FAQ
Common questions.
Straight answers about how Aorka works, what it costs, and how we handle your data. The security reference and privacy policy cover more depth. If your question isn't here, just ask us.
FAQ
Straight answers about how Aorka works, what it costs, and how we handle your data. The security reference and privacy policy cover more depth. If your question isn't here, just ask us.
What counts as a user?
Anyone who logs into the Aorka console: technicians, admins, engineers. Console seats are unlimited on every plan. Endpoints are the machines running the agent, billed at the flat per-endpoint rate with no cap on how many you can connect.
Is there a free trial?
We offer a guided one-month pilot. We deploy agents on a slice of your fleet and walk you through the platform. No commitment, no card.
How does pricing work?
One flat fee per endpoint covers the whole platform: every feature, the full safety pipeline, unlimited console seats, and the AI that runs your chat. There is no metering and no usage tier — your invoice is your endpoint count times the rate. Connecting your own AI subscription over MCP is part of that fee too, with no surcharge. See the pricing page for the details.
What model powers the chat?
Whichever one fits the job. Aorka routes each task to the model that suits it — a fast model for routine work, deeper reasoning where the job needs it — so you get quick answers without losing depth on the hard problems. Every request runs through Anthropic's and OpenAI's commercial APIs under commercial terms, not consumer accounts — your data is never used to train models. It is all included in the flat per-endpoint price, with no meter and no model for you to pick. MCP access, which connects external tools like Claude Code, Codex CLI, or Gemini CLI, is included for everyone.
Do I have to generate my own scripts?
No. Aorka includes a library of thousands of parameterized scripts, every one security-evaluated and scored by real execution history. When a script succeeds, its score rises; when it fails, it drops. You can see what works before you run it. The library grows constantly as new solutions are added, and every script is searchable by describing the problem in plain English.
Can I use my own AI tools with Aorka?
Yes, at no extra charge. Claude Code, Codex CLI, Gemini CLI, and any MCP-compatible tool can connect directly to your Aorka instance with full safety-pipeline enforcement. The external tool gets the same gates as the in-product chat. Because your own AI subscription carries the model cost, there are no AI charges through us on this path. MCP access comes with your plan rather than replacing it — it is included in the per-endpoint fee, with nothing added on top.
Does the AI have unrestricted access to my machines?
No. Every command passes through a three-layer safety pipeline: deterministic regex command filter, AI risk evaluation, and human approval in the browser. Dangerous operations are blocked outright, with no admin override. You approve every system change before it runs.
What if someone compromises my Aorka account?
Multiple layers limit the blast radius. Scripts scoring above 51 are hard-blocked and no admin can override. Every write operation requires a separate browser-based approval, not just API access. Jobs are cryptographically signed (HMAC‑SHA256) and verified independently at dispatch. New client units start read-only and must be explicitly unlocked. MFA protects sensitive operations. An attacker with a stolen session still cannot run destructive commands through Aorka.
Can the model be tricked into running dangerous commands?
Prompt injection can make a model suggest a dangerous command. It cannot make the safety pipeline approve one. Layer 1 is deterministic regex: it classifies every cmdlet before the model sees it, and no prompt can change a string match. Layer 3 is a human clicking “Approve” in a separate browser session. The model has no ability to click that button. The layers that matter most are not AI.
How are agent updates secured?
Agent updates are signed with an RSA‑2048 private key that never leaves the development machine. The agent verifies the signature before applying any update, so a compromised update server cannot produce a valid signature. Updates are pull-based (the agent decides whether to trust the payload) and rolled out in stages, never to the entire fleet at once.
What privileges does the agent need?
The agent runs as LocalSystem, the same privilege level as every other RMM agent. It needs this to manage services, query AD, and install updates. The difference is what controls those privileges: outbound-only connections (no listening ports), plaintext script execution (EDR-visible), machine-bound credential storage, device fingerprinting, and the full three-layer safety pipeline.
What about data privacy?
Your data is tenant-isolated at every layer. Facts, understandings, credentials, and conversations are scoped to your organization and stored on our infrastructure. Nothing is retained by Anthropic, OpenAI, Google, or any model provider. AI requests are stateless API calls. Your data is never used to train models.
Do I need to open firewall ports?
No. Agents initiate outbound WebSocket connections only. No inbound rules, no VPN, no port forwarding. If the machine can reach the internet over HTTPS, it can run Aorka.
Is there a detailed security document?
Yes. The security architecture reference covers each threat model in detail: control-plane compromise, prompt injection, supply chain integrity, agent privileges, the Rule of Two analysis, and a frank assessment of residual risk.
How do I deploy agents?
Agents are packaged as a standard Windows MSI. Deploy through GPO, Intune, NinjaRMM, JumpCloud, or anything else that can push an MSI. You can also push directly from the Aorka console or run a one-line PowerShell installer.
What platforms are supported?
The agent currently supports Windows (Server and Desktop). The platform also acts as an SSH gateway for network devices (FortiGate, SonicWall, PAN-OS, Cisco) and integrates with Microsoft 365 environments. Linux and macOS agents are on the roadmap.
Send it over and we'll answer in writing, including whatever we didn't think to put on this page. No trial, no call.
Ask us a question Start your trial