AI assistant
Optional, and how to keep it local
Edit this pageOptional, off unless a provider is configured, and local by default.
What it is good at
Questions that would otherwise be several filtered searches and a mental join:
- Which hosts gained a new service this week?
- What is exposed on the DMZ subnet with a critical CVE?
- Summarise what changed on this host since Friday.
- Which certificates expiring in 30 days are on internet-facing hosts?
It has read-only access to your inventory. It cannot enqueue a scan, change a finding's state, edit a host or alter configuration.
Enabling it
The default path is local. Point it at an Ollama you run:
LOOMSCOPE_OLLAMA_BASE_URL=http://127.0.0.1:11434/apiThat is the whole configuration. ollama is the default provider, so
nothing else needs setting and nothing leaves your network.
| Provider | Variable | Where the question goes |
|---|---|---|
ollama | LOOMSCOPE_OLLAMA_BASE_URL | Your hardware. Default. |
anthropic | LOOMSCOPE_ANTHROPIC_API_KEY | Anthropic. Leaves your network. |
openai | LOOMSCOPE_OPENAI_API_KEY | OpenAI. Leaves your network. |
Choosing a remote provider
The remote models are better at this, and that is a real trade an operator may want to make. Make it deliberately, because of what the question carries: to answer "what is exposed on the DMZ with a critical CVE" the assistant sends hostnames, service versions and unpatched CVE identifiers to whoever is serving the model. That is a map of how to attack the estate, sent to a third party, from a product whose main promise is that nothing leaves.
So it is opt-in twice — once to enable the assistant, once to move it off the local default:
LOOMSCOPE_AI_DEFAULT_PROVIDER=anthropic
LOOMSCOPE_ANTHROPIC_API_KEY=sk-ant-...For an air-gapped deployment the remote providers are not an option at all, which is the other reason the local one is the default rather than the fallback.
With no provider reachable, the assistant is not merely hidden — it is not wired up.
Per-organisation model and provider settings live under Settings → AI.
Two honest limitations
It answers from the inventory. Anything Loomscope has not discovered, the assistant cannot know. A host behind a firewall that drops every probe is as invisible to it as it is to the host list — and the assistant will not say "there is nothing there", it will answer about what it can see. Read its answers the way you would read a query result.
A per-organisation monthly token budget applies to hosted providers. When it is exhausted the assistant stops rather than continuing to spend — a surprise invoice is a worse failure than an unavailable feature. The budget is visible in Settings → AI.
Privacy
- Conversations are stored per organisation and scoped like everything else.
- The assistant receives inventory data relevant to the question, not a dump of the database.
- Credentials, API keys and SNMP community strings are never included in what is sent — the same redaction that applies to logs applies here.
- With Ollama, nothing leaves the network at all.
Turning it off
Unset the provider keys and restart the control plane. Existing conversations remain readable; nothing new is sent anywhere.