Security as a managed service
Connectivity is a commodity.
Cybersecurity is the opportunity.
One VeeaHub STAX at the business location becomes enterprise-grade cybersecurity, secure managed Wi-Fi and device segmentation — then expands into video, AIoT and optional AI services on the same hub, remotely, with nothing new to install.
Small-business networks are an accumulation rather than a design. A router from the operator, a firewall someone specified, a VPN appliance for remote access, access points added as the business grew, a gateway for whatever the camera vendor shipped. Awareness of cyber risk is high; the ability to deploy and sustain real security across sites like these is not, and every product in that pile is another console, another firmware and another renewal date.
The usual site stack
Seven products. Several vendors, several bills, and nobody accountable for the site as a whole.
With SecureConnect on STAX
- Wi-Fi 6 & mesh
- Next-gen firewall
- ZTNA
- Micro-segmentation
- VPN & SD-WAN
- IoT radios
- Local recording
- Edge apps
Read the two sides as bills rather than as boxes: the left is seven renewal dates, seven firmware trains and seven support numbers, and no one of them is answerable for the site. The right is one subscription an operator already owns.
On a flat network every device can reach every other one, which is why a compromised guest phone is a payments problem. Trust Domains put the payment terminals, the staff machines, the cameras, the IoT controls and the visitors on separate policy islands — on the same hub, over the same Wi-Fi, with no extra hardware and nothing to configure per device.
-
Payments & POS
- Till
- Card terminal
-
Staff & servers
- Back office
- File server
-
Cameras
- Front of house
- Stockroom
-
IoT & controls
- Door lock
- Cold-chain sensor
-
Guest devices
- Guest phone
- Guest tablet
The compromised device cannot reach the site's other protected domains.
The compromised device reaches the card terminal.
Nothing about the site changes between these two pictures — same devices, same hub, same Wi-Fi, same one uplink. The difference is policy, and it is enforced on the hub rather than decided upstream, so it holds when the cloud link does not.
Four things the hub does to every device on the site, continuously and without anything installed on the device:
- Identify
- Isolate
- Connect
- Monitor
Who gets onVerified before it connects, and while it stays
Identity is checked at the door and re-checked for as long as the session lasts, without asking the device to cooperate.
- Zero-trust network access — every user and device verified before it connects
- Agentless assessment — legacy and IoT devices secured with no endpoint software
- Continuous authentication — security and connectivity run concurrently
What it can reachNothing by default, and only what policy opens
Reachability is a decision somebody made rather than an accident of subnetting, and it is made on the hub.
- Micro-segmentation — Trust Domains keep payments, staff, CCTV, IoT and guests apart
- Next-generation firewalling — application-aware inspection of business-critical traffic
- DNS and web filtering — malicious destinations blocked at the lookup stage
What is watchedBehavior, not just packets
A device that is allowed on and allowed through is still watched for behaving unlike itself.
- AI anomaly detection — per-device-class models flag deviation from learned patterns
- Next-gen VPN and SD-WAN — enhanced WireGuard tunnels across one site or thousands
- PCI and compliance support — segmentation and event history reduce scope and evidence it
Policies, profiles, apps and AI models are defined once in VeeaCloud and pushed to the fleet. Enforcement runs on every hub, locally, which is what makes protection independent of the uplink — and it is the difference between a security service and a security dashboard.
- Café VeeaHub STAX Enforcing
- Retail floor VeeaHub STAX Enforcing
- Pharmacy VeeaHub STAX Management link to VeeaCloud is down Enforcing
- Clinic VeeaHub STAX Enforcing
- Branch office VeeaHub STAX Enforcing
One of these sites cannot see VeeaCloud at all, and nothing in the row gives it away — every hub is enforcing the same policy either way, because the policy is already on it. That is what “enforced locally” buys: the cloud defines and observes, and it is never in the path of the decision. During a backhaul interruption, locally enforced policies continue to protect the site. Cloud visibility and synchronization resume when connectivity returns.
One console, however many sites
Every hub is provisioned, monitored and orchestrated from the Veea Control Center and VeeaHub Manager. Tenancy is per-operator, with role-based access and SSO, so a channel partner runs its own estate without seeing anybody else’s — one site or thousands, from the same console.
VeeaCloud platform services
- Provisioning
- Tenancy & groups
- Monitoring
- Subscriptions
- Authentication
- Device management
- App management
- Network management
- Cellular activation
- Alarms & events
- Certificates & images
- Analytics
The hub itself is built to the same standard as the policy it carries, and the same properties hold on every unit in the fleet — the full architecture is under platform cybersecurity.
- Chain of trust
- Signed certificates
- TLS everywhere
- Hardened host
- Unprivileged containers
For an operator, install time is cost. A non-technical person on site can stand up a fully segmented, AI-monitored network by doing almost nothing — VeeaCloud does the provisioning.
Owners do not think in sensors. They think about the vaccine refrigerator, the controlled-substances cabinet, the stockroom door and the cash register. SecureConnect protects the network; VeeaVision and AIoT extend that into the physical site, so cameras and sensors stop being separate systems and become one record of what happened.
Both systems, on the hub that already runs the network
VeeaVision runs on the same STAX with supported cameras and wired or wireless sensors — live viewing, local NVR-style recording, and rules that fire on what the sensors see. The footage and the readings are retained on site.
- Multi-camera analytics
- Configurable zones
- Event logic
- IoT data fusion
- Response workflows
- Local recording
- Event history
- Optional AI inferencing
Stockroom door, 23:14
- From the sensorWhich door, at what time, and that it was outside hours.
- From the cameraThe footage of that doorway at that moment, and only that moment.
- Recorded locally
- Alert sent
- Kept in history
Take either lane away and the record loses half of itself. Without the sensor it is a camera that recorded all night and knows nothing; without the camera it is an alert with no picture — and both of those are systems businesses already own and already ignore. The fusion happens on the hub, which is why the alert arrives with its own evidence attached.
Packaged for a single business location — the network profiles, the cameras and the sensor rules under one operating view — this is VigiLynx.
The opportunity is not the hardware. It is a repeatable managed-services portfolio an operator can explain, sell, deploy and grow over time — each stage activating on the hub that is already installed.
LandCybersecure connectivity
“Protect your business network and keep your site connected with one managed edge solution.”
- Enterprise-grade cybersecurity, ZTNA, next-gen firewalling, DNS and web filtering
- Segmentation, secure internet, managed business and guest Wi-Fi
- 5G primary or failover, SD-WAN, next-gen VPN, network slicing, remote management
- Replaces the router, firewall, VPN, Wi-Fi, switch, IoT gateway, server and storage
AttachAIoT monitoring and video
“See what’s happening, record what matters, and get alerted when an event needs attention.”
- VeeaVision on STAX with supported cameras and wired or wireless sensors
- Live viewing and local NVR-style recording, with 4+ camera streams on baseline bundles
- Sensor-triggered events, rules, alerts, dashboards, telemetry and event history
- Replaces standalone camera and NVR systems, alarm panels and disconnected sensor apps
ExpandOptional AI and intelligence
“Build a smarter business location today, on a platform ready for tomorrow’s intelligence services.”
- Fused event history across networking, video, sensors, edge apps and assets
- Reporting, pattern detection and vertical modules
- Optional AI inferencing on-premises, at a nearby edge, or in a regional cloud
- Replaces disconnected data and manual reporting
Every stage runs on the same VeeaONE Platform™ and the same hub, so a customer who starts with security in month one is a monitoring customer in month six without anybody visiting the site.
Cybersecure connectivity, device segmentation, edge applications, IoT support, monitoring and expansion services on one cloud-managed platform. This is what that looks like against the boxes an operator would otherwise assemble.
The same all-in-one STAX platform adapts to each of them, with operator-validated bundles by use case — one plug-and-play SKU rather than a custom project per site. The same device protects the corner café and the multi-site retailer.
Operators already hold the connectivity, the billing relationship, the support model and the service lifecycle — which is the whole reason cybersecurity can arrive as a managed service instead of as an add-on the customer never gets around to buying.
The VeeaONE Developer Portal and the VeeaHub Toolkit go further: with the built-in IoT gateway and optional inferencing, an operator can ship its own cloud-managed applications to the edge, on hardware that extends as the customer grows.