PLATFORM-NATIVE AI

Orion IA — the co-pilot that watches with the operator

Orion IA (OIA) is the artificial intelligence built into OrionEye. It is not a chat window bolted onto a map: it is the layer that coordinates the platform's specialised agents — access control, network topology, cyber threat — and explains what they find, in the operator's language, at the moment it matters.

Multi-LLM orchestration, 8 providers Cloud or local inference, by plan Deterministic detection Pro and above
01

What a co-pilot means here

A cyber and geospatial operator does not lack data. They lack the minute in which to read it. OrionEye already gathers accesses, devices, network topology, satellites, incidents and threat feeds; the difficulty is noticing the one thing, among thousands, that requires a decision now.

That is the job OIA does. It watches continuously, stays silent when there is nothing to say, and when something does not add up it says so — with the facts that led to the conclusion and the action worth taking first.

Why the detection is not left to the model. OIA's findings come from deterministic rules, not from a language model's judgement. A model that decides whether an access is suspicious errs unrepeatably: two runs over the same data give different answers, and a security alert nobody can reproduce is one nobody can refute either. The model's job is the part a rule cannot do — explaining the event to a person, and saying what to do about it.
02

The architecture

One core, several specialised agents, one inference engine that can run in the cloud or entirely on the customer's premises. The operator talks to the core; the core decides which agent answers and which model narrates.

Operator map · panels · USB ORION IA core · scheduler rules · findings response actions Access & Devices zero-trust audit Topology SentraLink · TR-064 Cyber & Threat IOC · SSH · Grace Geospatial map · globe · events Multi-LLM · Cloud Gemini default OpenAI · Claude Mistral · Groq · … Multi-LLM · Local Docker on OmniAgent OS 127.0.0.1:11434 Pro · SaaS Enterprise · on-prem findings actions
cloud inference (Pro) local inference (Enterprise)
03

The first agent: Access & Devices

OIA's security audit agent reads the account's own history — logins, devices, addresses, programs — and looks for facts that are anomalous by definition, not for patterns it has learned. That is a deliberate choice: it works from day one, on an account with no history at all.

Unregistered device

A device key reached the login but matches no device on the account. The clearest signal there is: someone got in from a machine the operator never associated.

Impossible travel

Two accesses too far apart for the time between them. Works with two events and no baseline — nobody travels at 900 km/h.

First access from a country

A country that had never appeared. Stays silent on a short history: the first country an account uses is not new, it is the starting point.

Password guessing

Repeated rejected attempts from one address. Failed logins are recorded for exactly this reason — an agent that cannot see the attempts it repels watches half the problem.

New program on the account

The first time OmniAgent OS, SentraLink or the USB agent uses this account. Usually nothing to do — a note in the record of when it began.

On the map, where it happened

Each located finding becomes a pulsing red reticle on the globe, with the response actions in its card: block the device, force sign-out, archive.

04

How often, and with which engine

Both are the operator's choice, in the Access panel.

CadenceWhen it runsSuited to
On eventAt every new handshake or session, right after the response is sentSmall teams, immediate reaction
ScheduledHourly, daily, weekly or monthlyFleets, periodic review
The two can coexist. Findings are idempotent: the same rule on the same event cannot be recorded twice, so switching cadence back and forth never produces duplicates — and never produces a second alert about something the operator has already seen.
PlanInferenceWhere the analysis runs
Free—Not available — unless a Pro USB key raises the session
ProCloud, Gemini by default or your own API keyPlatform backend
EnterpriseLocal models only, containerised on OmniAgent OSThe operator's own machine
Stated precisely. On Enterprise the engine is constrained to the local model: accesses and topology are never handed to a third-party model vendor, and there is no silent fallback to the cloud. What that guarantees is exactly that — not that the records leave our infrastructure, because authentication is a service we run. Full confidentiality comes with a wholly on-premise installation, not with this setting.
05

When no model answers

OIA keeps working. Every rule carries its own written explanation, and that is what the operator reads when an API quota runs out or the local container is down — the findings are all there, the wording is simply less tailored. A security agent that falls silent because a key expired would be worse than no agent, because people rely on it.