Bobby's Capabilities
Bobby is Cert-IX's built-in AI assistant. It appears as a companion in the bottom-right of the interface and answers questions in natural language, in several languages. This page explains what Bobby can actually help you with, how it produces its answers, and where its boundaries are — which differ depending on where you are talking to it.
Two surfaces, two capability sets
Bobby runs on more than one surface, and it is important to understand the distinction because each has different powers and limits.
- The documentation assistant — available on this documentation site and on the public Cert-IX website. It answers questions about the product and about security concepts, grounded in the Cert-IX documentation. It is read-only: it explains and points you to the right page, but it never touches your account or data. Documentation sessions are anonymous.
- The in-platform assistant — available once you are signed in to the dashboard at app.cert-ix.com. It is aware of the context you are working in and can help you carry out certain tasks, always behind an explicit confirmation step (see Actions and confirmation).
| Documentation assistant | In-platform assistant | |
|---|---|---|
| Where | Docs site, public website | Signed-in dashboard |
| Grounding | Cert-IX documentation (with citations) | Your current context in the app |
| Account/data access | No — anonymous | Yes — scoped to your tenant and role |
| Can take actions | No | Yes, only after you confirm |
Bobby's responses are generated by Claude. Because answers are AI-generated, Bobby shows an AI notice and can occasionally be wrong or incomplete — always confirm anything important against the linked documentation or the live product.
How Bobby answers
The documentation assistant uses retrieval-augmented generation (RAG): it searches the Cert-IX documentation for the passages most relevant to your question, then composes an answer from them. Two practical consequences:
- Answers include citations. Bobby links back to the documentation pages it drew from, so you can open the source and read the full detail rather than relying on a summary.
- Answers reflect the current docs. As the documentation is updated, the assistant's knowledge follows, so guidance stays aligned with the shipped product rather than a fixed snapshot.
Ask in whatever language you are comfortable with — Bobby understands and replies in several languages.
What you can ask about
Bobby is most useful for two broad categories of question: understanding a security concept, and getting things done in Cert-IX. Rather than a long catalogue, here are the areas where it is genuinely well-grounded, each linking to the documentation it draws on.
Platform features and navigation
Bobby can explain how a feature works, when to use it, and where to find it — then hand you the relevant page. Well-covered areas include the dashboard and security score, asset management, scanner agents, the Scan API, and the MCP tools.
Vulnerability and security concepts
Bobby can explain vulnerability fundamentals — what a CVE is, what CVSS severity ratings (Critical, High, Medium, Low) mean, and how to think about remediation priority — and connect them to how Cert-IX presents findings in Vulnerability Management. It answers conceptual "what is…" and "how should I prioritize…" questions; it does not invent CVE records or scan results for you.
Compliance
Bobby can describe the compliance frameworks Cert-IX helps you track — such as NIST CSF, ISO 27001, SOC 2, CIS Controls, and NIS2 — and explain how the Compliance area works. Compliance is a Beta capability, so Bobby will point you to the current documentation for the most accurate, up-to-date behavior.
Getting started and setup
Bobby helps with onboarding questions: connecting the platform, deploying a
scanner agent, authenticating to the Scan API, or locating a setting. For
example, it can point you to where your Tenant ID lives (under Settings →
Organization) or explain how Scan API keys (formatted cix_sk_…, sent in the
X-API-Key header) are used.
Actions and confirmation (in-platform only)
The in-platform assistant can do more than explain — it can help you complete certain tasks. When it does, it follows a propose-then-confirm pattern: Bobby describes the change it is about to make and waits for your explicit confirmation before anything happens. You stay in control, and nothing is altered silently.
Destructive operations — such as deleting records — are not performed by Bobby. Action capabilities are also scoped to your role and permissions, and some may depend on your plan (Free, Starter, or Pro). If an action isn't available, Bobby will guide you to do it yourself in the relevant screen.
Example interactions
The following illustrate the kinds of questions Bobby handles well. Answers are paraphrased.
Understanding a concept
You: "What's the difference between a Critical and a High severity finding?"
Bobby: Explains CVSS severity bands and how Cert-IX ranks findings, then links to Vulnerability Management for the full model.
Finding your way around
You: "Where do I find my Tenant ID?"
Bobby: Points you to Settings → Organization, where the Tenant ID is shown for use when configuring scanner agents.
Getting set up
You: "How do I deploy a scanner agent on my internal network?"
Bobby: Summarizes the agent download-and-enroll flow and links to Scanner Agents.
Working with the API
You: "How do I authenticate to the Scan API?"
Bobby: Explains the
cix_sk_…API key andX-API-Keyheader, and links to Authentication.
Getting a recommendation
You: "Which compliance framework should I start with?"
Bobby: Talks through common starting points among the supported frameworks and links to Compliance. Because Compliance is in Beta, it flags that behavior may still be evolving.
Limitations and boundaries
Bobby's boundaries depend on the surface you are using.
Documentation assistant
- Does not access your account, tenant data, or live status — sessions are anonymous.
- Cannot make any change in the platform; it explains and links, nothing more.
- Answers reflect the documentation, not your specific configuration.
In-platform assistant
- Works within your role and permissions and only within your own tenant.
- Takes actions only after you explicitly confirm them; it does not act on its own.
- Does not perform destructive operations such as deletions.
Both
- Responses are AI-generated and may occasionally be incomplete or wrong — verify anything important against the linked documentation or the live product.
- Bobby is not a substitute for human review of security or compliance decisions.
When to go elsewhere
- Read the documentation for exhaustive technical detail, complete configuration options, and version-specific behavior.
- Contact support for account problems, billing questions, bugs, or feature requests.
Privacy and the AI notice
Documentation conversations are anonymous. Every Bobby surface displays an AI and privacy notice so it is clear you are talking to an automated assistant and how your input is handled. For the platform's overall data-handling practices, see the Cert-IX privacy notice.
Helping Bobby improve
You can rate responses and report anything that looks inaccurate. That feedback helps refine answers and surface gaps in the documentation the assistant draws from.
Learn more
- Bobby Overview — what Bobby is and where it appears
- How to Use Bobby — asking effective questions
- Vulnerability Management — how findings are ranked and remediated
- MCP Tools — connect Cert-IX capabilities to AI coding agents
War diese Seite hilfreich?