WaaS · Multi-tenant

One MSP.
Many independent ISPs.
Shared radio.

You own the outdoor network. Each of your customers runs a fully-independent ISP business on their own SSID — their pricing, their subscribers, their vouchers, their portal. Trafyx routes and isolates them all.

trafyx.ai / waas / ssid-routing
4 SSIDs live
Ruckus T350 MAC AA-BB-CC-DD-EE-FF CALLED-STATION-ID AA-BB-CC-DD-EE-FF: MARINA_CAFE AA-BB-CC-DD-EE-FF: CORNICHE_HOTEL AA-BB-CC-DD-EE-FF: DUNE_FIBRE AA-BB-CC-DD-EE-FF: GUEST_EVENT TENANT Marina Cafe WiFi plan: Guest 2h · AED 5 · voucher Corniche Hotel plan: Guest 24h · room-billed Dune Fibre plan: Home 100 · PPPoE · monthly Guest Event WiFi plan: 4hr pass · one-off FreeRADIUS policy · unlang · matches Called-Station-Id → sets Tmp-String-1 tenant_id
Why it matters

A gap the incumbents don't fill.

Traditional ISP platforms assume "one ISP, possibly multi-site." Trafyx WaaS assumes "one MSP, many independent ISP tenants sharing radio infrastructure." That's a real gap in the market, and it's where you'd land.

Tenant isolation

Row-level security in Postgres, plus per-tenant Supabase policies. A subscriber under Dune Fibre never sees Marina Cafe's data.

Per-tenant white-label portal

Each ISP tenant gets a branded subscriber portal at /portal/{slug}. Logo, colours, plan visibility all per tenant.

MSP super-admin

You see all tenants at once. Bill them per subscriber, per SSID, or per active session. Onboard a new ISP in minutes.

Voucher SMS delivery

For hospitality and event tenants — vouchers sent to guest phones on room check-in, ticket scan, or manual dispatch.

Fallback tenant

If a Called-Station-Id doesn't match any known SSID, RADIUS routes to a configurable default tenant. No silent auth failures.

Vendor-neutral SSID format

Ships parsing for Ruckus SmartZone. Plug-in patterns for Aruba, Ubiquiti, and Cisco Meraki are configurable.

Onboard a tenant

New ISP live in under 15 minutes.

01

Create the tenant

Name, slug, brand color, logo, contact. Trafyx provisions a Postgres schema record and portal route.

02

Map their SSIDs

Add every AP MAC + SSID combo that belongs to this tenant. Multiple APs, multiple SSIDs — all fine.

03

Configure their plans

Hotspot, PPPoE, prepaid — whatever this tenant sells. Optional: attach a reseller price book.

04

Reload the RADIUS policy

One systemctl reload freeradius-provix and the new SSIDs are routing.

MSPs, this one's for you

Serve every ISP on one platform.

The current build has been dogfooded on a live Ruckus SmartZone deployment. Ask for the reference call.