Coming Soon — Join the Early Access Programme

Network Access Control,
Reinvented

NACIO is enterprise-grade network access control software — 802.1x RADIUS, device profiling, compliance enforcement, and captive portals. Deploy self-hosted on your own infrastructure or via our cloud-hosted service, without the vendor lock-in.

Request Early Access → ▶ See it in action
0+
Authentication Sources
0k+
Endpoints Supported
0 min
Time to First Auth
0%
Self-Hosted or Cloud
💸

Perpetual licensing — buy once per major version

NACIO is sold as a perpetual per-device license tied to a major version. Buy it once and run it forever — no annual subscription required to keep using what you paid for. Upgrades to the next major version are optional.

🔒

Deploy your way — on-premise or cloud

Run NACIO fully self-hosted on your own infrastructure, or use a NACIO cloud-hosted instance. Either way, remote agents connect back over encrypted tunnels — no exposed ports, no third-party auth traffic.

🧩

Complex deployments taking weeks?

Most NAC platforms require professional services to deploy. NACIO has a built-in setup wizard — from install to first authenticated device in minutes.

📦

One vendor for everything?

NACIO integrates with any RADIUS-capable switch, AP, or firewall. Active Directory, LDAP, Azure AD, SAML, Google — pick your identity source.

Everything a modern network
access control platform needs

NACIO ships as a complete, self-contained NAC solution. No separate RADIUS server. No separate portal server. No sprawl.

🔐

Full-Featured RADIUS Server

Built-in RADIUS with the complete EAP stack — EAP-TLS, PEAP-MSCHAPv2, EAP-TTLS, EAP-FAST, and CHAP. Handles wired 802.1x, wireless, and VPN simultaneously with per-realm policy routing and real-time auth logs.

🏛️

Agent-Based PKI & Certificate Authority

NACIO ships with a complete internal CA. Issue and manage machine certificates and user certificates directly from the console. Deploy via agent to Windows and macOS — fully automates EAP-TLS without any third-party PKI.

☁️

Azure AD, SAML & Identity Federation

Connect Active Directory, Azure AD, Okta, Google Workspace, Entra ID, SAML 2.0, LDAP, RADIUS proxy, and NACIO's local user DB. Mix identity sources per realm — use cert auth for corporate, SAML for BYOD, local for guests.

🖥️

Device Profiling & Fingerprinting

Automatically classify endpoints by OS, vendor, and device type using DHCP fingerprinting, HTTP user-agent, and network behaviour analysis. Profiling runs entirely on your own infrastructure — or leverage NACIO's cloud-assisted profiling service to cross-reference a continuously updated device signature database without sending any sensitive data off-site.

📋

Remote Agent — Self-Hosted or Cloud

The NACIO agent runs on Windows and macOS to verify patch level, antivirus, disk encryption, firewall status, and custom rules before granting access. Deploy in fully self-hosted mode — agents phone home to your on-premise NACIO server — or connect to a NACIO cloud-hosted instance for organisations that prefer a managed control plane with no on-site server to maintain.

🌐

Captive Portal

Fully customisable guest portals with sponsor approval, SMS/email verification, social login, and time-limited access. Works with any CAPWAP-compatible access point.

🗺️

Remote Probes via Secure Tunnels

Deploy lightweight probe agents at remote sites over encrypted secure tunnels — no VPN or open firewall ports required. Install directly from the NACIO console and the probe establishes an outbound encrypted connection back, extending full NAC enforcement to branch offices, remote sites, and air-gapped segments.

🏢

Multi-Organisation

Segment policies, portals, and endpoints by organisation. Ideal for MSPs managing multiple clients from a single NACIO deployment.

Policy Engine & Dynamic VLAN

Assign users and devices to VLANs, ACLs, and bandwidth policies based on identity, device type, compliance posture, time-of-day, and location.

📡

DHCP Server Integration

Built-in DHCP server with scope management and lease tracking, or integrate with your existing infrastructure. DHCP fingerprinting feeds directly into device profiling.

🔍

Network Discovery & Scanner

Active and passive network scanning to discover every device on your subnets — including those that never authenticate. NACIO maps IP ranges, resolves hostnames, fingerprints open ports and services, and flags rogue or unmanaged devices before they become a threat. Discovery results feed directly into the endpoint inventory and profiling engine.

📊

Real-Time Dashboard

Live view of authentication activity, endpoint health, compliance status, and network events. Drill down from any metric to the individual endpoint or user.

🔄

High Availability

Active-passive HA with automatic failover so authentication is never a single point of failure. State is continuously synchronised across nodes — sessions, leases, and endpoint records persist through a failover. Deploy two NACIO nodes behind a load balancer or use built-in heartbeat-based promotion with no manual intervention required.

Works with the gear you already own

NACIO speaks standard RADIUS — if it supports 802.1x, it works with NACIO. No proprietary integrations required.

Switching & Wired
Cisco Catalyst Cisco Nexus Juniper EX HPE / Aruba Arista EOS Dell N-Series Netgear M-Series Ubiquiti UniFi MikroTik Extreme Networks
Wireless / Wi-Fi
Cisco WLC Aruba Controllers Ubiquiti UniFi AP Ruckus / CommScope Meraki MR Fortinet FortiAP Cambium EnGenius
Firewalls & VPN
Palo Alto Fortinet FortiGate Cisco ASA / FTD SonicWall Check Point pfSense / OPNsense Juniper SRX
Identity Sources
Active Directory Azure AD / Entra ID Okta Google Workspace SAML 2.0 LDAP / LDAPS RADIUS Proxy Local DB

Any RADIUS-capable device works — the list above covers the most common deployments.

Built for network engineers,
by network engineers

Real screenshots from a running NACIO deployment — no mockups, no stock UI.

Dashboard
NACIO Dashboard
Device Counts
Live CPU & Memory
Network Bandwidth
Disk & Health
NACIO Dashboard
Dashboard Real-time CPU, memory, bandwidth & disk monitoring — all from one screen
All Endpoints
Endpoint Inventory Every device on your network — vendor, IP, port location & last seen
Device Detail
Device Detail Device type, compliance policy, group membership & remote agent commands
Compliance Policies
Compliance Policies Build NIST, CIS, AV & OS patch policies — trigger on connect or schedule

Built for every network environment

🏢

Enterprise Campus

Full 802.1x wired and wireless enforcement with AD integration, dynamic VLAN assignment, and compliance gating for thousands of endpoints.

📱

BYOD Programmes

On-board personal devices through a self-service portal. Profile device type, verify ownership, apply appropriate access policies, and segment from corporate assets.

🏨

Hospitality & Venues

Branded captive portals with time-limited passes, PMS integration, and per-guest bandwidth controls for hotels, stadiums, and event spaces.

🏭

OT / IoT Environments

Profile and segment industrial and IoT devices. Enforce strict access control on devices that can't run traditional agents using MAC-based and DHCP fingerprinting policies.

🏥

Healthcare

Ensure medical devices, clinical workstations, and BYOD phones are all on the right VLAN with the right access — fully audited for compliance reporting.

🌐

Managed Service Providers

Manage multiple client organisations from a single NACIO console. Separate policies, portals, and reports per tenant with full isolation.

How NACIO compares

Capability NACIO Cisco ISE Aruba ClearPass Fortinet FortiNAC Portnox Cloud
Self-hosted / on-premise
Cloud-hosted option
802.1x RADIUS
Captive Portal
Device Profiling
Network Discovery & ScannerLimitedLimited
Compliance Scanning
Built-in PKI / CAAdd-onAdd-on
Perpetual license (no forced renewal)
Multi-organisation (MSP)ComplexLimitedLimited
Remote probes (secure tunnel install)ISE PSN nodesCollector VMs
Built-in DHCP server
Built-in High AvailabilityAdd-on licenseAdd-on licenseAdd-on license
Setup wizard (mins to deploy)
Vendor-neutral (any switch/AP)Cisco-preferredAruba-preferredFortinet-preferred

Be first in line when NACIO launches

We're preparing NACIO for general release. Register your interest and we'll reach out with early access details, pricing, and a personalised demo.

  • Priority access before public launch
  • Influence the product roadmap
  • Early-adopter perpetual license pricing locked in
  • Dedicated onboarding support
  • Direct line to the engineering team

Register Your Interest

Required
Required
Valid email required
🎉

You're on the list!

Thanks for registering your interest in NACIO. We'll be in touch soon with early access details and next steps.

In the meantime, feel free to share this page with colleagues who manage network access control.