The OneIQ platform

From infrastructure visualization to governed AI access for diverse IT environments.

OneIQ visualizes the estate. Infrastructure Pulse keeps it live. AI Studio lets you query it. OneIQ ICG makes it addressable by any AI agent. Here's how they fit together.

Free continuous telemetry with Infrastructure Pulse
Agentless — no attack surface added
ISO/IEC 27001 certified (BSI)
Data stays in the customer's environment

Platform components

Core · Assessment & discovery

OneIQ

Starts with a secure RVTools transfer, then visualizes the IT environment - every host, VM, and workload, how they depend on each other, and what each one costs to run, replace, or migrate.

See OneIQ ↓
Free · Continuous telemetry

OneIQ Infrastructure Pulse

A context collector that feeds OneIQ ICG, making infrastructure queryable by AI models — a continuous, 7-day rolling window of live telemetry, 24×7×365, at no cost. Keeps a current picture of the estate without waiting on the next assessment.

See Infrastructure Pulse ↓
Optional add-on · LLM

OneIQ AI Studio

An optional LLM layer on top of OneIQ's discoveries - query and interact with what OneIQ has found across the estate in plain language, without building your own AI integration.

See AI Studio ↓
Governed AI access

OneIQ Infrastructure Context Gateway (ICG)

The layer that makes the estate addressable by AI — deploys inside your perimeter, normalises every data source, and governs exactly what any AI agent can see and query.

See OneIQ ICG ↓

The core product

OneIQ

See the estate before you touch it.

OneIQ starts with a secure RVTools transfer - no agents, no live connection required to get started. From that export, OneIQ builds a visual map of the IT environment: every host, VM, and workload, how they depend on each other, and what each one costs to run, replace, or migrate.

Secure RVTools transfer

Upload an existing RVTools export through an encrypted, access-controlled channel - no agents installed, no live connection to the estate required to get the picture started.

Visualization of the IT environment

Every host, VM, and workload rendered as a single visual map of the estate - the starting picture every other OneIQ product builds on.

OneIQ topology map showing application, service, pod, cluster, node, and persistent volume layers with cost and utilization detail for a selected application

Identify dependencies

See how workloads, storage, and network paths depend on each other before you plan a migration, refresh, or change window.

OneIQ dependency view showing an Azure Public IP with dashed lines tracing its dependencies across virtual machines, disks, and storage accounts

Cost impacts

Every host and workload enriched with cost data, so a refresh, migration, or consolidation decision comes with a dollar figure attached.

OneIQ historical cost analysis showing average daily cost trends and a cost breakdown by platform across Microsoft Azure, VMware, AWS, and Nutanix

One map, every platform

AWS, Azure, Google Cloud, VMware, and Nutanix rendered side by side - a single view of the estate instead of a separate dashboard per platform.

OneIQ topology map showing AWS, Google Cloud, and Azure resources side by side, with a selected VM scale set detail panel

Every entity, cataloged

Clusters, hosts, subnets, storage, and virtual machines across every platform - searchable and filterable in one inventory.

OneIQ entity catalog table showing subnets across AWS, Nutanix, and VMware with an entity type filter open

Rightsizing recommendations

OneIQ flags oversized instances and shows the optimized alternative side by side, with the annual savings attached.

OneIQ downsize recommendation showing a current versus optimized Azure virtual machine with CPU and memory utilization charts and annual net savings

Estate-wide rollups

Cost, VM counts, Kubernetes footprint, and hardware age rolled up into a single view of the whole estate.

OneIQ overview dashboard showing cloud insights, VM breakdown by platform, Kubernetes hosting breakdown, and hardware lifecycle

Scoped, secure workspaces

Control exactly which platforms and environments are visible in a workspace, and scramble sensitive names and IP addresses when needed.

OneIQ change access policy dialog showing selected platforms and a data visibility toggle to scramble sensitive asset names and IP addresses

The always-on add-on

OneIQ Infrastructure Pulse

Turns a snapshot into real-time telemetry.

Infrastructure Pulse is a context collector — it continuously senses telemetry across the estate on behalf of OneIQ ICG, keeping a live, 7-day rolling window that ICG draws on to answer AI queries, 24×7×365, included at no charge with every assessment. No agents on endpoints, no waiting for the next assessment to know what changed.

Continuous, not point-in-time

A rolling 7-day window of live telemetry replaces the "how stale is this data" question that comes with any one-time assessment.

Free, always-on

Included automatically with every assessment, 24×7×365, at no additional charge. It's the free tier of the full OneIQ platform.

Feeds everything above it

As a context collector, Pulse continuously feeds OneIQ ICG — the context gateway — so AI agents can query live infrastructure telemetry instead of a stale snapshot.

Optional add-on

OneIQ AI Studio

Ask OneIQ's discoveries a question.

OneIQ AI Studio is an optional LLM layer on top of OneIQ's assessment data. Instead of digging through reports and dashboards, query and interact with what OneIQ has discovered across the estate in plain language - no AI integration to build yourself.

Natural-language queries

Ask questions about the estate directly - capacity, lifecycle, cost, dependencies - and get an answer shaped from OneIQ's own discoveries, not a raw export.

No integration to build

The LLM layer is included with OneIQ - point and ask. Nothing to wire up, host, or maintain on your side.

Works across every discovery

Query results from OneIQ assessments, Infrastructure Pulse telemetry, and Assessment Factory reports - one interface over everything OneIQ has found.

Governed AI access

OneIQ Infrastructure Context Gateway (ICG)

Three things OneIQ ICG does. Nothing else does all three.

OneIQ ICG is an infrastructure context gateway with an MCP interface — it speaks the Model Context Protocol, so any AI or LLM (a frontier model, a private model, a copilot) can query it the same standard way, with no proprietary integration to build. No MCP lock-in: any MCP-compatible client can connect, today or whichever one your customer standardises on next. Most tools give you data, or access, or a security boundary. OneIQ ICG provides all three in a single deployable layer — inside the perimeter, not outside it.

Deploys inside the perimeter

OneIQ ICG runs as an infrastructure context gateway with an MCP interface inside the customer's own environment. There is no cloud hop, no external dependency, and no data leaving the boundary. The estate telemetry never moves — the intelligence comes to it.

Normalises the estate

OneIQ ICG reads from every vendor and platform — virtual, HCI, physical, cloud, containerised — and translates fragmented, inconsistent telemetry into a single enriched picture. No vendor owns the format. No integration breaks when a platform changes.

Governs AI access

Agent Zones define exactly what each AI agent can see and query — scoped by environment, function, or risk level. The security team approves the boundary once. Every AI query that follows operates within it, with no path to unfiltered data.

Five layers. One governed output.

OneIQ sits between the raw infrastructure estate and everything that consumes it. Each layer has one job - together they turn scattered telemetry into answer-shaped context any agent or analyst can use immediately.

VALUE RISES AI FACTORY answer-shaped, lower-cost, faster AI agents & copilots Knowledge & retrieval Analytics & dashboards Automation & workflows Private LLMs Frontier models OneIQ – Infrastructure Context Gateway (ICG) one bracketed layer · what OneIQ owns Gateway / Delivery two ways to consume the same governed intelligence Direct gateway access Assessment Factory Agent Zones & Governance customer controls what AI sees; answer-shaped responses Customer-controlled scope Token-efficient Enrich raw telemetry becomes costed, decision-ready Chipset Cloud pricing Lifecycle & warranty Normalize & Model unify heterogeneous telemetry into one consistent model One unified infrastructure model Observe / Collect agentless or cloud-native collectors across all platforms Agentless Cloud-native Point-in-time or continuous CUSTOMER INFRASTRUCTURE ESTATE any vendor, any age, anywhere Physical Virtual HCI Cloud Kubernetes Storage Operating Systems

OneIQ sits between the raw infrastructure estate and everything that consumes it. Each layer has one job - together they turn scattered telemetry into answer-shaped context any agent or analyst can use immediately.

The enrichment layer

Your telemetry is one input among many.

OneIQ cross-references your customer's raw data with its own maintained libraries - cloud pricing, processor generations, hardware age, software support, power and energy - before the output ever reaches an agent or analyst.

Your telemetry YOURS Exchange rates Cloud pricing Processor generations Hardware age Software support Power & energy Your telemetry is one input among many – OneIQ maintains the libraries that make cross-referencing smart. OneIQ Infrastructure Context Gateway (ICG) match cost date scope ENRICHED OUT cost-enriched, decision-ready

Agent Zones

Scoped access. Not open access.

Agent Zones are the governance layer inside OneIQ ICG. Each zone defines what an AI agent can see — by environment, by function, by risk level. The security team approves the scope once; every AI query that follows operates within it. No unrestricted access. No prompt injection into raw telemetry.

Read-only by default
Per-zone encryption boundaries
Approved once, enforced always
Agent query routing
Allowed Capacity summary — prod virtualisation zone
Allowed Lifecycle exposure — all platforms
Scoped Cloud estate — read-only, DR zone only
Outside zone Raw config data — not in approved scope
Outside zone Credential store — not in approved scope
AES-256 • Zero-trust over HTTPS • Per-zone boundary

Token cost is a real line item

Every AI call costs money. Unscoped agents burn most of it.

When an AI agent has no context layer, it reads the entire estate to answer a single question — thousands of hosts, hundreds of thousands of metric rows, tens of thousands of event records. That is a lot of tokens per call, multiplied by every agent, every workflow, every day. OneIQ ICG's Agent Zones scope each call to exactly what the question needs. Same answer, a fraction of the tokens.

Illustrative example - not a benchmark
Point an agent at the raw estate
hosts: 4,212 records...
vm_inventory: 38,904 rows...
metrics.cpu.5m: [88,91,84,...]
storage.luns: 1,377 entries...
net.flows: 210,440 lines...
events.raw: 96,500...
... everything, unscoped ...
~38,000 tokens / call
Ungoverned and over-reaching. The model burns its budget hunting the whole estate for the one thing that matters.
Far fewer
tokens per call
Point it at an Agent Zone
Zone: "Capacity risk - Prod"
at_risk_hosts: 3
headroom: 11% (90d ↓)
top_driver: mem on node-7
recommended_action: rebalance
scope: prod only · read-only
 
~600 tokens / call
Scoped, enriched, governed. An answer-shaped response — tokens go to reasoning, not searching.

Representative figures, for illustration. Actual results depend on the zone and the question.

Security & compliance

Built for environments that can't afford surprises.

ISO/IEC 27001 certified (BSI)
Agentless — no attack surface added
AES-256, zero-trust over HTTPS
Per-customer encrypted boundary
Secure workspaces — data stays put

See it live on infrastructure you choose.

Pick any environment — virtual, HCI, physical, cloud, or a mix. We'll deploy a governed Agent Zone and show you exactly what an AI sees.