Introduction
Welcome to Sencai
Section titled “Welcome to Sencai”Sencai is a cloud management platform that acts as your team’s DevOps colleague — with hands on cloud and on-prem infrastructure. It connects to your existing cloud accounts, gives you visibility over every resource, enforces compliance policies automatically, and uses AI to help you respond to incidents faster.
Whether you’re managing a handful of cloud servers or running a complex multi-cloud, multi-team setup, Sencai gives you a single place to see, govern, and operate everything.
What Sencai does
Section titled “What Sencai does”Import & Inventory
Section titled “Import & Inventory”Connect your existing AWS, Azure, GCP, or Hetzner accounts and Sencai scans all your resources automatically. Every EC2 instance, virtual machine, network, IAM role, database, and load balancer appears in a unified inventory — without any manual entry.
You keep your existing infrastructure exactly as it is. Sencai adopts it into management without changing anything.
Multi-Cloud Operations
Section titled “Multi-Cloud Operations”Provision new infrastructure directly from Sencai across any supported provider. Stop, resize, or terminate instances. Manage DNS records on Route53, Azure DNS, GCP Cloud DNS, or Cloudflare. All changes are async, tracked, and auditable.
Fleet — Server Agent
Section titled “Fleet — Server Agent”Install the lightweight Sencai Fleet agent on any server (bare metal, VM, cloud). Once enrolled, the agent reports software inventory, patch status, and CIS security scan results back to Sencai. You can run runbooks remotely, open a browser-based terminal to any enrolled server, or quarantine a compromised machine with one click.
Compliance & Policies
Section titled “Compliance & Policies”Define rules that apply to all your resources — “all production servers must have a cost-center tag”, “no public S3 buckets”, “all VMs must pass CIS Level 1”. Sencai scores every resource and organization against your policy set and generates NIS2 compliance evidence automatically.
Intelligence — Lumen AI + OPSLOOP
Section titled “Intelligence — Lumen AI + OPSLOOP”Lumen AI is an in-platform assistant you can ask questions about your infrastructure, policies, and incidents. OPSLOOP is the background intelligence loop: it correlates alerts, anomalies, and scan results, then suggests runbooks and likely root causes before you’ve even started investigating.
Who it’s for
Section titled “Who it’s for”- DevOps teams managing multi-cloud infrastructure who want unified visibility and less toil
- IT managers who need compliance evidence, cost visibility, and policy enforcement without writing custom tooling
- MSPs and agencies who manage infrastructure for multiple customers and need cross-tenant operations with a proper audit trail — see Agency / MSP Relationships
- Platform engineers who want to enforce standards (tags, IAM, security benchmarks) across the whole organization automatically
Core capabilities at a glance
Section titled “Core capabilities at a glance”| Capability | What you get |
|---|---|
| Cloud inventory | Unified view of all resources across providers |
| Import existing infra | Connect BYOC accounts, scan and adopt resources |
| Cloud provisioning | Deploy new VMs/instances on any supported provider |
| Fleet agent | Lightweight Go binary for server monitoring and remote ops |
| Browser terminal | Open a terminal to any enrolled server from your browser |
| Compliance scoring | OPA/Cedar policy engine, automatic scoring, NIS2 evidence |
| Tag governance | Enforce mandatory tags, detect drift, get remediation proposals |
| DNS management | Route53, Azure DNS, GCP Cloud DNS, Cloudflare from one UI |
| Billing | Usage-based billing with Lago + Stripe, subscription tiers |
| Personal plans | Independent User Plan tiers (Free/Plus/AI/Unlimited) with a 14-day trial and sponsorship (one user can pay for another’s plan) |
| Dunning | Automated payment-failure grace period and suspension via sencai-watchdog |
| Audit trail | Immutable hash chain, Ed25519 anchors, tamper-evident log |
| SSO | Keycloak OIDC, EntraId (Azure AD), Google Workspace, SCIM |
| AI assistant | Lumen AI for natural language infrastructure queries |
| Incident intelligence | OPSLOOP correlation engine with runbook suggestions |
| Multi-tenancy | RBAC per organization, MSP cross-tenant operations |
Quick start path
Section titled “Quick start path”- Log in — Sign up or log in to Sencai
- Create an organization — Your team’s workspace with RBAC and billing
- Cloud infrastructure — Use Sencai-hosted infrastructure right away (default, no cloud account needed), or connect your own AWS/GCP/Azure/Hetzner BYOC credentials if you want full billing control
- Import existing infrastructure — Trigger a full scan, review discovered resources, adopt them
- Explore your inventory — All resources appear in Cloud Instances with tags, status, and cost
- Enroll a Fleet agent (optional) — Install the agent on a server for deep monitoring and terminal access
- Set up policies — Define tag and compliance rules, see your score
Documentation structure
Section titled “Documentation structure”User Guide
Section titled “User Guide”For end users, DevOps teams, and IT managers.
- Getting Started — Registration, login, first steps
- Organizations — Teams, members, RBAC
- Cloud Instances — Provision and manage cloud infrastructure
- Importing Infrastructure — Connect accounts and adopt existing resources
- Fleet — Server Agent — Install the agent, enroll servers, run runbooks
- Compliance & Policies — Policy engine, scoring, NIS2 evidence
- Tool Center — Docker images, registries, Git templates
- Account Settings — Profile, 2FA, API tokens
- FAQ — Common questions and troubleshooting
Developer Guide
Section titled “Developer Guide”For engineers and architects working on the Sencai platform itself.
- Architecture — Service map, data flows, security model
- Local Development — Set up your development environment
- Services — Deep dives into each microservice
- API Development — Building Strapi endpoints and policies
- Contributing — Code style, testing, and PR workflows
- Runbooks — Operational troubleshooting guides
Language
Section titled “Language”Documentation is available in English (default) and Czech. Use the language switcher in the top navigation.
Ready? Start with Getting Started to create your account and connect your first cloud.