MSP-native · Agentic by design

The agentic PSA + RMM platform built to replace your stitched-together stack.

One console for ticketing, monitoring, security, and compliance — with an AI layer that drafts, resolves, and prioritizes across every module, always supervised by a human before anything ships.

Live in our own MSP practice today — opening to a limited design-partner cohort. No spam, no lists sold. · See what's building

app.nexusrmm.aiPreview
AI resolved — printer offline (site B)
Auto-drafted
Patch ring 2 — 48 endpoints
Deployed
M365 backup — Exchange + OneDrive
Verified
AI call — approval requested
Escalated
Vuln scan — 2 critical
Needs approval
Built different, on purpose

Stop stitching your stack together.

Nexus isn’t an incremental improvement on the tools you already run — it’s a different set of bets on architecture, security, and how honest a vendor is willing to be.

One platform, not five stitched tools

Ticketing, monitoring, security, and compliance share one tenant-isolated record — no Zapier glue, no reconciled timestamps, no tab-switching to find a device’s history.

Outbound-only. Zero inbound site-firewall exposure.

The on-prem monitoring agent never listens for anything. No port to open, no firewall rule to justify at your next security review — at any client site, ever.

Policy-governed autonomy

Low-risk, non-destructive work can be automated within tenant policy. Anything consequential — destructive, irreversible, or outside that policy — stays approval-gated, RBAC-enforced, and audited, full stop.

We show you the real build status

No vaporware, no demo data dressed up as shipped. Every module is labeled by what’s actually true today, not what’s aspirational.

See the roadmap
Dogfooded daily

We run our own MSP practice on Nexus — every ticket, every device, every alert, for real client organizations — before we ever ask you to.

One platform, one bill

All your tools, one platform. One login. One bill.

Every row below is normally its own subscription, its own login, its own invoice, and its own vendor to chase. Nexus is the home for all of them — so the tool sprawl collapses into one platform and one vendor, and the total cost comes down with it.

PSA & ticketing

The helpdesk your team runs on

RMM & patching

Native agent, signed jobs, patch deployment

Endpoint management / MDM

Jamf, Intune, and more in one pane

Remote control

Launched straight from a ticket

Microsoft 365 backup

To your own bucket, verified by hash

Password vault

Encrypted, rotated, access-logged

SIEM & EDR

Security telemetry and threat feeds

Uptime monitoring

HTTP(S), TLS, and domain expiry

IT documentation

Docs linked to devices and tickets

CRM & sales

Pipeline through to a provisioned client

E-signature

Agreements signed in the portal

vCIO & QBR reporting

Board-ready reviews, generated

One platform · one login · one bill · one vendor.

The AI layer

Autonomous resolution. Creation to close.

The whole ticket lifecycle is agentic — created, triaged, diagnosed, and resolved by AI. The trajectory is full autonomy for routine, non-destructive work; a human always stays in the loop for anything destructive or irreversible, and the agent calls them when it needs a decision.

Autonomous resolution

Routine, non-destructive tickets — printer offline, password reset, everyday troubleshooting — get diagnosed, fixed, verified, and closed by the agent. Today the fix lands for one-click approval; hands-off for these classes is where Nexus is headed.

A human owns anything destructive

Destructive or irreversible actions never go autonomous. The agent stops, packages the full context, and routes the approval to a person — including calling them. You decide; it executes.

Inbound & outbound AI calling

On the roadmap

A voice agent that answers, triages, schedules, and places the escalation and approval calls — so a human is reached the moment one is needed, without your team watching a queue.

AI cyber analysis

Continuous posture scoring, phishing simulation, and breach/vulnerability analysis — prioritized by AI so your team acts on what actually matters first.

Honest about where this is: today, autonomous resolutions land for one-click approval, and anything destructive or irreversible always requires a human. Autonomy ships class by class — each capability labeled by what's true today versus what's on the roadmap.

One platform

Everything managed IT touches.

Every module on one multi-tenant platform — built for how MSPs and the organizations they serve actually budget, staff, and get audited.

Security & compliance, by design

Built to walk into a board meeting with the report already done.

Posture tracking maps to the frameworks your clients actually answer to — general and vertical-specific alike. AI triages every alert before it reaches a human, the on-prem monitoring agent has zero inbound site-firewall exposure, and integration secrets are encrypted at rest, fail-closed in production.

See the full trust center
NIST CSF
SOC 2
HIPAA
PCI-DSS
ISO 27001
CIS
FERPA/COPPA
Google Workspace
Microsoft 365
Email DNS (SPF/DKIM/DMARC)
How Nexus is built

Platform assurance, not adjectives.

Any vendor can say "tested" and "secure." Here is the specific, checkable evidence behind those words at Nexus — most of it drawn straight from our own public repository, not a claim you have to take on faith.

CI gates every merge

Classification, dependency audit, secret-scan, and the full test suite must pass before anything reaches main

10.8k lines of test code

A 5.3% test-to-production ratio, computed automatically and published on our own README, not asserted

Tenant isolation at the database

PostgreSQL row-level security keyed per tenant — enforced by Postgres itself, not just application code

Signed endpoint execution

Ed25519-signed remote jobs against a default-deny capability registry

Secrets encrypted, fail-closed

Integration credentials are encrypted at rest; production refuses to run misconfigured rather than storing one in plaintext

Outbound-only site agent

No inbound firewall rule at any client site — the agent phones home, nothing phones in

73 ADRs, 114 tracked controls

Architecture decisions and compliance controls are written down and versioned, not tribal knowledge

Dogfooded in production

Our own MSP practice runs on Nexus today — real tickets, real devices, real clients

Incident discipline

Every SEV-1/2 gets a same-day postmortem and a logged evidence trail, not a retro nobody writes

Figures current as of this writing and updated as the platform changes — ask us directly for the current numbers rather than assuming a snapshot stays accurate forever.

Building in the open

Built in the open. Shipped when it's real.

Nexus ships in small, tested increments rather than one big-bang release. This tracker is a rough guide to where we are — not a live status feed.

Foundation
Core modules
Private beta
General availability
See the full roadmap

Illustrative — not a precise metric

Ready to run PSA and RMM as one platform?

Nexus is live in our own MSP operations and opening to a limited design-partner cohort. Join the private-preview list.

Building in the open — one tested module at a time. No spam, no lists sold.