Evidence-first endpoint intelligence

Find out what's actually wrong.

PC Investigator turns endpoint telemetry into evidence-backed investigations—correlating events, system state, and historical signals so IT teams can find root causes faster.

Read-only by default
Windows · macOS · Linux
Self-host or managed
app.pcinvestigator.dev
Fleet DashboardEndpoint health at a glance
WD
ENDPOINTS42Managed fleet
ONLINE41Reporting now
ATTENTION4Warning findings
CRITICAL1Needs action
Needs AttentionPrioritized findings
View all
CRITICAL
WS-042Kernel panic evidence detected
4m
WARNING
DESKTOP-18Unexpected shutdown detected
18m
WARNING
SERVER-31Storage pressure detected
37m
Fleet HealthLatest assessment
88%Healthy
37 healthy4 attention1 critical
EndpointsCurrent fleet status
ENDPOINTSTATUSOSHEALTHLAST SEEN
Wills-MacBook-Pro● OnlinemacOSHealthyNow
DESKTOP-571D7QL● OnlineWindows 11WarningNow
THE INVESTIGATION LAYER

Alerts tell you what happened.
PC Investigator helps determine why.

01CollectEndpoint telemetry
02CorrelateEvidence & history
03InvestigateLikely causes
04ActGoverned diagnostics
A DIFFERENT KIND OF ENDPOINT TOOL

Built for investigation, not alert overload.

Turn noisy endpoint signals into a clear, defensible picture of what is established, what is plausible, and what to check next.

WARNING
Unexpected shutdown and shadow-copy failures detectedDESKTOP-571D7QL · Windows 11
ASSESSMENT92%
FINDING SUMMARY

The endpoint experienced an unclean shutdown. Shadow-copy failures are established near the same operating window, while graphics-driver errors remain a possible contributor rather than a proven cause.

SeverityWARNING
Root causeNot established
EvidenceCorroborated
ESTABLISHED EVIDENCE
  • Unexpected shutdown recorded
  • Volsnap shadow-storage failure
  • NVIDIA driver events observed
CAUSES / LIMITS
  • Power loss vs. hang not distinguished
  • GPU errors are correlated, not causal
  • Storage pressure may be contributory
NEXT DIAGNOSTIC
Recommended Correlate driver and storage events with the shutdown timeline.
01

Evidence-backed investigations

Correlate endpoint events, system state, and historical findings instead of forcing technicians to sift through raw logs.

Evidence ≠ hypothesis
02

AI-assisted reasoning

Use your preferred model to interpret curated evidence while deterministic policy controls endpoint health and severity.

AI explains. Policy decides.
03

Governed diagnostics

Collect additional evidence remotely through allowlisted diagnostic actions, bounded execution, and auditable results.

Human control stays in the loop
FROM SIGNAL TO ANSWER

Give every technician a stronger investigative workflow.

PC Investigator separates high-confidence facts from plausible causes, then recommends the next diagnostic that can actually reduce uncertainty.

1
Observe the endpoint

A lightweight agent collects bounded, platform-aware telemetry.

2
Score the evidence

Deterministic rules normalize noise and establish health before AI is involved.

3
Investigate the finding

AI interprets the evidence, identifies limits, and proposes targeted follow-up.

4
Approve the next action

Technicians choose what diagnostic or remediation is allowed to run.

Investigation timeline
DESKTOP-571D7QL
NVIDIA driver eventDisplay-driver error observed
Shadow-copy failureVolsnap storage could not grow
System responsiveness lostEvidence window
Unclean shutdown recordedKernel-Power 41 · EventLog 6008
Windows startupEndpoint reporting resumed
Root cause statusNot establishedPC Investigator preserves uncertainty instead of inventing certainty.
CROSS-PLATFORM BY DESIGN

One investigation model. Every endpoint.

Use a common investigative workflow across mixed fleets while preserving platform-specific evidence.

Windows

Event logs, hardware state, disks, drivers, services, reliability signals, and governed PowerShell diagnostics.

SUPPORTED

macOS

Unified Log signals, hardware profile, battery, storage, uptime, networking, and native diagnostic commands.

SUPPORTED

Linux

System inventory, memory, storage, networking, process state, and a growing set of platform-native collectors.

FOUNDATION
DEPLOY IT YOUR WAY

Your infrastructure.
Your AI.
Your data.

Run PC Investigator where your organization needs it. Start self-hosted today, with managed deployment options planned as the platform matures.

Container-first HubDocker today. Kubernetes-ready architecture.
Bring your own modelOpenAI today, provider abstraction built for more.
Outbound endpoint connectivityNo inbound firewall holes required for agents.
PC INVESTIGATOR ARCHITECTURELIVE DESIGN
Windows
macOS
Linux
Outbound TLS
PC Investigator HubInventory · Evidence · Policy · Audit
Curated evidence
AI ProviderBYO model & key
DatabaseSQLite / PostgreSQL
CONTROL BEFORE AUTOMATION

Designed to investigate safely.

The agent should be powerful enough to answer hard questions—not powerful enough to bypass your controls.

01

Read-only by default

Collection and investigation are designed around evidence gathering before remediation.

02

Allowlisted diagnostics

Remote commands are cataloged actions rather than arbitrary shell access.

03

Human approval

Privileged remediation is designed to require explicit policy and technician approval.

04

Auditable actions

Enrollment, investigations, commands, and future remediation flows are built around traceability.

Security is a product requirement, not a marketing badge.PC Investigator is under active development. We do not claim certifications or compliance attestations the product has not earned.
PC INVESTIGATOR EARLY ACCESS

Spend less time proving what isn't wrong.

Join the early-access list for product updates, self-hosted previews, and opportunities to help shape the investigation workflow.

No spam. Early-access contact only.