Parse & explain policies
Paste a security policy, NAT rulebase, or raw XML config. Get a plain-English explanation of what it does, what zones it spans, and what App-IDs it controls: without decoding it line by line yourself.
ADK Cyber AI translates the complexity of PAN-OS into plain English and plain English back into valid config. Paste a rulebase, ask a question, get an answer from an assistant built by someone who has actually run the platform.
No more cross-referencing the TechDocs, sifting through forum threads, or waiting for a TAC case. Ask it in plain English and get a PAN-specific answer.
Paste a security policy, NAT rulebase, or raw XML config. Get a plain-English explanation of what it does, what zones it spans, and what App-IDs it controls: without decoding it line by line yourself.
Upload your rulebase and get a report calling out shadow rules that will never match, overly permissive any-any entries, rules missing security profiles, and App-ID gaps: with specific remediation steps.
Describe what you need in plain English ("allow DNS from trust to untrust using App-ID, log at session end, with an IPS profile") and get the correct CLI or XML config ready to paste into your device.
Paste the output of show session all filter, a counters global dump, or a routing table and get a diagnostic read in seconds: not after 40 minutes on hold with TAC.
Ask follow-up questions, iterate on a config, or walk through a troubleshooting sequence step by step. The assistant holds context across the conversation and is trained to stay grounded in PAN-OS syntax and platform behavior: always verify output before applying to production.
ADK Cyber AI knows the differences between PAN-OS releases 8.x through 11.x, Panorama device-group hierarchy, Prisma Access tenant behavior, and Cortex XDR deployment nuances: so the answer fits your environment.
These are the actual questions that come up at 2am when a change is breaking something and the clock is running.
Walk through IKE phase 1/2 debug output to pinpoint mismatched proposals or DH groups without spending 45 minutes reading RFC docs.
Paste your decryption policy and profile. Get a checklist of the common reasons it silently fails: certificate trust, URL category, traffic direction.
Take your existing port-based rules and get App-ID equivalents with the right application dependencies and implicit ports mapped out.
Work through device-group and template hierarchy decisions: inheritance order, shared scope, and when to break vs. consolidate groups.
Paste your route table and interface config. Get a read on whether asymmetric routing is causing your stateful inspection to drop legitimate return traffic.
Find where profiles are being overridden by device-group or local policy and what traffic is running without the threat prevention you think it has.
ADK Cyber AI's system prompt was engineered by Jack Miller, ADK Cyber's CISO, using 15+ years of hands-on PAN-OS experience. It knows the platform's quirks (asymmetric routing behavior, security profile inheritance, decryption gotchas, and the commands that actually work) not just the TechDocs version of PAN-OS.
PAN-OS 8.x through 11.x, Panorama, Prisma Access, Cortex XDR/XSIAM/XSOAR: the assistant knows the version differences that matter.
It knows what actually breaks in production: not just the idealized deployment model the vendor docs describe.
ADK Cyber AI runs on your Windows PC. Credentials are redacted on your device before anything is sent. On cloud plans, redacted requests pass through ADK Cyber's gateway on Cloudflare (in transit only — not stored) to Anthropic for inference. The Anthropic key lives in the gateway, never on your machine. ADK Cyber only sees your account and usage.
On the Free, Pro, and MAX plans, here is exactly where your configuration goes, and where it does not.
ADK Cyber AI runs locally. Secrets (passwords, pre-shared keys, API keys, private keys) are redacted from your config on your device before anything is sent.
Hosted on Cloudflare. It checks your session and plan quota, then forwards the redacted request. It passes your data through in transit and does not store it. Your Anthropic key lives here, never on your machine.
Processes the redacted request and streams the answer back along the same path, under Anthropic's privacy policy.
On the Local plan, ADK Cyber AI runs against your own local model and nothing leaves your computer at all.
Install from the Microsoft Store on Windows 10 or 11 (64-bit).
The app runs locally on your machine. On Free, Pro, and MAX plans, inference is included — credentials are redacted on device, then relayed through ADK Cyber's gateway (not stored) to Anthropic. Local plan ($5/mo): your own LLM, nothing leaves your PC.
Try it out. No credit card needed.
Bring your own LLM. Your data never leaves your machine.
For engineers who reach for it daily.
Maximum queries, no seat cap.
Estimate your monthly usage and we'll recommend the right plan.
Windows 10/11 · 64-bit · Secrets redacted on device · Config relayed, never stored by ADK Cyber
Paid plans include cloud inference. Monthly caps are sized for a realistic Claude workload. On Pro and MAX you can also switch to Grok in the app when you want cheaper API cost per token for everyday work.
Best for deep PAN-OS troubleshooting and large config analysis. Auto-routing picks the model by complexity.
Available on Pro, MAX, and Owner under Settings → Chat provider. Same monthly query count; usually cheaper for us to serve.
Provider list and exact model IDs can change as we ship updates. In-app selection always reflects what your tier can use right now.
Best practice: Paste only the section of config relevant to your question rather than a full show config running export. This limits unnecessary exposure of your network topology to third-party AI infrastructure.
%LOCALAPPDATA%\Programs\ADK Cyber AI) and run PAN Copilot.exe from there — those copies still auto-update from our download server.ollama pull qwen2.5:14b, and make sure ollama serve is running (port 11434). Check the exact model name with ollama list.
1234). Use the model identifier shown in that panel.
http://localhost:11434/v1 for Ollama, or http://localhost:1234/v1 for LM Studio. Stop at /v1: the app adds /chat/completions itself.
qwen2.5:14b for Ollama, or qwen/qwen2.5-coder-14b for LM Studio).
You must click Save. Test connection only checks your settings; it doesn't store them. If chat still can't reach localhost:11434 after you set up LM Studio, your settings weren't saved, or the Base URL port is wrong (Ollama = 11434, LM Studio = 1234).
Free on Microsoft Store. Secrets redacted on your device; ADK Cyber never stores your config. Create an account, sign in, and you're running in five minutes.