NetStacksNetStacks

Credentials never touch your laptops

The NetStacks Controller owns all credentials, proxies every SSH connection, and logs every action. Your engineers connect to devices without ever seeing a password. That's not a feature — it's the architecture.

AES-256-GCMEncryption
12+Permissions
ZeroStanding Privileges
100%Audit Coverage

How it works: Controller-Proxied SSH

Engineer
Desktop or Browser
Authenticate
Controller
  • Auth & SSO
  • Credential Vault
  • SSH Proxy
  • Audit Engine
  • Session Recording
Proxied SSH
Network Devices
Routers, Switches, Firewalls
Credentials stay server-side. They live in the Controller's AES-256-GCM encrypted vault. Engineers connect to devices without seeing passwords or keys.
Every session is auditable. Every command can be recorded. The Controller is the single point of audit and compliance.
Access from anywhere. Native desktop app (macOS, Windows, Linux) or directly in any web browser. No VPN needed when the Controller is your gateway.

Teams & Enterprise run on the Controller

The free standalone app is full-featured for one engineer. The Controller is the shared server where the team capabilities live — shared memory, knowledge, automation, and resilient sessions for everyone.

Shared AI Knowledge Base (RAG)

An org-wide retrieval-augmented knowledge base — runbooks, configs, and indexed session history. Every engineer's AI draws on the same institutional knowledge, with embeddings generated locally on the Controller.

Shared Device Memory & Ticketing

Device history, incidents, root causes, and linked tickets live on the Controller and are shared across the team. Open a session to a device with a recent issue and it's flagged on the spot — and fed into that device's AI context.

Config Templates & Service Stacks

Versioned Jinja2 templates with automatic variable extraction, plus multi-device service stacks you can deploy, track, and roll back — with optional MOP-gated change control.

AI Alert Ingestion

Ingest alerts from syslog, SNMP traps, webhooks, and Kafka. Deduplicate, route, and escalate them through a pipeline — with LLM-powered analysis that can trigger NOC agents and open incidents.

Per-User Isolated Containers

Each engineer gets their own isolated jumpbox container on the Controller — a clean, tool-equipped bastion for reaching devices, with no shared shell state and full audit.

Multi-Session Multiplexing & Resilient Sessions

The Controller multiplexes and brokers sessions across nodes, so connections survive client disconnects and reconnects. Share live sessions read-only or read-write, and pick up where you left off.

Controller SSH Proxy

The architectural advantage — credentials never leave the server

All SSH connections route through the Controller. Credentials are fetched from the encrypted vault at connection time and stay in server memory — they never reach the engineer's laptop or browser. This means a compromised endpoint cannot leak your network passwords.

The browser-based terminal provides the same experience as the desktop app: AI assistant, session management, multi-send, and topology views. No install required — just a browser and your SSO credentials.

  • Credentials never on endpoints — zero exposure surface
  • Browser terminal — no install, same full feature set
  • Every session automatically recorded and indexed
  • Integrates with your existing SSO provider
connection-flow.shShell
# 1. Engineer authenticates to Controller
$ netstacks login --sso okta
✓ Authenticated via SAML (session: 8h)

# 2. Controller fetches credentials from vault
# → AES-256-GCM decrypt, Argon2 key derivation
# → Credentials stay in server memory only

# 3. Proxied SSH session established
$ netstacks connect core-rtr-01
✓ SSH proxy active (recording: enabled)

router-01# show ip bgp summary
Neighbor     AS  MsgRcvd  MsgSent  State
10.0.0.1  65001    12045    11982  Established
10.0.0.2  65002     8891     8820  Established

# 4. Session recorded, audit logged
# → Every command indexed and searchable

Defense in Depth

Five layers of security from transport to audit — each reinforcing the next

L5

Audit & Monitoring

Every action logged. Session recording with command indexing. SIEM export to Splunk, Elastic, QRadar.

L4

Access Control

RBAC with 12+ granular permissions. Custom roles. Approval workflows for privileged operations.

L3

Authentication

SSO via SAML, OIDC, LDAP. MFA enforcement. Short-lived SSH certificates from built-in CA.

L2

Credential Management

AES-256-GCM encrypted vault with Argon2 key derivation. Zero standing privileges. Folder-based access.

L1

Transport Security

All SSH connections proxied through Controller. TLS 1.3 for API and browser. Credentials never leave the server.

Identity & Access Control

Granular RBAC with custom roles matching your org

Built-in Admin, Operator, and Viewer roles cover common needs out of the box. Create custom roles to match your org — give network operators device and template access, security teams audit and credential management, and juniors read-only visibility.

Integrates with your identity provider via SAML 2.0, OpenID Connect, or LDAP. Single sign-on across the platform with MFA enforcement. Users from Okta, Azure AD, Google Workspace, and Active Directory authenticate seamlessly.

  • 12+ granular permissions across all platform areas
  • Custom roles with any permission combination
  • SSO via SAML, OIDC, LDAP — works with your IdP
  • Approval workflows for privileged operations
PermissionAdminOperatorViewer
Devices✓✓✓
Credentials✓——
Templates✓✓—
Stacks✓✓—
Tasks✓✓✓
MOPs✓✓—
AI Assistant✓✓✓
NOC Agents✓——
Users✓——
Settings✓——
Audit Logs✓——
Session Recording✓✓✓

Every action logged. Every session recorded.

Comprehensive audit trail with SIEM integration and mandatory session recording

Full Audit Logging

Every login, device connection, config change, credential access, and settings modification creates an immutable audit entry. Filter by user, action type, date range, or target device. Retain logs for as long as your compliance policy requires.

SIEM Export

Export audit data as JSON or CSV to Splunk, Elastic, or QRadar. Configure date ranges, event type filters, and scheduled exports. Feed your existing security dashboards without changing your workflow.

Session Recording

Enforce recording by device type, user role, or specific device groups. Centralized storage on the Controller with command-level indexing — search for any command across all recorded sessions.

Config Snapshots

Capture device configurations on schedule or on-demand. Visual diff across time periods to track drift, identify unauthorized changes, and restore previous known-good state with one click.

Shared Device Memory

Your team's tribal knowledge, attached to the device

NetStacks is not a terminal with AI bolted on. The device session is the context — and in Enterprise mode, every device's memory is shared across your organization. Incidents, root causes, standing instructions, and linked tickets live with the device, not in one engineer's head.

When anyone opens a session to a device that had an issue two weeks ago, NetStacks flags it on the spot — surfacing the ticket number, what happened, and how it was resolved. The same history is fed into that device's AI context (run through mandatory credential sanitization), so the assistant reasons with the full backstory. New team members walk into context instead of starting blind.

  • Org-wide device memory with RBAC and audit
  • Prior incidents flagged automatically on session open
  • Linked tickets from ServiceNow and Jira
  • Sanitized before it ever reaches the AI provider
session-open.logSession
$ netstacks connect core-rtr-01
⚠  Device flagged — 2 prior incidents (shared across org)

  INC-4821   14 days ago   BGP flap to AS 65002
    root cause: MTU mismatch on Te0/1/0 (carrier change)
    resolved:   mtu 9192 + clear bgp neighbor 10.0.0.2
    standing:   verify MTU before touching this peer
    owner:      j.rivera   ·   ticket: ServiceNow INC-4821

  CHG-2290   6 weeks ago   IOS-XR upgrade to 7.10.2

→ context loaded into this device's AI (credentials sanitized)
router-01#
Deployment Options

Deploy how you need to — cloud, on-prem, or air-gapped

The Controller is a single binary that runs on Linux, in Docker, or on Kubernetes. Choose the deployment model that matches your security posture — from fully air-gapped on-premises to cloud-hosted with browser access.

Configuration snapshots capture device configs on schedule. Visual diff shows changes across time periods — track drift, identify unauthorized modifications, and restore previous state. Bulk operations let you manage hundreds of devices from a single console.

  • Single binary — simple to deploy and maintain
  • Full air-gap support — no outbound internet required
  • Config snapshot and diff for change tracking
  • Bulk operations across your entire inventory

On-Premises

Full control. Deploy within your network perimeter on bare metal, VM, or container. No data leaves your environment. Air-gap ready.

Cloud / Hybrid

Run the Controller in your cloud VPC. Engineers connect via browser or desktop app. Same security model, flexible deployment.

LinuxDockerKubernetesAir-Gapped

Built for regulated environments

NetStacks provides the controls and audit capabilities required for compliance with industry standards

SOC 2HIPAAPCI DSSNIST 800-53CIS Benchmarks

Frequently asked questions

Ready to evaluate NetStacks for your organization?

See the Controller architecture in action. Schedule a demo or start a free trial.