ADK Cyber · ADK Cyber AI

Meet ADK Cyber AI the assistant that actually knows PAN-OS.

ADK Cyber AI translates the complexity of PAN-OS into plain English and plain English back into valid config. Paste a rulebase, ask a question, get an answer from an assistant built by someone who has actually run the platform.

PAN-OS 8.x–11.x aware Panorama · Prisma · Cortex Local app · secrets redacted on device Free on Microsoft Store
Capabilities

Five things PAN engineers do every day, but faster.

No more cross-referencing the TechDocs, sifting through forum threads, or waiting for a TAC case. Ask it in plain English and get a PAN-specific answer.

Parse & explain policies

Paste a security policy, NAT rulebase, or raw XML config. Get a plain-English explanation of what it does, what zones it spans, and what App-IDs it controls: without decoding it line by line yourself.

Audit for shadow & problem rules

Upload your rulebase and get a report calling out shadow rules that will never match, overly permissive any-any entries, rules missing security profiles, and App-ID gaps: with specific remediation steps.

Generate PAN-OS config snippets

Describe what you need in plain English ("allow DNS from trust to untrust using App-ID, log at session end, with an IPS profile") and get the correct CLI or XML config ready to paste into your device.

Troubleshoot CLI output

Paste the output of show session all filter, a counters global dump, or a routing table and get a diagnostic read in seconds: not after 40 minutes on hold with TAC.

AI chat that knows PAN-OS syntax

Ask follow-up questions, iterate on a config, or walk through a troubleshooting sequence step by step. The assistant holds context across the conversation and is trained to stay grounded in PAN-OS syntax and platform behavior: always verify output before applying to production.

Version & platform aware

ADK Cyber AI knows the differences between PAN-OS releases 8.x through 11.x, Panorama device-group hierarchy, Prisma Access tenant behavior, and Cortex XDR deployment nuances: so the answer fits your environment.

Built for real scenarios

The situations it was built for.

These are the actual questions that come up at 2am when a change is breaking something and the clock is running.

IPSec tunnel down after upgrade

Walk through IKE phase 1/2 debug output to pinpoint mismatched proposals or DH groups without spending 45 minutes reading RFC docs.

Decryption policy not firing

Paste your decryption policy and profile. Get a checklist of the common reasons it silently fails: certificate trust, URL category, traffic direction.

App-ID migration from port-based

Take your existing port-based rules and get App-ID equivalents with the right application dependencies and implicit ports mapped out.

Panorama template stack questions

Work through device-group and template hierarchy decisions: inheritance order, shared scope, and when to break vs. consolidate groups.

Asymmetric routing drops

Paste your route table and interface config. Get a read on whether asymmetric routing is causing your stateful inspection to drop legitimate return traffic.

Security profile inheritance audit

Find where profiles are being overridden by device-group or local policy and what traffic is running without the threat prevention you think it has.

Built by someone who runs it

Not a generic chatbot. A PAN-trained assistant.

ADK Cyber AI's system prompt was engineered by Jack Miller, ADK Cyber's CISO, using 15+ years of hands-on PAN-OS experience. It knows the platform's quirks (asymmetric routing behavior, security profile inheritance, decryption gotchas, and the commands that actually work) not just the TechDocs version of PAN-OS.

Domain knowledge baked in

PAN-OS 8.x through 11.x, Panorama, Prisma Access, Cortex XDR/XSIAM/XSOAR: the assistant knows the version differences that matter.

Grounded in real operational reality

It knows what actually breaks in production: not just the idealized deployment model the vendor docs describe.

Redacted on your device. Relayed, never stored.

ADK Cyber AI runs on your Windows PC. Credentials are redacted on your device before anything is sent. On cloud plans, redacted requests pass through ADK Cyber's gateway on Cloudflare (in transit only — not stored) to Anthropic for inference. The Anthropic key lives in the gateway, never on your machine. ADK Cyber only sees your account and usage.

How your data is handled

Redacted on your device. Relayed, never stored.

On the Free, Pro, and MAX plans, here is exactly where your configuration goes, and where it does not.

1

Your machine

ADK Cyber AI runs locally. Secrets (passwords, pre-shared keys, API keys, private keys) are redacted from your config on your device before anything is sent.

2

ADK Cyber gateway

Hosted on Cloudflare. It checks your session and plan quota, then forwards the redacted request. It passes your data through in transit and does not store it. Your Anthropic key lives here, never on your machine.

3

Anthropic

Processes the redacted request and streams the answer back along the same path, under Anthropic's privacy policy.

✓ Secrets redacted on your device ✓ Configuration never stored by ADK Cyber ✓ Key held in the gateway, not the client

On the Local plan, ADK Cyber AI runs against your own local model and nothing leaves your computer at all.

Install

Three steps to run.

Install from the Microsoft Store on Windows 10 or 11 (64-bit).

  1. Open the Microsoft Store using the button above (latest).
  2. Click Get (or Install) and wait for ADK Cyber AI to finish installing.
  3. Launch ADK Cyber AI, sign in, and pin it to your taskbar for quick access.
Pricing

Free on Microsoft Store. Pay only for the plan that fits how you work.

The app runs locally on your machine. On Free, Pro, and MAX plans, inference is included — credentials are redacted on device, then relayed through ADK Cyber's gateway (not stored) to Anthropic. Local plan ($5/mo): your own LLM, nothing leaves your PC.

Free
$0 / month

Try it out. No credit card needed.

  • 10 queries / week (~40/mo)
  • ADK Cyber API key included
  • Full chat interface
  • Config paste & file upload
  • Conversation history (local)
  • Powered by Claude Haiku: fast & efficient
  • Config pastes >8,000 chars count as 3 queries
Local
$5 / month

Bring your own LLM. Your data never leaves your machine.

  • Use your own local LLM (Ollama, LM Studio, etc.)
  • Every query runs on your machine
  • No cloud AI: nothing sent to our servers
  • Full chat, config paste & file upload
  • Conversation history (local)
  • Best-effort responses (cloud is the supported experience)
  • Cancel anytime
MAX
$50 / month
31× more queries than Free

Maximum queries, no seat cap.

  • Up to 1,250 queries / month
  • ADK Cyber API key included
  • All Pro features per seat
  • Single invoice for procurement
  • Priority email support
  • Cancel anytime

Not sure which plan fits?

Estimate your monthly usage and we'll recommend the right plan.

Queries per day 5
Engineers on your team 1
Recommended plan
Free
Get started

Windows 10/11 · 64-bit · Secrets redacted on device · Config relayed, never stored by ADK Cyber

Models

Claude by default.
Grok when you want lower cost per token.

Paid plans include cloud inference. Monthly caps are sized for a realistic Claude workload. On Pro and MAX you can also switch to Grok in the app when you want cheaper API cost per token for everyday work.

Claude (Anthropic)

Default routing

Best for deep PAN-OS troubleshooting and large config analysis. Auto-routing picks the model by complexity.

  • Haiku Short, simple questions
  • Sonnet Normal work and config pastes
  • Opus Large pastes and complex analysis
  • Caps Pro 500 / MAX 1,250 sized near break-even on this mix
~$3 / $15 Sonnet input / output per 1M tokens

Grok (xAI)

Lower $/token

Available on Pro, MAX, and Owner under Settings → Chat provider. Same monthly query count; usually cheaper for us to serve.

  • Best for Everyday Q&A and lighter config work at higher volume
  • Output Often ~2–2.5× cheaper than Claude Sonnet for similar-length answers
  • Quota Still counts 1:1 against your plan — no separate Grok pool
  • Switch Change providers anytime in Settings on paid plans
~$2 / $6 Grok 4.5-class input / output per 1M tokens

What this means for you

Fixed monthly pool No metered overages from ADK Cyber. Caps stay honest for Claude-heavy use.
When to use Grok Speed and volume matter more than max Claude reasoning depth.
When to use Claude Large rulebase audits, deep diagnostics, and hard PAN-OS edge cases. Free stays Haiku-only; Local never leaves your machine.

Provider list and exact model IDs can change as we ship updates. In-app selection always reflects what your tier can use right now.

FAQ

Common questions.

Is this just ChatGPT with a PAN-OS prompt?
It uses a large language model under the hood, but what makes it useful is the system prompt: which was engineered by someone with 15+ years of hands-on PAN-OS experience. The prompt encodes version-specific behavior, known gotchas (asymmetric routing, security profile inheritance, decryption quirks), and real operational context that a generic assistant won't have. The difference shows up immediately when you paste actual config output.
Do I need my own Anthropic or xAI API key?
No. On Free, Pro, and MAX plans, cloud inference is included — you sign in and the app handles the rest. Secrets in your config are redacted on your device first; the redacted request is relayed through ADK Cyber's gateway (which does not store it) to Anthropic or, on paid plans when you select Grok, to xAI. Provider keys live in the gateway, never on your machine. ADK Cyber's account server sees only your email, session token, and subscription status — never your config.
Why choose Grok instead of Claude?
Both go through the same redaction + gateway path and count against the same monthly query limit. Claude (Sonnet/Opus routing) is the deeper default for hard PAN-OS work and large config analysis. Grok is usually cheaper per token on the API (especially output), so it is a good default for high-volume everyday questions when you want to stretch the same Pro or MAX quota. You can switch providers in Settings anytime on paid plans. See Models for the cost comparison.
Is it safe to paste my production firewall config?
Significantly safer than a hosted cloud tool. The app runs locally on your machine. Credentials (passwords, shared secrets, pre-shared keys, API keys, private keys) are automatically redacted on your device before anything is sent. Your redacted request — which still includes network topology, IP addresses, and configuration structure so the AI can reason about them — is relayed through ADK Cyber's inference gateway (pass-through, not stored) to Anthropic, subject to Anthropic's privacy policy. ADK Cyber does not store your configuration.
⚠️

Best practice: Paste only the section of config relevant to your question rather than a full show config running export. This limits unnecessary exposure of your network topology to third-party AI infrastructure.

Which PAN-OS versions and products does it cover?
PAN-OS 8.x through 11.x, Panorama (including device-group and template hierarchy), Prisma Access (tenant and remote-network configuration), Cortex XDR, XSIAM, XSOAR, Strata Cloud Manager, and Prisma Cloud. If your question is version-specific, say which version you're on and the answer will reflect it.
Are there any usage limits?
Yes. Free tier: 10 queries/week (~40/month), powered by Claude Haiku. Pasting a config over 8,000 characters counts as 3 queries. The app warns you before you submit. Pro: up to 500 queries/month with full model routing (Claude Sonnet for normal queries, Opus for large config analysis; Grok available on paid plans) at $20/mo: up to 12× more than free. MAX: up to 1,250 queries/month at $50/mo: up to 31× more than free. Limits are sized so a typical Anthropic-routed workload sits near API break-even at the subscription price; there are no per-query charges from ADK Cyber on any plan. Choosing Grok as your provider usually costs us less per token, so the same quota goes further on our side when you prefer it. The app shows your live usage count so you always know where you stand.
Can my whole team use it?
Yes: the MAX plan has no seat cap. Each engineer installs their own copy from the Microsoft Store, creates their own account, and shares the 1,250 query/month pool. For a managed deployment or enterprise billing, reach out to jmiller@adkcyber.com.
What operating systems does it run on?
The current release is a native Windows 10/11 (64-bit) desktop app — no browser tab required (it uses the built-in WebView2 runtime that ships with Microsoft Edge). Install from the Microsoft Store. A macOS build is in progress.
The update banner won't go away — what do I do?
If you installed from the Microsoft Store, open the Store app and check Library for pending updates. Still stuck? Uninstall ADK Cyber AI from Windows Settings, then reinstall from the Store listing. If you're on a legacy ZIP install from before the Store release, extract the latest build to a folder you own (for example %LOCALAPPDATA%\Programs\ADK Cyber AI) and run PAN Copilot.exe from there — those copies still auto-update from our download server.
How do I run it with my own local LLM (Local plan)?
On the Local plan, ADK Cyber AI runs against any OpenAI-compatible model server on your own machine: Ollama, LM Studio, llama.cpp, vLLM, so nothing you type ever leaves your computer.

1. Start a local model server and load a model.
Ollama: install from ollama.com, run ollama pull qwen2.5:14b, and make sure ollama serve is running (port 11434). Check the exact model name with ollama list.
LM Studio: install from lmstudio.ai, download a model, then open the Developer (Local Server) tab, load the model, and switch the server to Running (port 1234). Use the model identifier shown in that panel.

2. Connect the app. Open Settings → Chat Provider → My local LLM and enter:
Base URL: http://localhost:11434/v1 for Ollama, or http://localhost:1234/v1 for LM Studio. Stop at /v1: the app adds /chat/completions itself.
Model: the exact name from your server (e.g. qwen2.5:14b for Ollama, or qwen/qwen2.5-coder-14b for LM Studio).
API key: leave blank: local servers don't require one.

3. Click Test connection, then Save, and send a message: it now runs entirely on your hardware.
⚠️

You must click Save. Test connection only checks your settings; it doesn't store them. If chat still can't reach localhost:11434 after you set up LM Studio, your settings weren't saved, or the Base URL port is wrong (Ollama = 11434, LM Studio = 1234).

Ready to spend less time fighting the platform?

Free on Microsoft Store. Secrets redacted on your device; ADK Cyber never stores your config. Create an account, sign in, and you're running in five minutes.