Every subscriber authenticated. Every megabit accounted for.
SmartGuard is the carrier-grade access control platform behind 5,000+ live networks. RADIUS authentication, branded captive portal, traffic shaping, firewall and usage-linked billing — one console, one vendor, one support number.
- Deployed in 11 countries
- Vendor-neutral RADIUS
- On-premise or cloud
Four tools, four vendors, and still no answer to “who used the bandwidth?”
Most networks bolt authentication, shaping, filtering and billing together from separate products. The seams are where revenue, visibility and support hours disappear.
Bandwidth anarchy
A handful of heavy users saturate the pipe while paying customers see degraded service. Without per-user shaping, capacity upgrades only buy you a few months.
Anonymous access
Devices join the network with no identity attached. When a compliance request or an incident lands, there is no defensible session record to hand over.
Vendor sprawl
A RADIUS server here, a portal appliance there, a firewall from a third vendor, billing in a spreadsheet. Every integration is a support ticket waiting to happen.
Revenue leakage
Usage data never reaches the invoice. Expired packages keep working, renewals get missed, and the difference is written off as churn.
One console for the entire access layer
Six subsystems that ship together, share one subscriber record, and are administered from a single interface.
AAA / RADIUS authentication
Native RADIUS authentication, authorisation and accounting with Change-of-Authorisation support. Drops into existing NAS estates without re-architecting the network.
Branded captive portal
Fully themed login journeys with OTP, voucher, social, PMS and Aadhaar-backed onboarding. Different portals per SSID, site or tenant from one installation.
Bandwidth orchestration
Shape, throttle and prioritise at IP, port, package and application level. Burst windows, fair-use thresholds and guaranteed floors for the traffic that cannot slow down.
Multi-layer firewall & filtering
Client-level policy enforcement, category-based content filtering, gateway anti-virus and anti-spam. Compliance-ready logging for regulated and public networks.
Subscriber & package management
Build packages with defined speed, data quota and validity. Automated renewal, grace periods, suspension and top-ups — enforced on the network, not on trust.
Billing & support desk
Invoices generated straight from accounting data, prepaid and postpaid, with taxes and payment gateway hooks. Integrated ticketing so support sees the session and the bill together.
What happens in the 400 ms after a device connects
The same path for a hostel laptop, a hotel guest phone and a corporate handset — only the policy differs.
Associate
Device attaches to the NAS — MikroTik, Cisco, Cambium, Ubiquiti or any RADIUS-capable gateway.
Authenticate
Credentials, OTP, voucher or MAC bypass are validated against the SmartGuard AAA store or your directory.
Authorise
The subscriber's package resolves into a live policy: speed floors and ceilings, quota, filtering profile, session limits.
Enforce
Traffic is shaped and filtered in real time. Threshold breaches trigger a CoA — no reconnect required.
Account
Every byte and minute lands in accounting, feeding invoices, usage reports and the compliance log.
Shaping that survives peak hour
Contention is a policy problem, not a capacity problem. SmartGuard lets you sell the same pipe to more subscribers while protecting the experience of every one of them.
- Guaranteed floors. Reserve throughput for VoIP, CCTV, ERP or exam portals so they never contend with recreational traffic.
- Burst then settle. Give subscribers headline speeds for the first seconds of a transfer, then settle to the committed rate.
- Fair-use enforcement. Automatic step-down at the quota line, with the subscriber notified and offered a top-up.
- Time-of-day profiles. Different rules for business hours, night windows and scheduled backup periods.
Policy classes are defined once and inherited by every package, site and tenant beneath them.
A portal your marketing team is happy to put a logo on
The captive portal is the first thing a subscriber sees. SmartGuard treats it as a product surface, not a config screen — and as a compliance checkpoint at the same time.
- Any auth method. Username, OTP over SMS or email, prepaid voucher, social login, PMS room-number match, or H.A.R.T. eKYC for regulated onboarding.
- Per-tenant themes. One deployment can serve dozens of branded portals — ideal for operators, malls and managed campuses.
- Consent & retention built in. Terms acceptance, log retention windows and lawful-intercept-ready records for public Wi-Fi obligations.
- Monetisable. Sponsored splash pages, upsell offers and voucher sales run through the same journey.
Median time from association to authorised session across production deployments: under four seconds.
Same platform, six very different networks
Packages, portals and policies are configuration — not custom builds. That is why one codebase serves an ISP in Lagos and a university in Noida.
Internet service providers
Tiered packages, prepaid recharge, self-care portal and automated suspension for non-payment — at ISP-grade session counts.
Cable & broadband operators
Multi-service households, bundled voice and data allocation, and franchise-level billing separation across regions.
Enterprise campuses
Departmental policy, contractor quarantine, guest networks isolated from corporate VLANs, and AD-linked identity.
Education & hostels
Student, faculty and hostel segregation, exam-mode profiles, content filtering and per-block fair-use enforcement.
Hotels & hospitality
PMS integration for room-number login, tiered guest plans, conference-room bandwidth and branded splash per property.
Government & public Wi-Fi
City-scale hotspot networks with eKYC onboarding, mandated log retention and audit-ready session records.
Built to sit in someone else’s network
SmartGuard is deliberately vendor-neutral. If your gateway speaks RADIUS, it speaks SmartGuard — which means no forklift upgrade and no lock-in on the hardware you already own.
- Proven at ISP scale — sized deployments running thousands of concurrent subscribers per node, with horizontal scale-out.
- High availability — active/passive or active/active pairs with database replication and stateful failover.
- Open integration — REST APIs and webhooks for provisioning, payments, CRM and the wider XS platform.
| Authentication | RADIUS (PAP/CHAP/MSCHAPv2), 802.1X, MAC bypass, LDAP / Active Directory, OTP, voucher, social, eKYC |
|---|---|
| Policy control | RFC 3576 Change-of-Authorisation, dynamic VLAN assignment, per-session rate limits |
| Traffic control | Per IP / port / package / application shaping, burst, FUP step-down, time-of-day profiles |
| Security | Stateful firewall, category content filtering, gateway anti-virus, anti-spam, reverse proxy |
| Tested gateways | MikroTik Cisco Juniper Ubiquiti Cambium Ruckus Aruba |
| Deployment | Bare metal, VM, private cloud or XS-managed. Linux-based appliance image available. |
| Interfaces | Admin console, subscriber self-care portal, franchise/reseller panel, REST API |
| Compliance | Configurable log retention, session audit trail, consent capture, lawful-intercept-ready exports |
The people who wrote it are the people who answer the phone
Thirty years, one focus
XS Infosol has been building network and billing software since 1995. SmartGuard is not a side product — it is the platform the company was built around.
Engineering-level support
Escalations reach the core team, in your timezone, with local presence across India, the UAE, Africa, Canada and the USA — not a follow-the-sun ticket queue.
One platform, not four
SmartGuard shares its subscriber record with B.O.S.S. billing, NMS monitoring and H.A.R.T. eKYC. Adding a capability means enabling a module, not signing another vendor.
Before you talk to sales
Almost certainly. SmartGuard is RADIUS-native and vendor-neutral — it has been deployed against MikroTik, Cisco, Juniper, Ubiquiti, Cambium, Ruckus and Aruba estates, often mixed within the same network. If your gateway supports RADIUS authentication and accounting, no hardware change is required.
Production deployments run thousands of concurrent sessions per node, and the architecture scales horizontally for larger estates — we have sized systems for public Wi-Fi rollouts spanning 1,500+ access points. Our team will size the deployment against your actual session, throughput and accounting-write volumes before you commit.
Yes. SmartGuard runs on bare metal, in your own virtualisation estate, in a private cloud, or as an XS-managed service — the same build in every case. Operators with data localisation obligations typically choose on-premise with XS providing remote support and AMC.
SmartGuard generates invoices directly from RADIUS accounting data and exposes REST APIs and webhooks for payment gateways, CRM and ERP. For operators who need full OSS/BSS — service catalogue, provisioning, revenue assurance — SmartGuard hands off natively to B.O.S.S. rather than duplicating it.
A single-site enterprise or campus deployment is usually live within days of the environment being ready. Multi-site operator rollouts run as a phased project with a pilot region first. Every engagement starts with a trial licence on your own network, so the platform is proven against your traffic before any commercial commitment.
Administrator training is part of every deployment, and annual maintenance contracts cover version upgrades, security patches and direct escalation to the engineering team. Partners and resellers receive additional enablement, including deployment playbooks and a dedicated technical contact.
Run SmartGuard against your own traffic.
Request a trial licence and our engineers will help you stand it up on your network, with your gateways and your packages — before any commercial conversation.