AiSulivo
AiSulivo
Menu
AiSulivo
AiSulivo

IncidentFox

Investigate alerts, inspect system evidence and prepare reviewed remediation with IncidentFox.

Pricing
Open-core self-hosting is available under Apache 2.0 for core components. Managed/cloud paid subscriptions and private deployments are offered, but public numerical SaaS rates were not verified.
Free plan
Yes for open-core/self-hosted core deployment; managed cloud may offer a free trial, while production SaaS/private plans are paid.
Platforms
Web, Slack, Hosted or self-hosted server

Tool Information

IncidentFox
IncidentFox
Updated: September 2026
Tool type: AI Incident Investigation Platform
Pricing: Open-core self-hosting is available under Apache 2.0 for core components. Managed/cloud paid subscriptions and private deployments are offered, but public numerical SaaS rates were not verified.
Free plan: Yes for open-core/self-hosted core deployment; managed cloud may offer a free trial, while production SaaS/private plans are paid.
Platforms: Web, Slack, Hosted or self-hosted server
Login required: Account or company onboarding required
API: Yes; Slack, self-hosting, Kubernetes/private-cluster and observability integrations are documented; API details depend on deployment.
Browser extension: No official browser extension verified
Mobile app: No official native mobile app verified
AI models: Underlying model versions not publicly specified
Developer: IncidentFox

About IncidentFox

IncidentFox is an AI incident-investigation platform for engineering teams. It connects alerts with logs, metrics, code and deployment context, then prepares an explanation and possible remediation. The main interaction happens in Slack, where responders can ask follow-up questions and inspect supporting material.

Investigation with system context

The agent uses connected observability and infrastructure tools to investigate a problem. Screenshots, log files and configuration material can be added to the conversation. Reports and scripts are returned alongside the analysis so a responder can examine more than a short summary.

The company describes learning from code, past incidents and team context during setup. This may help make investigations more relevant, but an inferred root cause still needs validation against the running system. A plausible explanation is not proof that a proposed command is safe.

Execution and deployment controls

IncidentFox advertises isolated execution, proxy-based credential injection and action logging. The site describes approval for writes while also offering configurable automatic mitigation for selected runbooks. Teams should verify the active autonomy setting instead of assuming approval is unavoidable in every configuration.

Hosted, private infrastructure and open-core self-hosting options are described. The official page says SOC 2 auditing is in progress, so it should not be represented as completed certification. Public numerical subscription pricing was not established.

Introducing an AI responder

Start with read-only investigation of a known incident. Compare the explanation with source evidence and inspect generated scripts line by line. Define rollback procedures and approval owners before allowing writes. Expand access only after responders can audit the agent’s actions and recognise when human investigation must take over.

Key features
  • Alert investigation
  • Log and metric correlation
  • Slack follow-up
  • Fix-script preparation
  • Action audit trail
  • Sandboxed execution
Use cases
Alert investigation,Log and metric correlation,Slack follow-up,Fix-script preparation
How to use
  1. Choose hosted or approved self-hosted setup.
  2. Connect a limited Slack workspace.
  3. Authorise read-only observability access.
  4. Replay a known incident.
  5. Inspect the evidence and proposed cause.
  6. Review any remediation script.
  7. Set explicit write-approval rules.
  8. Monitor and audit production use.
Best for
SRE Teams, Platform Engineers, On-Call Responders
Integrations
Slack,PagerDuty,AWS,Datadog,Prometheus,Grafana,GitHub,Kubernetes,Sentry
Commercial use
Infrastructure operations with scoped credentials and authorised remediation controls

Related Tags