Get started with Veea

Tell us about your sites and what you want to run on them, and a Veea team member will follow up.

Prefer the full page? Go to Contact.

Security as a managed service

Connectivity is a commodity.
Cybersecurity is the opportunity.

One VeeaHub STAX at the business location becomes enterprise-grade cybersecurity, secure managed Wi-Fi and device segmentation — then expands into video, AIoT and optional AI services on the same hub, remotely, with nothing new to install.

A VeeaHub STAX on a café shelf beside the equipment it replaces
VeeaHub STAX with integrated 5G
  • Zero-trust access
  • Micro-segmentation
  • Next-gen firewall
  • DNS & web filtering
  • AI anomaly detection
  • Next-gen VPN
  • SD-WAN
  • Network slicing
  • 5G primary or failover
  • Managed guest Wi-Fi
  • Local NVR recording
  • Sensor rules & alerts
  • Edge apps
  • Remote management
  • Router
  • Firewall
  • VPN appliance
  • Wi-Fi access points
  • Switch
  • IoT gateway
  • Camera / NVR
  • Local storage
  • Alarm panel
  • SD-WAN box
  • Content filter
  • A second support contract
At a glance

One hub at the site, and the day it arrives it works

  • One platform

    Cybersecurity, secure Wi-Fi, edge compute, IoT radios and storage converge in one compact hub.

  • Plug and play

    It ships to the site, powers on, and self-provisions from VeeaCloud in minutes.

  • Secure by design

    Security embedded at every layer, with cloud-managed policy enforced locally on the hub.

  • Built to expand

    Video, AIoT and optional AI services activate on hardware already deployed.

The gap

Seven products, several vendors — or one hub

Small-business networks are an accumulation rather than a design. A router from the operator, a firewall someone specified, a VPN appliance for remote access, access points added as the business grew, a gateway for whatever the camera vendor shipped. Awareness of cyber risk is high; the ability to deploy and sustain real security across sites like these is not, and every product in that pile is another console, another firmware and another renewal date.

The usual site stack

Router
Firewall
VPN appliance
Wi-Fi access points
Switch
IoT gateway
Camera / NVR and storage

Seven products. Several vendors, several bills, and nobody accountable for the site as a whole.

With SecureConnect on STAX

One device
  • Wi-Fi 6 & mesh
  • Next-gen firewall
  • ZTNA
  • Micro-segmentation
  • VPN & SD-WAN
  • IoT radios
  • Local recording
  • Edge apps
One platform, one bill, one accountable party. It ships to the site, auto-configures on arrival, and is fully operational the same day.

Read the two sides as bills rather than as boxes: the left is seven renewal dates, seven firmware trains and seven support numbers, and no one of them is answerable for the site. The right is one subscription an operator already owns.

Trust Domains

A breach that stays where it started

On a flat network every device can reach every other one, which is why a compromised guest phone is a payments problem. Trust Domains put the payment terminals, the staff machines, the cameras, the IoT controls and the visitors on separate policy islands — on the same hub, over the same Wi-Fi, with no extra hardware and nothing to configure per device.

The same site, two policies
Click to compare
  • Payments & POS

    • Till
    • Card terminal
    Isolated Reachable
  • Staff & servers

    • Back office
    • File server
    Isolated Reachable
  • Cameras

    • Front of house
    • Stockroom
    Isolated Reachable
  • IoT & controls

    • Door lock
    • Cold-chain sensor
    Isolated Reachable
  • Guest devices

    • Guest phone
    • Guest tablet
    One device compromised

The compromised device cannot reach the site's other protected domains.

The compromised device reaches the card terminal.

Nothing about the site changes between these two pictures — same devices, same hub, same Wi-Fi, same one uplink. The difference is policy, and it is enforced on the hub rather than decided upstream, so it holds when the cloud link does not.

Four things the hub does to every device on the site, continuously and without anything installed on the device:

  • Identify
  • Isolate
  • Connect
  • Monitor

Who gets onVerified before it connects, and while it stays

Identity is checked at the door and re-checked for as long as the session lasts, without asking the device to cooperate.

  • Zero-trust network access — every user and device verified before it connects
  • Agentless assessment — legacy and IoT devices secured with no endpoint software
  • Continuous authentication — security and connectivity run concurrently

What it can reachNothing by default, and only what policy opens

Reachability is a decision somebody made rather than an accident of subnetting, and it is made on the hub.

  • Micro-segmentation — Trust Domains keep payments, staff, CCTV, IoT and guests apart
  • Next-generation firewalling — application-aware inspection of business-critical traffic
  • DNS and web filtering — malicious destinations blocked at the lookup stage

What is watchedBehavior, not just packets

A device that is allowed on and allowed through is still watched for behaving unlike itself.

  • AI anomaly detection — per-device-class models flag deviation from learned patterns
  • Next-gen VPN and SD-WAN — enhanced WireGuard tunnels across one site or thousands
  • PCI and compliance support — segmentation and event history reduce scope and evidence it
Cloud controlled, edge executed

The policy does not live in the cloud. It only comes from there.

Policies, profiles, apps and AI models are defined once in VeeaCloud and pushed to the fleet. Enforcement runs on every hub, locally, which is what makes protection independent of the uplink — and it is the difference between a security service and a security dashboard.

Defined here VeeaCloud Control Center · VeeaHub Manager · per-operator tenancy
  • Café VeeaHub STAX Enforcing
  • Retail floor VeeaHub STAX Enforcing
  • Pharmacy VeeaHub STAX Management link to VeeaCloud is down Enforcing
  • Clinic VeeaHub STAX Enforcing
  • Branch office VeeaHub STAX Enforcing

One of these sites cannot see VeeaCloud at all, and nothing in the row gives it away — every hub is enforcing the same policy either way, because the policy is already on it. That is what “enforced locally” buys: the cloud defines and observes, and it is never in the path of the decision. During a backhaul interruption, locally enforced policies continue to protect the site. Cloud visibility and synchronization resume when connectivity returns.

One console, however many sites

Every hub is provisioned, monitored and orchestrated from the Veea Control Center and VeeaHub Manager. Tenancy is per-operator, with role-based access and SSO, so a channel partner runs its own estate without seeing anybody else’s — one site or thousands, from the same console.

VeeaCloud platform services

  • Provisioning
  • Tenancy & groups
  • Monitoring
  • Subscriptions
  • Authentication
  • Device management
  • App management
  • Network management
  • Cellular activation
  • Alarms & events
  • Certificates & images
  • Analytics
The Veea Control Center on a laptop, tablet and phone

The hub itself is built to the same standard as the policy it carries, and the same properties hold on every unit in the fleet — the full architecture is under platform cybersecurity.

  • Chain of trust
  • Signed certificates
  • TLS everywhere
  • Hardened host
  • Unprivileged containers
Deploy

The whole installation is plugging it in

For an operator, install time is cost. A non-technical person on site can stand up a fully segmented, AI-monitored network by doing almost nothing — VeeaCloud does the provisioning.

  1. Connect the WAN

    The hub powers on and auto-registers with VeeaCloud over fiber or 5G.

  2. Apply the IoT profile

    Pre-curated profiles classify each device and place it in the right Trust Domain.

  3. Enforce policy

    Cloud-managed ZTNA, micro-segmentation, Wi-Fi and AI monitoring come online automatically.

  4. Manage anywhere

    One site or thousands, from the same console.

No firewall configuration, no port forwarding, no specialist visit — an operator adds a SKU rather than starting a project.

AIoT asset intelligence

The sensor knows that. The camera knows what.

Owners do not think in sensors. They think about the vaccine refrigerator, the controlled-substances cabinet, the stockroom door and the cash register. SecureConnect protects the network; VeeaVision and AIoT extend that into the physical site, so cameras and sensors stop being separate systems and become one record of what happened.

Two cameras beside an operator-branded VeeaHub STAX

Both systems, on the hub that already runs the network

VeeaVision runs on the same STAX with supported cameras and wired or wireless sensors — live viewing, local NVR-style recording, and rules that fire on what the sensors see. The footage and the readings are retained on site.

  • Multi-camera analytics
  • Configurable zones
  • Event logic
  • IoT data fusion
  • Response workflows
  • Local recording
  • Event history
  • Optional AI inferencing
The sensor knows that Stockroom door Opened at 23:14, outside trading hours. It cannot tell you by whom.
The camera knows what Stockroom camera Recording the doorway all night. It cannot tell you which moment mattered.
One event

Stockroom door, 23:14

  • From the sensorWhich door, at what time, and that it was outside hours.
  • From the cameraThe footage of that doorway at that moment, and only that moment.
  • Recorded locally
  • Alert sent
  • Kept in history

Take either lane away and the record loses half of itself. Without the sensor it is a camera that recorded all night and knows nothing; without the camera it is an alert with no picture — and both of those are systems businesses already own and already ignore. The fusion happens on the hub, which is why the alert arrives with its own evidence attached.

Packaged for a single business location — the network profiles, the cameras and the sensor rules under one operating view — this is VigiLynx.

The difference

Architectural, not a better bundle

  • What that gets you A site goes live the day it arrives
    The usual site A multi-vendor configuration project per site, with a technician on the ground.
    With SecureConnect One SKU ships, powers on, and self-provisions from the cloud.
  • What that gets you Protection that holds when the uplink does not
    The usual site Security bolted on after the network, and decided upstream.
    With SecureConnect Policy defined once in the cloud, enforced locally on the hub.
  • What that gets you A compromise stays where it started
    The usual site One flat network, where a camera and a card reader share a subnet.
    With SecureConnect Trust Domains isolate payments, staff, CCTV, IoT and guests.
  • What that gets you New services without a truck roll
    The usual site Every added service means new hardware and another visit.
    With SecureConnect Monitoring, AIoT and AI activate remotely on the hub already on site.
  • What that gets you One party owns the whole site
    The usual site Several vendors, several bills, and no single point of accountability.
    With SecureConnect One operator-owned subscription, on the bill the customer already pays.
The portfolio

Secure the site. Monitor what matters. Understand the business.

The opportunity is not the hardware. It is a repeatable managed-services portfolio an operator can explain, sell, deploy and grow over time — each stage activating on the hub that is already installed.

LandCybersecure connectivity

“Protect your business network and keep your site connected with one managed edge solution.”

  • Enterprise-grade cybersecurity, ZTNA, next-gen firewalling, DNS and web filtering
  • Segmentation, secure internet, managed business and guest Wi-Fi
  • 5G primary or failover, SD-WAN, next-gen VPN, network slicing, remote management
  • Replaces the router, firewall, VPN, Wi-Fi, switch, IoT gateway, server and storage

AttachAIoT monitoring and video

“See what’s happening, record what matters, and get alerted when an event needs attention.”

  • VeeaVision on STAX with supported cameras and wired or wireless sensors
  • Live viewing and local NVR-style recording, with 4+ camera streams on baseline bundles
  • Sensor-triggered events, rules, alerts, dashboards, telemetry and event history
  • Replaces standalone camera and NVR systems, alarm panels and disconnected sensor apps

ExpandOptional AI and intelligence

“Build a smarter business location today, on a platform ready for tomorrow’s intelligence services.”

  • Fused event history across networking, video, sensors, edge apps and assets
  • Reporting, pattern detection and vertical modules
  • Optional AI inferencing on-premises, at a nearby edge, or in a regional cloud
  • Replaces disconnected data and manual reporting

Every stage runs on the same VeeaONE Platform™ and the same hub, so a customer who starts with security in month one is a monitoring customer in month six without anybody visiting the site.

Side by side

Everyone sells a firewall. Convergence is the difference.

Cybersecure connectivity, device segmentation, edge applications, IoT support, monitoring and expansion services on one cloud-managed platform. This is what that looks like against the boxes an operator would otherwise assemble.

Capability Firewall appliance Standalone hardware firewall Cellular router SD-WAN / LTE gateway SSE service Cloud-delivered security service edge Veea SecureConnect On VeeaHub STAX
Zero-trust architecture — no device connects without permission Yes No Yes
Agentless — every device secured with no software loaded on it No No No
Edge computing — runs secure apps such as CCTV on the same hub No No No
Computing and networking mesh — Wi-Fi coverage plus on-prem compute No No No
IoT and legacy device support — segmented, isolated and managed Partial Partial No
DNS and web filtering with ML — blocked at the lookup stage Partial Yes No
Monitoring — security and connectivity concurrent, with app awareness Partial Yes Yes
Where it runs

The places people actually run a business

The same all-in-one STAX platform adapts to each of them, with operator-validated bundles by use case — one plug-and-play SKU rather than a custom project per site. The same device protects the corner café and the multi-site retailer.

For operators and channel

You already own the site. This is what to sell into it.

Operators already hold the connectivity, the billing relationship, the support model and the service lifecycle — which is the whole reason cybersecurity can arrive as a managed service instead of as an add-on the customer never gets around to buying.

  • One bill, one brand

    Operator-owned end to end, bundled into the bill the customer already pays.

  • Expand with no new hardware

    Monitoring, AIoT and AI activate remotely on a hub that is already on site.

  • Data stays local

    Cloud-managed, locally processed — privacy, sovereignty and compliance evidence.

  • A service that sticks

    A site running several managed services does not churn for a cheaper pipe.

  • Thousands of sites, one pane

    Provision, monitor and orchestrate the whole estate from VeeaCloud.

The VeeaONE Developer Portal and the VeeaHub Toolkit go further: with the built-in IoT gateway and optional inferencing, an operator can ship its own cloud-managed applications to the edge, on hardware that extends as the customer grows.

Answers

What SecureConnect gives an operator

What does the customer actually have to do?

Connect the hub to the internet. That is the installation. It powers on, auto-registers with VeeaCloud over fiber or 5G, inventories the cameras, terminals, sensors and locks on the site, classifies each one against a pre-curated IoT profile, and places it in the right Trust Domain. Policy, Wi-Fi and AI monitoring come online on their own. There is no firewall configuration and no port forwarding, and a site is normally live the same day it arrives.

What happens when the uplink or the cloud goes down?

Two different answers, and both matter. If the primary connection drops, integrated 5G takes over as failover automatically. If the cloud management link drops, enforcement carries on regardless — policies, segmentation and filtering run on the hub itself rather than being decided upstream, which is the point of enforcing at the edge rather than in a cloud.

Do endpoints need an agent installed?

No, and that is deliberate. Identification, assessment, segmentation and isolation are all agentless — which is the only workable answer for the devices that most need segmenting, since payment terminals, cameras, locks and sensors will not accept software you write.

How does an operator brand it and bill it?

The service is operator-owned end to end and lands on the bill the customer already pays. VeeaCloud is multi-tenant by design, with per-tenant isolation, role-based access and SSO integration, so a channel partner runs its own estate without seeing anybody else’s. Pricing, packaging and the upsell path are yours.

What is in the hub, and can it grow?

Wi-Fi 6 with mesh, Zigbee and Thread, Bluetooth 5.x, dual Ethernet, integrated 5G on 5G models, quad-core compute, microSDXC, NVMe up to 2 TB and a secured container runtime for edge applications. It is the VeeaHub STAX, so a site that needs more storage, PoE or cellular specifies the module with the order. The same Developer Portal and Toolkit let an operator ship its own applications to that runtime.

How do we add video and sensors later?

Remotely, on the hub already installed. VeeaVision runs on the same STAX with supported cameras and wired or wireless sensors — live viewing, local NVR-style recording with 4+ camera streams on baseline bundles, sensor-triggered events, rules, alerts, dashboards and event history. That is an activation rather than a visit, which is what makes the second stage worth selling.

Turn connectivity into a cybersecurity-led managed service.

Start with SecureConnect on one site, then expand into VeeaVision, AIoT and optional AI services on the same platform.