An alternative to N-able, ConnectWise and TeamViewer
IronWatch
Support that reaches the machine without opening a hole in the firewall.
IronWatch is the remote support and monitoring half of the suite — a small agent on each machine that dials out to your own coordinator, so a technician or an AI can look at a real box, diagnose it and fix it without anyone opening an inbound port. It is the product version of the system our own support desk has used on its own fleet for years.

- Planned agent
- One small binary, Linux and Windows, no inbound ports
- Planned reach
- Machines behind NAT, without a VPN or port forward
- Planned AI
- A model on your own hardware, or a hosted one, your choice
- Planned access
- Remote desktop and terminal, per technician
- Planned tenancy
- One coordinator per customer, never shared
The agent dials out, so nothing needs opening
The plan is for the agent to make outbound connections only and hold them open for instructions, which is what lets it reach a machine behind NAT or a router you do not control. No inbound firewall rule, no port forward and no VPN for the sake of support.
A machine you can read before you touch it
Planned first — processor, memory, disk, load and uptime, and the log file you name, gathered on request. Looking at a problem should not require interrupting whoever is using the machine.
AI that investigates, and a person who decides
The intention is that a model can gather evidence, propose a fix and verify it afterwards, with the authority to actually change something granted per session rather than standing. The internal version already works this way, and the separation is the part worth copying.
The model can run on your own hardware
Planned to work against a model you host yourself, so the logs and command output it reads never leave your building. A hosted model stays an option for anyone who would rather have it — the point is that it is your decision and not ours.
Remote desktop when reading is not enough
Planned to include a real remote desktop and terminal session, so the same tool covers both the unattended fix and the one where somebody needs to be shown what happened.
One coordinator per customer
The plan is for each customer's machines to report to their own coordinator rather than a shared one, so no fleet is visible from another and the audit log of who ran what belongs to the customer it concerns.