For company and campus WiFi

Every employee on their own account and device, and a record of who changed what.

Who is on the network, on which device, and until when. An account locks to the first device it signed in with, and any change someone on your team makes is recorded against their name.

  • An account locks to one device
  • Permissions you decide
  • A log nobody can delete

session — staff-1042

device
AC:DE:48:00:11:22
mac lock
learned
sessions
1 of 1
quota
12.4 GB left
audit
role updated

online

Problems you can stop dealing with

One WiFi password goes round the whole building, and nobody knows who is on.

An account locks to the first device it signed in with and refuses the rest, including a device that randomises its address. You decide how many devices can use the same account at once.

Someone changed an account and nobody knows who.

A log nobody can delete says who did what, when, and what changed. Every sign-in attempt is recorded too, whether it was accepted or refused, and why.

The help desk needs to do one thing, not hold every permission.

You build the roles yourself and give each person only the permission they need, and each manager sees only the people below them.

A key you made so another program could connect has slowly become a key to everything.

A key can never do more than its owner can do today, and it is never an administrator.

What you get for your company network

Devices under control

An account learns its first device and refuses the rest, and you can refuse devices that randomise their address if you want. You can disconnect anyone who is online from the panel.

Limits for every plan

Usage, time and speed for each plan. When a device leaves without signing off, the system closes its session on its own.

Your team's permissions

Roles you create, and each manager sees only their own branch. Every account on your team has two-step sign-in from a phone, and you can sign someone out of every device they have open.

Connecting your own systems

Keys for your own programs with limited permissions you choose, and signed notices sent to your programs when something happens.

Details

The log

Everything your team did, and every sign-in attempt. You can search it and export it to a file.

Visitors

A visitor plan that opens only the sites you allow while they are on it, and cards ready for the reception desk.

The technical part

If you own the place you can skip this part. It is for your network engineer.

MAC lock and sessions

MAC lock learns a subscriber's first address and rejects the others, with an option to reject randomised addresses. The concurrent-session limit is counted as a set of live session ids. Disconnect from the panel goes over CoA.

Quotas and idle sessions

Data, time and speed counters on the hot path in Redis, Postgres as the source of truth. The idle reaper closes sessions the NAS forgot.

Permissions and integration

Roles from a flat permission catalogue, TOTP two-factor and session revocation. An API token's authority is the intersection of its scope and its owner's live permissions, and it is never an administrator. Signed outbound webhooks for events. The audit log is append-only and exports as a background job.

290 req/s

Admin API throughput without saturating, alongside 800 auth/s of authentication at p95 13.7 ms, measured on one 4 vCPU / 7.7 GB server, release 0.2.16.

Questions we get asked a lot

Can I give the help desk view-only access?

Yes. Make a role with only the view permissions and give it to the help desk account.

Can our HR system create and close accounts?

Yes, with an API key whose permissions you choose. The key can never do more than its owner can, and it is never an administrator.

Where is the data kept?

In a Postgres database on the server your panel runs on, with your data kept apart from everyone else's inside the database itself. Backups are encrypted, and you can have them saved to your own Google Drive.

Put a name behind every connection on your network.

50 subscribers for 7 days. You pay nothing.