Open source · Apache 2.0

AI Agent that helps run
your factory.

OpenNeko is an open source AI harness built to help run your company. What takes human teams months to do, OpenNeko can automate to deliver instant results. Setup time is days or weeks, not months, and can end up saving a company millions in the first year.

OpenNeko2:14 AM · watching

Line 2's critical spare crosses its reorder point tonight.

Primary vendor is 7 days out · 385 units left · drawing ~172/wk

Drafted 2 Actions · Awaiting Approval

Rush the PO to the backup vendor

PO #4471 · arrives before stock-out

ApproveReject

Brief the plant lead + maintenance on the ETA

Slack · #maintenance

ApproveReject

Approve once, or set a rule and OpenNeko handles it next time.

Made for your operation

It answers the questions your industry runs on.

Ask them in plain language, or set a watcher that checks on a schedule and flags you when the answer changes.

EnergyWhich feeders ran over rating during last night's peak?
Oil & gasWhich wells are trending under plan this week?
ManufacturingWhich line is losing margin to scrap?
Defense techWhich quotes have sat in review past their SLA?
Real estateWhich leases expire in the next 90 days?
InsuranceWhich open claims are aging past 30 days?

In production

Already in use across real operations.

We built OpenNeko for asset-heavy, regulated operations. The deployments below run in defense technology and global commercial real estate, and the numbers come straight from them.

High-density electronics in close detailOn-premDefense Tech · Revenue

A defense technology company

Snowflake · CRM

OpenNeko runs on their own network across Snowflake and CRM, spanning 80B+ records: scoring buying intent, flagging accounts before they churn, triaging the custom-quote queue, and keeping critical components in stock. It drafts the next move; the team approves.

80B+records across Snowflake and CRM
100+active accounts a month
200+custom quotes triaged a month
Corporate glass office towers seen from belowTheir AzureReal Estate · Research

A global commercial real estate firm

Azure Data Lake

Their analysts answer clients' questions across hundreds of millions of data points on property research, investment, and performance. Agents now do the legwork: an analyst asks in plain language, OpenNeko queries the full dataset and drafts the insight with its evidence, and the analyst signs off.

100M+data points behind every answerresearch, investment, performance

Using OpenNeko

How you work with the agent.

Ask anything about your company in plain language. OpenNeko finds the right data, works out the answer, and shows the evidence.

And it watches while you're away: anything urgent lands on your briefing with a response drafted, waiting for your approval. One loop runs it all: observe, understand, decide, act. We call it OUDA.

01ObserveWatches your systems and data around the clock.
02UnderstandWorks out what changed, using your data and your rules.
03DecideDrafts the specific action to take, with its reasoning.
04ActRuns only after you approve, or under a rule you set.
OpenNekoAcme Industrial · live · 7:30 AM
Needs you

Line 2's critical spare crosses its reorder point tonight

Caught 2:14 AM · vendor 7 days out · PO #4471 drafted and waiting

Units shipped today
540↑ 4%
Cash runway
14 mosteady
Shipments in SLA
100%on track

A running read on the business. Anything that needs you sits up top.

Under the hood

Five building blocks that improve with use.

Each block does one job, and they work better together. Every action you approve teaches the agent how you want things done. The full specs live in the docs.

Architecture

A question, answered from your data.

Ask in plain language. OpenNeko's agents break the question down and read your databases through GraphJin, which compiles it straight to SQL and computes the answer where your data already lives.

PostgreSQLMSSQLSnowflakeMongoDBGraphJinOpenNeko
You ask
“Why is the top product running low?”
AI Agents
OpenNeko Agents
Decompose the question and plan the data fetch.
Query Engine
GraphJin
Compiles to optimized SQL across your databases.
PostgreSQL
MSSQL
Snowflake
MongoDB

How it's all wired.

OpenNeko runs as three tiers, split by trust. A small control plane, the worker, holds your secrets, your database access, and the model gateway. Everything that runs model-written or third-party code runs sandboxed beside it, reaching the control plane through one narrow broker.

Security and Governance

Your data and your model stay on your infrastructure.

The agent and its plugins run in a sandbox with no access to your keys or your database. Your model's API key never enters it. Run a local model and no data leaves your network.

Your cloud

Deploy into the AWS, GCP, or Azure account your team already uses. Your data stays inside your own perimeter.

On-prem

Self-host on your own server. It needs only Docker, with no virtualization.

Your model

Use any LLM provider, or a local model through Ollama. With a local model, no data leaves your network.

The threat model

Even hijacked, it can't touch your data.

The agent reads data and documents you don't control and runs them through a model, so OpenNeko treats it as untrusted code. In most systems that agent holds the most access: the keys, the database, the network. OpenNeko flips that: the agent runs sandboxed, and the worker holds everything.

Assume the worst

Say a malicious record fully hijacks the model, and the agent does whatever an attacker wants. Its blast radius is only what it was already given, which is almost nothing.

A fully compromised agent can say things and request actions that still wait for your approval. An uncompromised agent has exactly the same reach, by design.

Default-deny egressPer-run tokenApproval-gated
Secrets: the key in the box is a placeholder; the real value stays in the gateway.
Your database: the sandbox holds no credentials, and every call is bound to one run.
Network egress: denied by default; only the model and the broker are reachable.
Shelling out to curl: only authorized binaries can use the network, and curl isn't one of them, even to an allowed host.
Real-world actions: the agent can only request one, and the request still goes through your approval.

For builders

The full security model, from sandbox policies and key handling to the audit chain, is in the security docs ↗.

Who built it

20 years shipping the three things this product has to get right.

Data engineering

Certified data engineer with years building data systems that handle real volume. The data layer is where OpenNeko earns its trustworthiness.

AI engineering

Deployed AI workflows that added or saved tens of millions to the bottom line. Built agentic systems before agents were a trend.

Enterprise security

Security-audited Fortune 500 companies. Knows what breaks in regulated environments and what compliance requires.

Two ways to start

Install it now, or see the demo first.

Self-host it in a few minutes on your own infrastructure. Or send us the problem you most want solved, and we'll show you how OpenNeko would handle it.