Surfsonix Cloud.
Multi-tenant cloud control plane for guest networks, captive portals, vouchers, analytics and audit logs — across every site you operate.
One console, every venue.
Whether you operate three hotels or three hundred, Surfsonix Cloud gives you one place to configure portals, segment networks, push policy changes and watch what's happening in real time.
- Hierarchical organizations
Brand → region → property → SSID. Push config from any level, override where needed.
- Per-venue branding
Logos, themes, languages, sponsorship banners, terms — without touching code.
- Voucher & ticket auth
Generate, sell or print vouchers; integrate with PMS for room-based access.
- Marketing capture
Email, OTP, social login, surveys — all opt-in and exportable to your CRM.
- Visitor analytics
Footfall, return visits, dwell time, conversion on portals — at venue and brand level.
- Audit & compliance
Every config change tracked. Visitor data retention configurable per region.
Organizations, sites, SSIDs — and who can touch what
Surfsonix Cloud is built as a hierarchy, not a flat list of networks. Configuration and permissions both follow the same shape, so the two-hundredth site doesn't mean losing track of the first one.
The tenant itself. Billing, global branding defaults, staff SSO and the list of sites underneath it all live at this level.
Each hotel, store, campus or venue is a site, with its own address, timezone, local admins and network integration — NEO, Meraki or EnGenius.
A site can run several SSIDs — guest, staff, event — each with its own splash design, authentication method and bandwidth policy.
Every connection, voucher redemption and configuration change is recorded against the org, site and SSID it happened on.
Roles that follow the same tree
Permissions are scoped to a level in the hierarchy, not granted globally by default — a site manager sees their site; billing stays with the org owner.
Full control of the tenant — billing, adding or removing sites, and appointing other admins.
Configures any site and rolls out policy across the whole tenant, without access to billing.
Full control of one site or a named group of sites — portal, vouchers, bandwidth — nothing outside that scope.
Looks up sessions, reissues vouchers, restarts a portal — no access to network policy or billing.
Views configuration, logs and reports across an org or site with no ability to change anything.
Scoped credentials for a PMS, CRM or BI tool to pull data or push vouchers without a human login.
What admins actually do in the console
Most days aren't a redesign. They're a support ticket, a voucher batch, or a policy tweak that needs to go out to one site or fifty.
Update a splash page, bandwidth cap or auth method at the brand level and roll it out to one site, a region, or the whole estate.
Generate a batch, print or email the codes, watch redemption in real time, and revoke a batch if one leaks.
Search by MAC address, email or room number to see what a guest connected to and when, without touching the network.
Footfall, dwell time, capture rate and marketing opt-ins, filtered by property, region or date range.
Guardrails a security review can check
A multi-tenant console is only as good as the boundaries around it. Access, data and change history are scoped by default, not bolted on after a customer asks.
- Role-based access control
Every action is scoped to an org, site or SSID — nobody gets more reach than their role needs.
- Full audit trail
Every configuration change is attributed to a user, timestamped, and kept for as long as your policy requires.
- Encrypted in transit & at rest
TLS across the console and APIs; visitor and configuration data encrypted at rest.
- Regional data residency
Choose where visitor data is stored and how long it's retained, to match the rules of the region you operate in.
- SSO for staff logins
Bring your own identity provider for admin and support logins, with session timeouts you control.
- Exportable, deletable guest data
Respond to access and erasure requests directly, without opening a support ticket with us.
Questions from IT and ops teams
NEO is the on-premise gateway that keeps a single venue online and enforcing policy even without an internet connection. Cloud is the multi-tenant console that sits above your whole estate — connected properties sync configuration and reporting up to Cloud, so you're not managing each site by hand.
Yes. Cloud pairs with our native Meraki and EnGenius integration, so you can run the portal, vouchers and reporting layer entirely from the cloud on top of access points you already own, with no NEO appliance required.
Access is scoped by role and by level in the hierarchy — organization, site or SSID. A regional manager sees their region, a single-property admin sees only their property, and billing and tenant-wide settings stay with the org owner.
You choose the data residency region and retention window per organization, so you can align with the privacy rules that apply where you operate. Data can be exported or deleted on request.
Yes, through the API and configurable exports. Vouchers, sessions and marketing opt-ins can be pushed to or pulled from the systems you already run — the same integration pattern NEO uses for property-management systems.
If the site runs behind a NEO gateway, it keeps working locally and syncs back to Cloud once connectivity returns. If a site runs purely on Cloud-managed Meraki or EnGenius access points, portal and auth availability follows the resilience of those access points and the site's own internet link.
See it on your sites.
We'll spin up a sandbox tenant for your team and walk you through onboarding one of your real venues. No commitment.
