2Ed25519OAuth 2.0 PKCEPKCS#11Landlock + seccompPostgreSQLAES-256 Anthropic MCPClaudeOllamaWebAuthn / FIDO2Ed25519OAuth 2.0 PKCEPKCS#11Landlock + seccompPostgreSQLAES-256
The Vision

The future of IT management.

No more rigid dashboards and scripts. The next era of infrastructure is conversational, intelligent, and secure by design.

Talk to your infrastructure

The future is natural conversations with your IT systems: voice or prompts, no more hard-coded interfaces. Just talk to an AI that distributes tasks to a fleet of autonomous sysop agents, each with their own intelligence and specialized skills.

Local + Cloud AI, the right way

The work is split where it belongs: a local model on your own servers reads the logs, configs and secrets, so what your machines print stays with your machines. The reasoning that needs a frontier model (planning a change, explaining a failure) happens in the cloud, on the description of the problem rather than on its contents.

Not another control panel

Control panels and config tools (Webmin, cPanel, Plesk and the rest) automate only what was predicted, with every button and playbook written in advance. ManageLM is agent-based: smart agents on your servers understand intent, inspect the live system, and handle the tasks no menu or playbook ever anticipated.

How It Works

Three layers. Zero complexity.

From natural language to server execution in seconds. With every command validated and constrained.

STEP 01

Ask in plain language, from wherever you work

The portal, Claude over MCP, the browser console, the server's own shell, or a plugin in the tool you already use. All the same platform. "Restart the app", "Check logs", "Update packages on all staging servers".

Natural language → MCP → Portal
Ask in plain language from any interface — natural language to the portal
STEP 02

Portal authenticates & routes

The ManageLM portal verifies your identity via OAuth 2.0, checks permissions, identifies the target agent, and dispatches the task over a secure WebSocket channel.

Auth · RBAC · Skill validation · Routing
Portal authenticates and routes — Auth, RBAC, Skill validation, Routing
STEP 03

Agent executes with a local LLM

The lightweight agent uses Ollama (or any compatible LLM) in your infrastructure to interpret the task, generates commands, validates each one against the skill's allowlist, and executes. A single LLM server can serve all your agents, and with your own model nothing your servers print ever leaves your network.

Local LLM · Command validation · Sandboxed
Agent executes with a local LLM — command validation, sandboxed
Preview

See it in action.

A clean, fast interface built for sysadmins who need clarity and full control. In light or dark.

app.managelm.com
ManageLM portal dashboard showing server fleet overview
Security

Security isn't a feature.
It's the architecture.

The model is treated as untrusted input. Every command it produces is checked in code, so a hallucination or a prompt injection has nothing to act on.

Command Allowlisting

Skills define explicit permitted commands. Every AI-generated command is validated in code. Anything outside is blocked.

Run the LLM Yourself: Data Stays In Your Network

Point the agents at your own Ollama instance and task interpretation never leaves your infrastructure: passwords, configs and logs stay inside. A hosted model is available too, for teams that do not want to run one.

View-Only AI Access

Switch a server or a whole group to view-only and the AI can inspect and report there, but not change anything. Enforced by the kernel on the host. Skills start with no write commands at all until you grant them.

Zero Inbound Ports

Agents connect outward via WebSocket. Your servers never expose a port. Nothing to scan, nothing to brute-force, no SSH or VPN to keep patched.

$

Secrets Hidden from AI

Secrets are env vars. The LLM only sees $VAR_NAME. Actual values injected at execution time.

Ed25519 Signed Messages

Every portal-to-agent message is cryptographically signed. Agents reject unsigned or tampered messages. No command can be injected via the WebSocket.

Change Tracking & Revert

Every mutating task is git-snapshotted before and after. See exactly what changed, get the full diff, and one-click revert any task within 30 days.

Kernel Sandbox (Landlock + seccomp)

Opt-in kernel confinement (Linux). Landlock restricts filesystem writes to allowed paths. seccomp-bpf blocks dangerous syscalls like mount and reboot. Even if a command passes all other checks, the kernel stops it.

Four-Layer Enforcement
1
Skill Scope
Enforced
2
Command Allowlist
Enforced
3
Destructive Guard
Enforced
4
Kernel Sandbox
Enforced

✓ LLM is untrusted by design

The AI generates commands, but every command is validated in code before execution. A prompt injection or a hallucination cannot reach the shell.

↻ Execution limits per task

Max 10 turns · 120s timeout · 8KB output cap. Every operation logged in a full audit trail.

Built-in Skills

33 skills. 390+ operations.

From systemd to Kubernetes, Active Directory to VPNs. On Linux and on Windows. Every skill is security-scoped with an exact command allowlist.

Containers & K8s29 ops
Files19 ops
Services19 ops
Virtualization17 ops
Email16 ops
Packages16 ops
Web Server16 ops
Developer15 ops
Certificates14 ops
Database14 ops
Security14 ops
Users14 ops
Backup12 ops
Network12 ops
Storage12 ops
System12 ops
Automation11 ops
File Sharing11 ops
Active Directory10 ops
Firewall10 ops
Logs10 ops
NoSQL10 ops
VPN10 ops
DNS9 ops
LLM Servers9 ops
Base Utilities8 ops
Remote Desktop8 ops
Message Queue7 ops
Registry7 ops
Web Apps7 ops
LDAP6 ops
Monitoring6 ops
Proxy6 ops
+ Custom Skills with RAG Documentationunlimited
Each skill defines exact allowed commands: nothing more, nothing less
Built-in Intelligence

Security, monitoring, PKI & backups.
Built in. One click.

Automated security scanning, full service discovery, SSH & sudo access mapping, and user activity auditing on every server: no skills required, no prompting. Just actionable results.

Compliance & Frameworks

Map your security posture
to industry standards.

Automatically evaluate your fleet against 13 frameworks: CIS, SOC 2, PCI DSS, ISO 27001, NIS2, DORA, GDPR Article 32, NIST and HIPAA. Detect drift, track progress, and generate auditor-ready evidence PDFs. All from the same security scans.

13 Frameworks

CIS Level 1, CIS Controls v8, CIS Docker, CIS Windows, SOC 2, PCI DSS, ISO 27001, NIS2, DORA, GDPR Article 32, NIST CSF, NIST 800-53 and HIPAA. All evaluated automatically against your fleet's security scan results. Add custom frameworks with a single JSON file.

Drift Detection

When a rule that previously passed starts failing, ManageLM detects it instantly. In-app alerts and optional email notifications so your team catches regressions before auditors do.

Evidence PDFs

Generate per-framework audit evidence documents with control-by-control status, technical check results, per-server findings with raw command output, remediation guidance, and a full infrastructure inventory.

Choose Your Interface

One platform, many ways in.

Five ways into the same fleet, under the same permissions and the same audit trail: the web portal, Claude over MCP, a browser shell on any server, the server’s own command line, and plugins for the tools your team already works in.

PortalClaude / MCPConsoleShellPlugins
Work in natural language✓ Guided✓ Best✓ Assistant✓ On the host✓ In your tools
Console-based AI assistance✓ Launches it✓ Best~ Already on it
Fleet-level investigations✓ Bulk select✓ Fleet-wide✗ One host✗ One host✓ Same reach
On-demand smart reporting✓ Fleet-wide PDFs✓ Just ask~ This host~ This host✓ Same answers
Security audits and fixes✓ Scan + remediate✓ Ask for findings~ By hand~ By hand✓ Same findings
Auditor-ready evidence✓ Per-framework PDFs✓ Ask for status~ Via portal
Threat detection and response✓ Alerts + one-click kill✓ Investigate & act✓ Hands-on triage~ That host✓ Same reach
One-click privileged access✓ Roles + passkey✓ Your own role✓ Root, no SSH key~ Host login✓ Your own role
Passwords and secrets lifecycle✓ Rotate and deliver✓ Finds them~ Via portal
Scheduled maintenance✓ Built-in scheduler~ Via portal✓ Cron✓ Workflow tools
Emergency troubleshooting✓ From anywhere✓ Step by step✓ Root shell, no VPN✓ Works offline✓ In your tools
Best forFleet control, RBAC and reportingComplex, multi-step workHands-on troubleshootingLocal, scripted and offline useThe tools your team already uses

Assisted and agentic. You choose, task by task.

Most tools pick a side: an AI that only talks about your servers, or automation that only runs playbooks. ManageLM does both. Keep the keyboard when a job needs care, or hand the whole task to an agent.

AI-assisted administration

Open a real shell on any managed host straight from your browser: no SSH key, no VPN, no open port 22. You type, and the assistant works with you: it explains what went wrong and proposes the next command. Nothing reaches the shell until you press Run or Insert.

Agentic administration

Describe the outcome and let the platform work it out. Autonomous agents pick the right skills (33 of them, 390+ operations), plan the steps and run them across the whole fleet, inside a hard-enforced command allowlist, a kernel sandbox and a full audit trail.

Agentic does not have to mean write access.

View-only AI access is a switch on one server or on a whole group. With it on, agents still inspect, correlate and report across the fleet. They simply cannot change anything. The restriction is enforced by the kernel on the host, not by asking the model to behave.

VIEWProduction: reporting, audits and incident investigation in read-only mode. The agent reads logs, services, packages and configs, and writes nothing.
FULLStaging and dev, fully agentic. The agent plans the change, applies it, and reports what it did, with every task snapshotted and revertible.
Why ManageLM

Not just another management tool.

Built for the teams who run mixed Linux and Windows fleets and have to answer for them: internal IT, MSPs and hosting providers. The only platform that puts both AI assistance and AI automation behind hard-enforced security.

ManageLMSSH + ScriptsAnsible / PuppetGeneric AI
Natural language interface
No learning curve✓ Just talk✗ Bash✗ YAML
AI-assisted browser console✓ No SSH key✗ SSH client
Agentic server management (autonomous)✓ Fleet-wide~ Playbooks✗ Chat only
IDE, chat & workflow integrations✓ MCP + plugins~ API only~ Chat only
Command allowlisting (hard-enforced)✓ In code~ Limited
Skill-scoped permissions✗ Full access~ Roles
Kernel sandbox (Landlock/seccomp)
Zero inbound ports✗ Port 22✗ SSH~ Varies
Private LLM (data stays in your network)N/AN/A✗ Cloud only
Full audit trail~ Manual
Multi-tenant RBAC~ Limited
Built-in security audits✓ + remediation
Compliance frameworks & evidence PDFs✓ 13 frameworks~ DIY roles
Automated penetration testing✓ 9 tests
Runtime threat detection✓ + one-click response
Credential rotation & delivery✓ End-to-end~ Scripts~ Storage only
Certificate management & PKI✓ CA + LE~ Modules
Asset & software inventory~ Manual~ Facts
Service monitoring & alerts✓ 49 services
Encrypted S3 backups & restore✓ AES-256 client-side~ Scripts~ DIY
Cloud & infrastructure connectors✓ Synced~ Modules
Pricing

Free for 10 servers. No catches.

Every feature, every integration, every skill. Unrestricted on your first 10 agents. No credit card. No time limit. No feature held back for a paid tier.

FREE FOREVER
$0/month
Up to 10 agents, all features unrestricted
  • All 33 built-in skills
  • 390+ operations
  • Multi-tenant teams & RBAC
  • Server groups
  • Scheduled tasks
  • Webhooks & API keys
  • Full audit trail
  • Passkeys & MFA
  • Trial LLM included
  • Local LLM support
  • Security audits & inventory
  • Service monitoring & alerts
Get Started Free →

No credit card required · No feature gates · Full platform access

PRO & ENTERPRISE

Need more agents?

Scale beyond 10 agents with flexible plans for growing teams and enterprises.

  • Unlimited agents
  • Enterprise-grade Pentests
  • Priority support
  • Custom onboarding
  • Volume discounts
View Plans →
Deploy

Deploy your way.

Start with our managed cloud in seconds, or self-host on your own infrastructure with Docker.

ManageLM Cloud

Managed SaaS: start in minutes

  • Free for up to 10 agents
  • Fully managed infrastructure
  • Automatic updates
  • Trial LLM included

ManageLM Self-Hosted

Run on your infrastructure

  • Full data sovereignty
  • Docker Compose deployment
  • Proxied LLM: centralized API keys
  • No external dependencies
Platform

Everything you need at scale.

Multi-Tenant Teams

Owner, admin, member roles with granular permissions. Invite teammates, scope access per server or group.

Server Groups

Organize agents into groups. Run operations across entire groups with a single request.

Scheduled Tasks

Cron-based schedules for backups, log rotation, health checks, all automated.

Webhooks & API Keys

Real-time notifications on events. Full REST API for integration into existing workflows.

Full Audit Trail

Every action logged with timestamps, IPs, and full context. Complete accountability.

Passkeys & MFA

WebAuthn/FIDO2 passwordless login. Multi-factor auth and IP whitelisting for MCP.

Contact

Get in touch.

Questions, demos, or enterprise needs? We'd love to hear from you.

Response Time

We typically respond within 24 hours on business days.

Email client opened!

Please send the email from your mail application to complete the message.