Optimesh Technologies

Every network change, proven safe before it ships.

Not a best guess. A deterministic proof of exactly what your change does to the live network.

Your network, as Optimesh sees it

Every path it touches is computed, instantly.

Caught at the gate, with the exact reason.

Every change, proven before it ships.

● Blocked
app-sg → 0.0.0.0/0
Rulepermit ip any any (line 42)
Effectexposes app-sg to the public internet
Verdict is deterministic. Stopped before merge.
Scroll
Just ask

Describe the change. It writes it and proves it.

No more hand-crafting CLI at 2 a.m. Tell Config Studio what you want in plain English. It finds the fault, writes the vendor-correct fix, and proves it safe on a model of your live network before anything ships.

Intent in, proof out. The plain-English ask becomes a concrete diff plus a deterministic verdict you can trust.
Every fact is checked. The model proposes; the engine decides. It can't talk its way past the gate.
Config Studio · chat
Ask Config Studio to make a change…
Your whole network, one surface

Generate a change on the left. Watch the fleet on the right.

Config Studio · custom dashboardruns inside your network · read-only
{ } Generated change
Auto-filled
Target device
Vendor
Intent
Routers
48 / 48 verified
Switches
71 / 72 online
Firewalls
12 / 12 verified
Cloud SGs
320 / 320 clean
Changes verified · 24h1,284 proven · 7 blocked

Change anything. Break nothing.

Every change to your network runs the gate first — simulated on your live topology, proven safe or blocked, before it ships. Here is a real run.

optimesh · verify --pr 482blocked
$ optimesh verify --pr 482
ingest3 files changed · core-sw-02, edge-fw, k8s/netpol
diagnoseACL drift on Vlan40 — guest VLAN can reach finance
simulate12,481 paths on live topology  ✓ 41ms
checksreachability 8/8 · isolation · loops · acl
BLOCKED. app-sg → 0.0.0.0/0 opens on line 42. The merge is stopped and the exact rule is cited — nothing ships until it's proven safe.
Two products, one engine

Simulation you can build on. Remediation you can trust.

Hammerhead

Offline forwarding-plane simulator

Point it at your configs and ask what a change will do. Reachability and traceroute across every major vendor, answered in milliseconds.

  • 800× faster than the industry standard, 99.93% FIB parity
  • Memory-safe by construction, deterministic, audit-ready
  • CLI, Python SDK, REST API, CI integration and Jupyter
Config Studio

AI diagnosis and verified remediation

When a config breaks, it finds the fault, writes the fix, and proves it safe in simulation — before anyone approves it.

  • 99.6% diagnostic accuracy, 99% reduction in MTTR
  • Small, reviewable diffs — every fix checked before you see it
  • On-prem and air-gapped — nothing ever leaves your network
The gate that never guesses

A verdict backed by math, not a hunch

Config Studio computes exactly what a change does to every path in your network, then shows the routes and rules behind the answer. If it can't prove a change safe, it blocks it.

Deterministic, fail-closed. Any lost reachability, any new loop, any ACL change it can't prove safe fails the build.
Evidence, line by line. Every verdict cites the exact FIB entries, routes, and ACL lines that produced it.
verdict.json
"status": "BLOCKED",
"reason": "ACL flow disposition changed",
"flow": "app-sg → 0.0.0.0/0",
"rule": "permit ip any any (line 42)",
"reachability": "8/8 preserved",
"safe_to_deploy": false
reachable-from-internet · exposure scan
On-prem ACL AWS security groups Azure NSG GCP firewall Kubernetes NetworkPolicy Istio mesh

One graph spans them all. Ask "what can reach my database from the public internet right now," and get a real answer.

One graph, every domain

On-prem to cloud to cluster

Reachability is modeled across on-prem, every major cloud, Kubernetes, and the service mesh as a single graph. A change in one domain can't quietly open a hole in another.

What-if before you touch it. Drain a device, drop a link, withdraw a prefix, preview the impact with zero risk.
Blast radius on every apply. Before-and-after reachability diff, isolated devices, newly unreachable prefixes, gated.

Blast radius, beyond the checkbox

One change. See everything it can break — before it ships.

scroll to trace it
Trust is the product

Your configs never leave your network

Built for the security team that has to sign off. Runs where your network runs, changes nothing without a human.

In-network, air-gap ready

Runs entirely inside your environment. Configs and state stay on your hosts. Works fully offline with a self-hosted model.

Read-only by default

Reads configs; it does not push. Applying is a staged write with a human approval and auto-rollback.

The model sits outside the gate

An AI proposes the fix, but a deterministic engine decides if it's safe. The model can never reach "deploy" on its own.

SSO, RBAC, full audit

OIDC single sign-on, role-based access, and an audit event with before/after hashes on every apply.

Compliance, continuously

Offline checks mapped to STIG, CIS, NERC, HIPAA, and PCI run on every snapshot, no model required.

Drift and snapshots

Baselines your intended state and flags drift the moment a device diverges from the source of truth.

Why now

Four forces are remaking how networks get changed.

Each one alone would justify a new category of tooling. Arriving together, they make verification non-optional.

01

AI agents are managing production infrastructure.

Cisco reports 165,000+ agentic workflow executions monthly. AI is no longer drafting suggestions, it's executing changes on live networks, clusters, and clouds.

02

Nobody is verifying what agents do.

Every major AI agent ships without a deterministic verifier between the model and production. We built the platform that proves an AI-proposed change is safe before it executes.

03

Regulation now requires it.

The EU AI Act, effective August 2026, mandates auditability and human oversight for high-risk AI. Infrastructure agents fall squarely in scope.

04

The trust gap is the bottleneck.

Enterprises want autonomous operations but won't let AI change things unsupervised. Deterministic verification closes the gap: the agent proposes, the verifier proves.

Where the existing answers fall short

What other approaches miss.

ApproachPrevents the bad changeRuns at CI speedVerifies AI outputRuns on your hardware
Monitoring & observabilitypartial
Legacy verification toolspartialpartial
Intent-based networkingpartialpartialpartial
AI copilots & config assistantspartial
Optimesh
What we're building

A platform for autonomous networking, in horizons.

Now · Software

Verify every change

Hammerhead verifies network, Kubernetes, and cloud changes; Config Studio adds AI diagnosis and remediation. Both run on your hardware today.

Next · Hardware

Air-gapped appliances

Purpose-built appliances with local AI inference and deterministic verification, the autonomous network engineer that never sleeps.

Then · Universal

Every agent, any infra

Verification for every AI agent acting on any infrastructure: Terraform, databases, CI/CD, and beyond. The trust layer becomes the standard.

Insights

Notes on the future of network intelligence.

From the Optimesh founders, on verification, the shift to AI-driven operations, and where the field goes next.

Trusted by the teams who can't afford an outage

Customer stories →

Company

Bring certainty to the networks that run the world.

Optimesh builds offline intelligence so the engineers routing the world's traffic know exactly what a change will do before they make it.

Newsroom
Read
The team

Built by people who ship where failure is not an option.

Flight systems for lunar landers. The satellite network connecting the planet. Platforms at billions-of-users scale. The people who spent a decade proving the impossible correct are now doing it for the network.

The climb

From a hard research bet to the trust layer — and what's next.

Proved the impossible fast

An entire network's forwarding plane, simulated in milliseconds. 99.93% parity with the industry standard, 800× faster, on a laptop.

Put it in production

The first network teams run verified change on their own fabrics, on their own hardware. Nothing leaves the building.

Gave the network a brain

Config Studio diagnoses the fault, writes the fix, and proves it safe before a human ever approves it.

Backed to go further

Operators who have run real networks, angel investors, and NVIDIA's startup program bet on the thesis.

Building the trust layer

Deterministic verification for every AI-driven change to any infrastructure. Software today. Purpose-built hardware next.

On the horizon

An autonomous, AI-native IT engineer

Verification is the groundwork. Next: an agent that runs your network end to end — diagnosing, fixing, and proving every change safe on its own, with humans only on the calls that matter.

What we believe

Trustworthy by construction.

Proof over promises

Cross-validated against industry-standard analysis and a live routing stack. Every output deterministic. If the data doesn't support the claim, we don't make it.

Fast enough to live in CI

Whole-fabric simulation in milliseconds. Validation runs on every commit, not once a quarter.

Your network stays yours

Runs entirely on your hardware. On-prem and air-gap ready. Your configs never leave the network.

Hammerhead

Know what a change will do, before you make it.

Point it at a directory of router configs. It builds the forwarding tables for every device, runs your reachability query, and tells you the answer, in under a second. Ships as a single binary. Nothing else to install.

Request access →Read the white paper
Memory-safe by construction · deterministic · audit-ready
hammerhead
800×
Fast enough for every commit
A whole network checked in under a second.
99.93%
Answers you can trust
Matches the analysis your auditors already rely on.
<1s
No waiting on a result
1,280 devices simulated in a single pass.
100%
Reproducible for audits
Same answer every time, so anyone can re-run it.
32 CLI subcommands

One engine. The whole validation loop.

Parse & simulate

Read raw configs, run protocol convergence, build the routing and forwarding tables.

parsesimulateribfib

Query

Ask where a packet goes. Reachability, traceroutes, path joins, IP ownership.

reachabilitytraceroutefind-ip

Analyze

Diff snapshots, detect loops, scan for single points of failure, audit ACLs.

diffloopsfailure-analysis

Verify

Check configs against a YAML compliance DSL. CIS, PCI, and SOC 2 templates included.

policy-checkCISPCI
Protocols & data planes

Models the network you actually run.

Routing protocols

OSPFv2 / v3BGP-4route reflectionEIGRPIS-IS L1/L2RIPv2

Overlays & VPN

MPLS L3VPNBGP L3VPNEVPN 2/3/5VXLANGRE & IPSec

Data plane & L2

NAT / PATswitchport / trunkSTPper-VLAN forwardingBDD headerspace
Surfaces

Meets you where you already work.

CLI

Single static binary. No Docker, no JVM, no server.

Python SDK

Notebook-native. from hammerhead import Hammerhead

REST API

An axum server with 11 endpoints for wiring into anything.

CI pipeline

Gate merges on a FIB diff. Fast enough to run on every commit.

Jupyter

8 tutorial notebooks: BGP analysis, traceroute, change validation, ACL walkthroughs.

vs the standard

Matches industry-standard analysis at 99.93%, 800× faster, fully deterministic and diffable.

Config Studio

Diagnose config faults and generate verified fixes.

Finds the fault, writes the exact CLI patch, and proves it restores reachability before you approve it. In seconds. On your own hardware.

Request access →Powered by Hammerhead
config-studio · ~11s
Fault class
BGP session down · conf. 0.94
Suspect edge-2. Neighbor ASN mismatch on peer 10.0.4.1.
- remote-as 65099
+ remote-as 65020
✓ Hammerhead verified · reachability restored 99.7% · re-simulated offline
✓ Apply✗ Reject
99%
Minutes, not a long night
Incidents resolved before they blow up.
99.6%
Finds the real problem
Pinpoints the fault so no one hunts for it.
100%
Never ships a bad fix
Every fix proven safe before you approve it.
0
Your configs stay yours
Runs on your hardware. Nothing leaves the building.
Mean time to resolution

From alert to verified fix in seconds, not hours.

The slow part of an incident was never the fix. It was finding the fault and trusting the repair. Config Studio does both, and proves it, before you approve.

Manual incident response
~45 min
bisecting configs hop by hop, under pressure
With Config Studio
11s
diagnosed, patched, and proven safe
1
Sanitize
instant
Strips prompt-injection hidden in config comments before the model ever sees them.
2
Diagnose
~6s
Pinpoints the fault and the suspect device against a 32-class taxonomy. No human bisecting the fabric hop by hop.
3
Patch
~2s
Writes the minimal CLI diff, the exact lines you would have typed at 2 a.m.
4
Verify
~3s
Hammerhead re-simulates offline and rejects anything that drops reachability, so the fix you approve is already proven.
Two surfaces

Ask it live, or gate it on every commit.

/studio

Chat + config editor

A chat wired to 15 network tools and an in-session config editor. Ask in plain English; it reasons over your fabric and proposes verified edits inline.

/changes

Pull-request gating

A webhook receiver that runs diagnose → patch → verify on every commit, posts a verdict comment with a deep link, and can gate the merge.

RuleHawk · Free

Audit your firewall rules in seconds.

Paste your config, get a full report. Shadowed rules, overly permissive access, compliance gaps. No sign-up, no install, runs in your browser.

Launch RuleHawk →Fix with Config Studio
Audit reportinstant
Rule #42 is shadowed by Rule #18
permit tcp 10.0.0.0/8 any eq 443 — already matched above
Rule #7 allows any → any on ports 1-65535
3 Critical7 Warnings52 Clean
What it detects

Six categories of firewall risk.

Shadowed rules

Rules that never fire because a broader rule matches first.

Overly permissive access

Wide source and destination ranges, any-any patterns.

Redundant rules

Duplicates that add complexity without changing policy.

Ordering issues

First-match semantics producing unintended outcomes.

Compliance gaps

Missing deny-all defaults and logging gaps.

Unused rules

Zero-hit candidates for cleanup.

Contact

Get in touch.

Questions about Optimesh, your network, or partnering with us? Reach out and you'll get a real person on the founding team, usually within a business day.

Request access → Email the team

Prove your next change safe.

Bring one recurring network incident. We'll diagnose it, patch it, and prove the fix — on your configs, in your environment.

The trust layer for
autonomous infrastructure.

Deterministic verification for every AI-driven infrastructure change.

© 2026 Optimesh Technologies. All rights reserved.Privacy · Terms · Security