Pillar 5 • Auditing, Compliance & AI

5-Tier Immutable Audit Trails &
Deterministic Network AI Copilot

Deliver total forensic accountability for ISO 27001, SOC 2, and PCI-DSS compliance audits. Centralize RADIUS, Syslog, CLI commands, and Apprise multi-channel alerts, backed by a deterministic AI Copilot with complete tool execution auditability.

Compliance

Centralized 5-Tier Immutable Audit Log Suite

Unifies 5 distinct forensic logging layers into a single tamper-evident, searchable audit repository:

  • 1. RADIUS Auth Logs : Every login attempt, client IP, NAS-IP, and Accept/Reject reason.
  • 2. RADIUS Accounting : Session duration, octets in/out, and disconnect cause.
  • 3. CLI Command Audit : Time-stamped keystrokes and command lines executed per operator.
  • 4. Device Event Logs : Interface flaps, BGP neighbor state transitions, and hardware alerts.
  • 5. System Event Trail: User role alterations, vault access, and configuration restores.
RADIUS Authentication Audit Log
Inspect High-Res Screen

RADIUS Forensic Table: Detailed records of operator authentication, NAS identifier, and OTP token statuses.

Syslog Regex Classifiers
Inspect High-Res Screen

Regex Pattern Engine: Rule definitions categorizing raw router syslog streams into actionable high-severity events.

Log Analytics

Syslog Regular Expression Pattern Classifiers

Transform millions of noisy router syslog messages into actionable operational insights. Define custom regex patterns to classify critical events:

  • Pattern Matching: Tag BGP neighbor drops, OSPF link flaps, and firewall brute force attempts automatically.
  • Asynchronous Elastic Search: Query historical device syslog streams across years of data in milliseconds.
Alerting

Multi-Channel Alert Dispatcher (Apprise)

Ensure critical network incidents reach on-call engineers within seconds. MikroWizard integrates Apprise, supporting 80+ notification channels:

  • Slack, Discord, Telegram, Pushover, Microsoft Teams, Webhooks, Twilio SMS.
  • Custom routing rules based on event severity, device group, or time of day.
Apprise Alert Notification Channels
Inspect High-Res Screen

Notification Channels: Configured webhook URLs, chat bot tokens, and active event triggers.

AI Engine Configuration
Inspect High-Res Screen

AI Copilot Settings: Multi-provider LLM connector (Gemini, OpenAI, Claude, Local Ollama) with 13 sandboxed tool actions.

Intelligence

Multi-Provider AI Copilot with 13 Deterministic RouterOS Tool Actions

Accelerate incident root-cause analysis with an AI assistant that understands network topology and RouterOS syntax. Supports Google Gemini (gemini-3.6-flash), OpenAI, Claude, and local Ollama instances via a unified LLM abstraction layer.

  • Multi-Provider LLM: Google Gemini, OpenAI, Claude, and local Ollama instances — switch providers without code changes.
  • 13 Deterministic Tools: AI executes sandboxed read-only commands — ping, traceroute, interface stats, routes, speed tests, and RouterOS script generation.
  • Plain-English Queries: Diagnose outages, generate RouterOS configurations, and analyze logs using natural language — no CLI expertise required.
AI Governance

AI Copilot Compliance Audit Trail & Tool Execution History

Enterprise AI safety, explainability, and governance — every AI interaction is immutably logged. Satisfy security auditors who need complete visibility into what the AI assistant did, why, and on which routers.

  • Full Session Logging: Records operator prompts, model responses, every tool call invoked, parameter payloads, and affected device IDs in AIChatSessions_pro.
  • Reasoning Explainability: Inspect the AI's decision chain and tool execution tree for any historical session.
  • ISO 27001 / SOC 2 Ready: AI governance logs feed directly into compliance evidence packages alongside human operator audit trails.
AI Copilot Audit Logs
Inspect High-Res Screen

AI Audit Trail: Chronological record of AI interactions, tool invocations, parameters, and affected router IDs.

SSL/TLS Certificate Manager
Inspect High-Res Screen

SSL/TLS Manager: Automated Let's Encrypt ACME HTTP-01 challenge flow and custom PEM certificate upload.

System Infrastructure

Automated Let's Encrypt SSL/TLS Certificate Provisioning

Zero-touch HTTPS encryption for the entire management portal. MikroWizard automates the ACME HTTP-01 challenge verification for Let's Encrypt certificates, eliminating manual renewal headaches.

  • Auto-Renewal Timers: Certificates renew automatically before expiry — no crontab or manual intervention required.
  • Custom PEM Upload: Supports manual upload of corporate or wildcard certificates with private key validation.
  • HTTPS Everywhere: Enforces encrypted transport for admin panel, subscriber portal, and all API endpoints.
System Infrastructure

SMTP Email Dispatcher & Notification Server Settings

Reliable automated email delivery for critical network alerts, administrative password recovery, and audit report distribution via configurable SMTP relay.

  • SSL/TLS Support: STARTTLS and SSL/TLS on port 465/587 with custom sender addresses and authentication credentials.
  • Live Test Email: Interactive test dispatcher to verify SMTP relay configuration without triggering production alerts.
  • Alert Routing: Powers device-offline email alerts, backup failure notifications, and system event digests.
SMTP Email Configuration
Inspect High-Res Screen

SMTP Settings: SSL/TLS relay configuration with live test email dispatcher and sender address management.

Audit Compliant

Pass Every Network Security Audit with MikroWizard

Deploy on-premises. Maintain 5-tier forensic logs, regex syslog classifiers, and deterministic AI auditability.

Request Live Architecture Demo Explore Pricing Plans