Τῖφυςhelmsman of the Argo

Steer your fleet through the clashing rocks.

Tiphys is an AI operations crew for the orchestrators you run. It reads your clusters and the cloud they run on, diagnoses problems with live data, and charts a fix. Nothing changes until you give the word.

Read-only by defaultEvery write needs your approvalEvery action signed and logged
κυβερνήτης
kybernētēs · helmsman

In Greek myth, Tiphys was the helmsman of the Argo. He read the stars and the wind and steered Jason's crew through the Clashing Rocks. Tiphys does the same for your workloads, whatever orchestrator they run on.

Α΄The crossing

Watch the crew at work.

Short loops from the product, running on sample data.

Lynceus diagnoses a flapping service and waits for approval before changing anything.

Β΄The crew

Two to steer, one to build.

Ask in plain language. Tiphys hands the work to the right crewmate and passes it between them when a problem crosses boundaries.

ΛΥΓΚΕΥΣCluster agent

Lynceus

The lookout, who could see through sea and stone.

Diagnoses pods, services, and nodes from live cluster state, logs, events, and metrics, so you see trouble before you hit it.

  • why is checkout restarting?
  • which workloads have no resource limits?
  • rotate secrets for payments-svc
ΑΙΟΛΟΣCloud agent

Aeolus

Keeper of the winds, who stilled them for the Argo.

Connects your workloads to the cloud behind them: roles and workload identity, databases, buckets, secrets, networking, and what each one costs. Aeolus works when your clusters run in a cloud account.

  • which IAM role does checkout assume?
  • why can't payments-api reach its database?
  • what does prod-east cost each month?
ΑΡΓΟΣIDP agent

Argus

The shipwright who built the Argo.

Builds services and environments in your clusters from your own templates and conventions. When a fix belongs in git, it opens a pull request on GitHub, and Argo CD or your deploy pipeline ships it.

  • spin up a staging env for notifications-api
  • which services drift from our template?
  • scaffold a new Go service
Γ΄The captain's word

Nothing changes without your approval.

Tiphys reads freely and writes carefully. Every change is proposed, reviewed, signed, and recorded.

α

Read-only by default

Tiphys runs under service accounts and IAM roles you scope. Writes are off until you enable them.

β

Approval gates with diffs

Every write arrives as a plan with its impact, a diff, and a dry-run result. You apply, reject, or edit it.

γ

Signed and reversible

Applied changes carry a signature and a rollback token, so any change can be traced and undone.

δ

The ship's log

Every query and action is written to an append-only, hash-chained log you can export to your SIEM.

ships-log·last 24hlive
TimeActorActionResultApprover
14:33:52lynceuskubectl.patchokjamie@acme
14:33:44lynceusplan.generatedapprovedjamie@acme
14:32:58lynceusprometheus.queryok—
14:32:22lynceuskubectl.logsok—
14:18:44aeolusidentity.verifyok—
14:11:32argusidp.pr.draftqueued—
14:04:01lynceussecret.rotateblockedneeds approval
append-only · hash-chained · SIEM export
Δ΄Home waters

Built for the orchestrators you run.

Tiphys works inside your clusters and the cloud they run on, and learns the patterns it finds there. Beyond that, Argus opens pull requests on GitHub when a fix belongs in git.

Your clusters
  • Workloads and Helm releases
  • Nodes, events, and logs
  • Ingress and network policies
  • Prometheus and metrics-server
The cloud behind them
  • Roles and workload identity
  • Managed databases and caches
  • Buckets, registries, secrets
  • Networks and cloud metrics
GitHub, for Argus
  • Service templates
  • PRs you review and merge
  • Shipped by Argo CD or CI/CD

Aeolus needs clusters that run in a cloud account; on-prem clusters run without it. Argus needs Argo CD or a deploy pipeline to ship what merges.

Ε΄Passage

Plans and pricing

Tiphys plans are on the Intelligant AI pricing page. One Intelligant account covers every product you use.

See pricing
ΣΤ΄Questions

What teams ask first.

Does Tiphys change anything without asking?

No. Tiphys is read-only by default. When you enable writes, every change is presented as a plan with a diff and impact summary, and nothing is applied until someone with permission approves it.

What access does Tiphys need?

A service account in your cluster with read-only RBAC, created and scoped by you. Aeolus, the cloud agent, also needs a read-only cloud role bound to that service account. Start read-only and widen access per namespace when you're ready.

Does Tiphys need a cloud?

No. Lynceus runs on any cluster, in a cloud or on-prem. Aeolus reads the cloud account behind your clusters, so it only works when they run in one. Argus needs a way for its changes to reach your clusters, such as Argo CD or a deploy pipeline.

Who are Lynceus, Aeolus, and Argus?

They're the three agents inside Tiphys, named for their jobs. Lynceus watches your clusters, Aeolus maps your workloads to the cloud behind them, and Argus builds new services and environments.

How does Tiphys learn our conventions?

It scans your clusters: manifests, Helm releases, probes and resource limits, admission policies, IAM bindings, and the changes you've approved. It records the patterns it finds with a confidence score, and you can review, edit, or remove anything it has learned.

Where does our data go?

Tiphys runs inside your cluster. Cluster and cloud data is processed to answer your questions and is not used to train models, and with a cloud-native or self-hosted model provider it stays inside your trust boundary.

Ζ΄Set sail

See Tiphys steer your own fleet.

In a 30-minute demo we connect Tiphys to a test cluster and walk through a real diagnosis. If you're not ready yet, join the waitlist and we'll let you know when your spot opens.

We'll only use this to contact you about Tiphys.