Meet CortexShell — Your AI Infrastructure Sysadmin

Your AI Sysadmin.
Your Infrastructure.

CortexShell is an AI infrastructure assistant that knows every server you manage — ask it to check, fix, or automate anything, in any language. Built by practitioners who manage real infrastructure every day and teach the next generation of engineers in university classrooms.

Academic & Industry Background

The team behind CortexShell combines over 25 years of hands-on IT and security experience with active roles in higher education — teaching IT, cybersecurity, and systems administration at university level.

Built for Real Problems

CortexShell started as an internal tool to solve the infrastructure management challenges the team faced daily. After years of real-world use, it became the commercial platform it is today.

10+ Integrations
8 AI Providers
24/7 AI On Call
CortexShell — AI Infrastructure Assistant
you web-03 is returning 502 errors — can you find out why?
CortexShell Checking web-03… running diagnostics on nginx, PHP-FPM, and disk.
✓ nginx running   ⚠ php-fpm: inactive (dead)   ⚠ /var/log: 97% full
CortexShell Root cause: PHP-FPM crashed because /var/log filled up and it couldn't write its PID file. I can clear old logs and restart the service — want me to proceed?
you   Yes, go ahead.
CortexShell Done. Cleared 4.2 GB of logs, restarted php-fpm. web-03 is responding normally. ✓

Like having a senior sysadmin
available 24/7.

Most tools give you access to your servers. CortexShell gives you an AI that understands them. CortexShell knows your entire server inventory — names, IPs, tags, notes, and current state. Describe what you need in any language; CortexShell figures out the commands, runs them, and reports back.

01
Investigate & diagnose

"Why is web-02 slow?" — CortexShell checks CPU, memory, disk, running processes, and error logs to find the root cause.

02
Execute across your fleet

"Restart nginx on all production servers" — CortexShell runs commands in parallel across every tagged server and reports results.

03
Open terminals & act autonomously

CortexShell doesn't just suggest — with your approval it opens a terminal to the right server and executes the fix directly.

04
Explain & advise

"What does this log entry mean?" or "Is this cron safe to delete?" — CortexShell explains and gives an honest recommendation.

05
Security checks & incident triage

CortexShell can review failed logins, exposed services, sudo activity, weak permissions, and suspicious processes, then turn findings into a clear action plan.

06
Create cases in your tools

When an issue needs follow-up, CortexShell can prepare a case or task for OpenProject, Vikunja, or your support workflow with the evidence already summarized.

07
Plan upgrades & bugfixes

Ask which servers need OS updates, product upgrades, reboots, or service fixes. CortexShell checks the current state, suggests the safest sequence, and verifies after changes.

08
Compare configuration drift

CortexShell can compare nginx, SSH, firewall, package, or application configs across 10, 20, or more servers and highlight what changed, where, and why it matters.

09
Coordinate safe rollouts

Deploy apps, copy approved configs, install agents, or restart services in controlled batches. CortexShell tracks each server, pauses on errors, and reports the final state.

10
Maintain the whole fleet

From package versions and missing updates to failed daemons and inconsistent cron jobs, CortexShell turns scattered server checks into one structured maintenance workflow.

11
Work with Terraform, Ansible & Jenkins

CortexShell can help review Terraform plans, prepare Ansible playbooks, trigger Jenkins jobs, inspect failed pipelines, and connect infrastructure changes back to the servers they affect.

"It's like having a colleague who has memorized every runbook, never gets tired, and is always at the keyboard."
— What our users say about CortexShell
Things you can Ask CortexShell:
Check free memory on all staging servers
Find all failed login attempts in the last 24h
Which servers haven't been updated in 30 days?
Deploy my app to web-01 and web-02
Tail the nginx error log on db-primary
Add a cron job to run cleanup.sh every night at 2am
Run a cybersecurity check for exposed SSH and weak permissions
Create a security case in OpenProject for this failed login spike
Create a Vikunja task to patch all Ubuntu 22.04 servers
Check which servers need OS upgrades or reboot after updates
Upgrade nginx safely on production and verify the service
Find the bug causing 502 errors and suggest a fix
Send a GrayLog search query for sudo failures this week
Check Zabbix agent status and repair broken monitoring
Compare nginx configs across 20 web servers and show differences
Copy the approved sshd_config to 10 servers and reload SSH safely
Deploy version 2.4.1 to 20 app servers with rolling restarts
Install Zabbix Agent 2 on 15 Linux servers and verify registration
Check package versions across 10 database servers
Sync the same cron job to 20 servers and report failures
Powered by your choice of AI:
✦ Claude ◎ OpenAI ✧ Gemini ▲ Bedrock ⟁ DeepInfra ⊛ Qwen 🦙 Ollama ◈ LM Studio
Academic Background

Built from research,
not guesswork.

CortexShell didn't emerge from a weekend hackathon. It was born from years of academic work in computer science, IT systems management, and cybersecurity — studying how infrastructure fails, how credentials get exposed, and how teams lose control of their servers.

The design decisions behind every feature — from the access control model to the way secrets are stored — are grounded in academic knowledge of what actually works and why. This is a product built by people who have studied, taught, and researched these exact problems in a university environment.

  • Research-backed security model

    Every security decision is grounded in academic knowledge of attack vectors, credential exposure, and least-privilege principles.

  • Deep IT infrastructure knowledge

    The platform reflects years of studying how real systems are managed, where teams struggle, and what actually reduces operational risk.

  • Theory meets practice

    Academic rigor applied to real-world problems — not just best-practice checklists, but a genuine understanding of the reasoning behind them.

Scales With You

From your first server
to tailored scale.

CortexShell is designed to be useful from day one — whether you're a solo admin who's never touched a Linux terminal, or a seasoned DevOps lead running a multi-team infrastructure operation.

Starter
1 admin · up to 10 servers

No Linux expertise required. CortexShell explains what commands do before running them, guides you through setup, and handles the technical complexity so you can focus on your business.

Professional
2–10 admins · up to 25 servers

Access control matters. Assign each person to only their servers. Session recordings and audit logs create accountability. CortexShell automates the repetitive work across your whole fleet.

Custom
Custom limits · custom features

Vault integration, 2FA, SBOM scanning, GrayLog forwarding, and full audit trails satisfy compliance requirements. Custom feature development can be added around your workflow.

You don't need to pick the right tier upfront — CortexShell grows with you at each step.

Everything your team needs
to run infrastructure

From day-one SSH access to enterprise-grade automation — CortexShell grows with your team.

Secure SSH workspace

Open servers, files, recordings and CortexShell AI in one browser workspace. Your team gets fast access without shared passwords, VPN friction or desktop tools.

prod-web-01
$ CortexShell status --fleet
10 servers online
split terminal · sftp · recording active
AI assistant ready with server context
AI

CortexShell AI assistant

Understands server context, explains commands and helps execute infrastructure work with confirmation before risky actions.

SFTP

File manager

Browse, upload, download, rename and edit files over SFTP directly from the same server workspace.

01

Server inventory

Tag hosts, store notes, assign access and keep credentials protected in Vault.

02

Scheduled jobs

Run recurring tasks with logs, history, manual triggers and email notifications where included.

03

Recordings & audit

Replay terminal sessions and search a clear audit trail for user, server and access events.

04

Security controls

2FA, scoped users, Let's Encrypt SSL, GrayLog/Syslog forwarding, instant access revocation and tamper-evident audit log.

Built for the boring work that actually matters.

CortexShell covers the daily infrastructure loop: connect, investigate, change, record, audit and automate. The interface stays focused, so teams can scan it quickly and keep moving.

  • Browser terminal with split-view sessions
  • Real-time server health — Online/Offline status and latency per host
  • Active sessions overview — see who is connected and to which server, in real time
  • Backup & restore — export and import the full platform state in one click
  • Docker and Linux deployment with bundled HashiCorp Vault
  • Let's Encrypt auto-renewal and custom certificate upload
  • White-label branding — your logo, your name, your chat examples

Real screenshots.
No mockups.

Every screen shown is from a live CortexShell instance managing real servers.

Shared infrastructure.
Zero shared risk.

When multiple people access the same servers, the weakest permissions define your security posture. CortexShell fixes that — one master admin controls the entire access matrix, and every layer of the platform enforces it.

01

Master Admin

One account with unrestricted platform control. Creates all user accounts, registers servers, and defines who can access what. The permission structure can only be changed by the master admin — nobody else.

controls ↓
02

Scoped Users

Each account is whitelisted to an explicit set of servers. Users only see their permitted servers in the interface — production databases, critical infrastructure, or other teams' servers are completely invisible to them.

enforced at ↓
03

Every Layer

Permissions are checked at the terminal, the REST API, and the AI layer. A user asking CortexShell to "run a command on all servers" will only affect their permitted servers — the rest don't exist from their perspective.

master-admin Full platform access
User access assignments
👤 ops-team
web-01 web-02 web-03 db-primary db-replica
👤 dba-team
web-01 web-02 db-primary db-replica db-backup
👤 dev-alice
dev-01 staging-01 web-01 db-primary
No lateral movement

Users cannot pivot to servers they're not assigned to — even from within an open terminal session.

Credentials never exposed

SSH passwords and private keys are stored encrypted. Users authenticate through CortexShell and never see the underlying credentials.

Per-user audit trail

Every terminal command, every CortexShell conversation, every server connection — logged with the user's identity for full accountability.

Instant revocation

Remove a user's access or delete their account — all active sessions terminate within seconds, no stale connections.

Choose your AI engine

CortexShell works with the AI providers you already use — cloud or fully local. Switch at any time without changing how CortexShell works.

OpenAI

GPT-4 and GPT-4o for teams already in the OpenAI ecosystem.

Cloud

Gemini (Google)

Google's Gemini models via API — strong multimodal reasoning and large context windows.

Cloud

AWS Bedrock

Access foundation models hosted in your AWS account — no data leaves your cloud environment.

Cloud

DeepInfra

Serverless inference for open-source models like Llama and Mistral at competitive cost.

Cloud

Qwen (Alibaba)

Alibaba's Qwen models — strong multilingual and code capabilities for international teams.

Cloud

Ollama

Run open-source models locally — complete data privacy, no external API calls.

Local

LM Studio

Local model inference for teams experimenting with custom or fine-tuned models.

Local

Plugs into your
existing stack

CortexShell doesn't replace your tools — it connects them.

Z

Zabbix

Deploy and configure Zabbix Agent 2 on any server directly from CortexShell. Supports TLS/PSK encryption, automatic OS detection, and systemd service management.

Agent Install TLS/PSK Streaming Output
V

HashiCorp Vault

Store all SSH credentials and API keys in Vault. AppRole authentication with automatic token renewal — secrets never touch disk in plaintext.

AppRole Auth KV v2 Auto-Renewal
N

Netmaker VPN

Enroll servers into your Netmaker WireGuard network with a single click. Token-based enrollment with automatic OS detection and progress streaming.

WireGuard Token Enrollment Multi-OS
G

GrayLog / Syslog

Forward all application logs to your centralized log management system. Supports GELF and RFC 5424 Syslog with structured severity levels over UDP.

GELF RFC 5424 UDP
@

SMTP Email

Receive job execution results by email. Configure any SMTP server with TLS/SSL support and custom sender addresses per job.

TLS/SSL Job Alerts Custom Sender
O

OpenProject

Connect your infrastructure management to your project workflows. Link server operations to tickets, track infrastructure work alongside software development.

Project Management Ticketing
V

Vikunja

Sync infrastructure tasks with your Vikunja project board. Create and track tasks directly from CortexShell — keep ops work visible alongside the rest of your team's workload.

Task Management Open Source Self-Hosted
S

OWASP Dependency-Track

Generate a CycloneDX SBOM from the platform's dependencies, upload it to Dependency-Track, and pull back a live CVE vulnerability list with severity ratings.

SBOM CVE Scanning CycloneDX
+

More Coming

Prometheus metrics, PagerDuty alerting, Slack notifications, and Kubernetes cluster management are on the roadmap. Request an integration →

Roadmap

Secure by design,
not by configuration

Security in CortexShell operates at two levels: the platform protects itself, and the platform protects your infrastructure from internal misuse.

System Security

Your data never leaves encrypted

Every SSH password and private key is encrypted at rest using scrypt-derived keys. Secrets can be moved entirely to HashiCorp Vault — CortexShell never holds plaintext credentials anywhere.

  • Encrypted at rest

    All credentials encrypted with scrypt before storage

  • Vault-backed secrets

    Delegate all secrets to HashiCorp Vault KV v2 — nothing on disk

  • JWT authentication

    Short-lived tokens with immediate revocation support

  • TOTP two-factor authentication

    RFC 6238 compliant 2FA with backup codes and admin-managed reset

  • Automated SSL / HTTPS

    Let's Encrypt certificate provisioning with auto-renewal — HTTPS enforced with zero manual config

  • Full audit via Syslog

    Every action forwarded to your centralized log aggregator

Access Security

Control who touches what — and prove it

In shared environments, CortexShell acts as a strict gatekeeper. The master admin defines the access rules; the platform enforces them at every layer — terminal, API, and AI.

  • Single governance point

    One master admin controls all accounts and all access rules

  • Server-level isolation

    Users are whitelisted per server — unlisted servers are invisible

  • AI enforces boundaries

    CortexShell respects access rules — restricted users can't bypass them via AI commands

  • Session recordings

    Every terminal session recorded and replayable — proof of exactly what was done and by whom

  • Per-user activity log

    Full audit trail — every command, connection, and conversation tied to an identity

Built for teams that
run real infrastructure

From solo engineers to enterprise MSPs — CortexShell adapts to how your team works.

No Linux skills needed

First-Time Admins

Ask CortexShell what you want in any language — it confirms before acting and explains any output you don't recognize. A learning tool and a management tool at the same time.

Teams

DevOps Teams

Centralize server access and eliminate shared SSH keys. Every session is recorded, every action logged. CortexShell handles the routine so engineers stay focused on what matters.

Service Providers

Managed Service Providers

Each customer gets their own account scoped to only their servers. White-label your instance with your logo and name. Full audit trail and session recordings for SLA compliance — no customer sees another's infrastructure.

Compliance

Security-Conscious Organizations

Vault, 2FA, session recordings, audit logs, and SBOM scanning satisfy most compliance requirements out of the box. No plaintext credentials. Every action tied to an identity.

Small teams

Small Teams Moving Fast

CortexShell handles log checks, updates, restarts, and cron jobs so you don't have to. One engineer can manage dozens of servers without breaking focus or writing runbooks.

Remote-first

Remote & Distributed Teams

Browser-based, no VPN client needed. Your team across multiple countries gets identical access from any machine and any OS — just a browser and their credentials.

CortexShell vs. the alternatives

Most tools give you one piece of the puzzle. CortexShell gives you all of it — with AI baked in.

Feature CortexShell Teleport Bastillion JumpServer Guacamole
AI assistant (built-in) ✓ Built-in CortexShell
SFTP file manager Upload only Partial
Session recording & playback Audit logs
Split terminal view ✓ Up to 3 panes Composite
HashiCorp Vault secrets ✓ Native
Core access without target agent ✓ Pure SSH ✗ Needs agent SSH keys ✗ Needs agent
Lightweight deployment ✓ Single process ✗ Complex Moderate ✗ Complex ✗ Complex
Local LLM support ✓ Ollama, LM Studio
2FA / MFA (TOTP) ✓ Built-in
Tamper-proof license system ✓ Ed25519 signed
Self-hosted
Built-in SSL / Let's Encrypt ✓ Auto-renew External External
Backup & restore ✓ One click Manual Manual
White-label branding ✓ Logo, name, prompts Partial

Simple, host-based pricing

Monthly plans with clear server, user and job limits. Save 20% with yearly billing.

Starter
25 /month
Up to 10 servers
  • ✓ Web SSH terminal (split-view)
  • ✓ CortexShell AI assistant
  • ✓ Server management & tagging
  • ✓ Scheduled jobs (5 jobs)
  • ✓ Conversation history
  • 1 user account
  • ✓ Let's Encrypt Certbot
  • ✓ Custom SSL certificate
  • ✓ HashiCorp Vault integration
  • ✓ Last 7 days recordings
  • ● All updates & new features included
Get Started
Business
160 /month
Up to 100 servers
  • ✓ Everything in Professional
  • ✓ Scheduled jobs (50 jobs)
  • ✓ Up to 30 user accounts
  • GrayLog / Syslog forwarding
  • ✓ All recordings retained
  • ✓ Dedicated onboarding session
  • ✓ Priority chat & email support
  • ● All updates & new features included
Get Started
Custom
Custom
Tailored to your needs
  • ✓ Everything in Business
  • ✓ Limits adjusted to your requirements
  • ✓ Custom feature development
  • ▸ Scope, support and limits are agreed based on your needs
🏛 Public sector & one-time billing

Prefer a single invoice over a subscription? CortexShell is available as a perpetual license — pay once for the software, then optionally renew updates annually. The first year of updates is included at no extra cost. Suitable for government bodies, municipalities, and organizations with procurement policies that require one-time purchases.

Contact Sales
Prices shown exclude VAT.

How much is your team spending on repetitive tasks?

Adjust the sliders to match your setup and instantly see your potential savings with CortexShell.

Number of servers 20
Engineers / admins 3
Hours/week on repetitive tasks per person 8 h
Average hourly rate €60
Hours saved / week
Saved / month
Return on investment

Based on 40% reduction in repetitive task time — consistent with published IT operations research.

Ready to take control of your infrastructure?

Book a 1:1 demo and see CortexShell in action on your own infrastructure.

Common questions

What counts as a "server"?

Any host you add to CortexShell with SSH credentials — physical servers, VMs, cloud instances, or containers with SSH exposed. The count is based on configured hosts, not concurrent connections.

Can I bring my own AI API keys?

Yes. You provide your own Anthropic, OpenAI, Ollama, or LM Studio credentials. CortexShell stores them encrypted and never shares them. For local providers (Ollama, LM Studio), no external API calls are made at all.

Is CortexShell self-hosted?

Yes — CortexShell runs entirely on your own infrastructure. You can deploy it as a Docker container on any Linux host with a single docker compose up, or run it directly on Linux with Node.js + PM2. All data is stored in a local volume — migrating to a new server takes minutes. No cloud dependency, no SaaS lock-in.

How are SSH credentials secured?

Passwords and private keys are encrypted at rest using scrypt-derived keys before being written to the database. If you enable the HashiCorp Vault integration, credentials are moved out of the local database entirely.

Can I upgrade or downgrade my plan?

Yes, at any time. Upgrades take effect immediately; downgrades apply at the end of the current billing period. If you exceed your server limit after downgrading, existing servers remain accessible but new ones cannot be added until the count is reduced.

How does the admin hierarchy work?

There is one master admin account with full platform control. The master admin creates all other user accounts and assigns each one to specific servers. Regular users only see and can interact with their assigned servers — via terminal, API, or AI. Access changes take effect instantly; the master admin can revoke any account at any time.

Is there an API for external integrations?

CortexShell exposes a full REST API used by the web frontend. Custom plan customers can request API documentation and authentication tokens for integration into existing DevOps pipelines and dashboards.

Is there a backup and restore option?

Yes. CortexShell includes a Backup & Restore tab in Settings. A full platform snapshot — servers, users, jobs, credentials, and configuration — can be exported in one click and re-imported on a new host. Migrations between servers take minutes, not hours.

Can I monitor server availability in real time?

Yes. The Servers list includes a live status column that pings each host and shows Online/Offline state with latency in milliseconds. The Active Sessions panel shows who is currently connected and to which server, updated in real time.

How modern teams
run their infrastructure

Practical guides and real-world perspectives on server management, security, and automation.

AI & Automation May 2026

Your AI sysadmin never sleeps: how CortexShell changes daily server operations

Most infrastructure teams spend a significant chunk of their week on repetitive tasks — checking disk space, restarting services, reviewing logs. CortexShell doesn't replace your engineers. It handles the boring work so they can focus on the work that matters. Here's what that looks like in practice at a team managing 30 Linux servers.

Read article
Security April 2026

Zero shared passwords: eliminating credential risk in a multi-admin environment

Shared root passwords are one of the most common security failures in small and mid-size IT teams — not because people are careless, but because the tooling makes it too easy to take shortcuts. HashiCorp Vault integration and per-user access control change that equation entirely. No one ever sees the credentials they use.

Read article
Compliance March 2026

Session recording as a compliance tool: why every terminal action should be replayable

When an incident happens — a misconfiguration, a data change, a service outage — the first question is always "what exactly was done, and by whom?" Session recordings answer that question precisely. We look at how audit-ready organisations are using terminal playback to meet internal and regulatory requirements without adding process overhead.

Read article
Scaling February 2026

From one server to a hundred: scaling infrastructure without scaling headcount

The gap between a 5-server setup and a 50-server operation isn't just technical — it's organisational. Teams that grow without the right tooling end up with scattered SSH keys, undocumented runbooks, and two people who "know how everything works." Scheduled jobs, fleet-wide AI commands, and a central audit trail close that gap before it becomes a crisis.

Read article
DevOps January 2026

The browser-based terminal: why your team should never install PuTTY again

SSH clients have barely changed in 20 years. PuTTY, MobaXterm, Terminal.app — they're all fine tools, but they tie access to a specific machine, a specific OS, and a specific person's configuration. A browser-based workspace means every engineer on your team has identical access from any device, with session recording and AI assistance built in from day one.

Read article

We're here to help —
and we listen

Report a bug, ask a question, or suggest the next feature. Every message goes directly to the team.

Support & Feature Request

Send a bug report, configuration question, support request, or product idea from one place.

Or email us directly: [email protected]