Introducing Project Aether · Live platform · Available now

Replace seven stacks.
One platform.
Infinite intelligence.

The unified access management platform that replaces seven fragmented stacks with a single high-performance system — from OpenWRT routers to QSDK and RDK-B gateways, from OpenWiFi access points to prplOS mesh nodes, and out to fixed wireless CPE, transport gear and O-RAN A1.

$0.30
Per device / month — no AI tax
1
Binary replaces 15 services
6
Device platforms supported
10
Protocols in one binary
200 B
Config delta payload, not 50 KB
QSDK RDK-B OpenWrt OpenWiFi prplOS Plume AETHER PLATFORM
The Problem

The industry is fragmented.
Operators are paying for it.

Today's wireless management landscape forces operators to stitch together incompatible systems, maintain separate codebases per device platform, and pay per-device royalties for AI features that should be table stakes.

🧩
Protocol Fragmentation
uCentral, TR-369/USP, WRP, IEEE 1905.1, OpenSync — each requiring separate integration teams and separate deployments.
🏗️
Platform Lock-in
QSDK, RDK-B, OpenWRT, OpenWiFi, prplOS — each with its own management quirks and no unified control plane.
💸
Proprietary AI Tax
Plume, Cognitive Systems, and Minim charge per-device SaaS fees for RF optimization and security that could run on your own infrastructure.
🔓
No Open Alternative
OpenWiFi (C++) covers only its own stack. Xmidt (Go) covers only RDK-B. There is no single open platform that covers everything.
Architecture

One modular high-performance core.
Infinite device reach.

AETHER PLATFORM OpenWiFi native client OpenWrt device agent QSDK device agent + HAL RDK-B Parodus / WRP prplOS data model bus OpenSync Native port (FFI bridge) Hermes PROTOCOL ROUTER uCentral / TIP OpenWiFi TR-369 / USP WRP / Xmidt IEEE 1905.1 EasyMesh OpenSync (native port) MQTT / MQTT Broker Meridian MESH MANAGEMENT Multi-topology · Steering · Topology Pheme EVENT DELIVERY Webhooks · Pub-Sub · Event fanout Prometheus AI / ML ENGINE RF optimizer · Federated learning Argus IoT IDENT classification DB Aegis SECURITY DNS filter Distributed SQL PostgreSQL / CockroachDB · compile-time queries Event Streaming Telemetry · Audit · AI pipeline MQTT Broker MQTT 5.0 · USP / OpenSync PKI Automation step-ca · X.509 · OTT issuance PII Vault Databunker · GDPR compliant Post-Quantum TLS X25519 + ML-KEM-768 REST / GraphQL API · Aether Ops · Aether Home · TMF Open API TMF638 · TMF632 · TMF678 · TMF621 → BSS / OSS integration
Components

Seven components. One platform.
Complete coverage.

Hermes
Protocol Router
The universal translator. Hermes speaks every wireless, transport and RAN management protocol natively — routing, transforming, and normalizing device telemetry from any vendor into a single internal event stream.
uCentralTR-369/USP · 4 MTPsWRP/XmidtIEEE 1905.1OpenSyncMQTTNETCONFSNMPgNMIO-RAN A1/VES
Meridian
Mesh Management
The convergence layer. Meridian owns the entire mesh lifecycle — topology discovery, client steering, band management, and automated channel optimization across all backhaul topologies: EasyMesh, OpenSync OVSDB, 802.11s, and proprietary backhaul.
EasyMesh R1–R5OpenSync OVSDB802.11sClient SteeringBackhaul
Pheme
Event Delivery
The broadcast goddess. Pheme delivers real-time events, webhook notifications, and pub-sub streams to any downstream consumer — OSS/BSS systems, third-party apps, or operator dashboards.
WebhooksPub/SubEvent fanoutImmutable auditSSE
Prometheus
AI / ML Engine
The fire-bringer. Prometheus ingests fleet-wide telemetry to run deterministic RF optimization and, over time, federated reinforcement learning — without centralizing subscriber data. It also predicts device failure before it strands a subscriber, senses interference and rogue APs, and closes the loop: decided remediations apply as config changes through the normal operate path, every one audited and reversible.
RF OptimizerFederated RLFailure PredictionAuto-RemediationRogue AP DetectionInterference SensingMotion Sensing (on-device)Anomaly DetectionML inference
Argus
IoT Fingerprinting
The all-seeing giant. Argus identifies every device on the network using DHCP fingerprinting, mDNS/DNS-SD, OUI lookups, and a device classification database — classifying threats before they connect.
Device fingerprint DBDHCP FingerprintmDNS/DNS-SDOUI DatabaseML Classifier
Aegis
Content Filtering & Security
Zeus's shield. Aegis provides DNS-layer content filtering with parental controls and real-time threat blocking — running entirely on your infrastructure.
DNS FilteringParental ControlsThreat feedPhishing feedDNS blocklist
Experience Index
Wi-Fi QoE Scoring
The number support can act on. A 0–100 score for how a household’s Wi-Fi actually feels, rolled up from client to access point to household — and it never arrives bare. Every score carries the dimensions behind it and the reasons it is not 100, so the first question on a call is which link to fix, not whether there is a problem.
Signal & SNRAirtime & interferenceLoss & latencyRoaming stabilityThroughput vs capabilityExplainable factors
Protocol Coverage

Every protocol.
Zero compromises.

Ten protocols in one binary. Beyond the WiFi CPE stacks, Hermes speaks NETCONF, SNMP and gNMI for transport and backhaul, plus O-RAN A1 and VES for RAN policy and event collection — so the access network and the CPE fleet live in the same control plane.

Hermes Protocol Support Matrix uCentral / TIP WebSocket + JSON · OpenWiFi · OpenWrt NATIVE TR-369 / USP All 4 USP MTPs · protobuf · QSDK · prplOS NATIVE WRP / Xmidt WebSocket + binary encoding · RDK-B (zero-install via Parodus) NATIVE IEEE 1905.1 Raw socket EtherType 0x893a · CMDU · EasyMesh R1–R5 NATIVE OpenSync MQTT · Apache 2.0 · Plume Cloud migration path NATIVE MQTT / Broker MQTT 3.1 / 5.0 · clustered broker · USP MQTT MTP NATIVE NETCONF / YANG SSH + XML framing · RFC 6241 / 6242 · YANG models NATIVE SNMP v1 / v2c / v3 · polling + traps · legacy CPE & backhaul NATIVE gNMI gRPC + protobuf · streaming telemetry · OpenConfig NATIVE O-RAN A1 / VES A1 policy · O1 over NETCONF · VES 7 collector NATIVE
RAN & Cellular

Not just WiFi.
The whole access edge.

Fixed wireless and mobile access sit in the same control plane as the CPE fleet — so a subscriber complaint can be traced from the home, through the backhaul, to the radio without leaving one system.

O-RAN
A1 policy interface
Full policy lifecycle against a Near-RT RIC — deliver, withdraw, fetch, and enumerate policy types, with policy status tracked and stored. Aether is an A1 client, not a RIC.
O-RAN
O1 interface
O-RAN node management over real NETCONF — get-config and edit-config against the running datastore, verified against netopeer2. FM/PM ingestion arrives on the standard VES 7 event listener.
O-RAN
VES collector
Emits VES events into ONAP-style OSS. The same pipeline carrying CPE telemetry reports RAN events to the systems your RAN already reports into.
Cellular / FWA
Device.Cellular
TR-181 cellular data model on OpenWRT CPE via ModemManager — IMEI, IMSI, ICCID, and live RSRP, RSRQ and SINR. Fixed wireless CPE managed exactly like fixed-line CPE.
Transport
NETCONF · SNMP · gNMI
Aggregation and backhaul gear in the same device list as the CPE. YANG models over NETCONF, streaming telemetry over gNMI, and SNMP for anything too old for either.
IoT & Sensor Networks

Not every managed device
is a router.

A sensor on a mountainside, a camera event, a Zigbee hub in a living room and a subscriber’s access point are all just devices with identity, health and telemetry. Aether onboards them through the same control plane, into the same device list, under the same tenancy and audit rules — so an operator does not buy a second platform to manage the things that are not access points.

Shipped
Generic MQTT ingest
Topic patterns map to a device serial and a tenant; the payload lands in device telemetry and the device appears in the unified list. One adapter covers purpose-built sensors, camera events, and Zigbee or Z-Wave behind a zigbee2mqtt bridge.
Shipped
LwM2M over CoAP
Registration, update and deregistration; read, write and execute on objects and resources; observe and notify into telemetry. IPSO sensor objects supported. Gated on a live wakaama client registering in-cluster, not on a unit test.
Scope
Control plane, not media plane
Aether onboards a camera, holds its credentials and brokers access to its stream URL. It never terminates the stream. Video belongs in a media server, and a management platform that pretends otherwise becomes a bandwidth bill.
Discipline
No invented readings
No adapter may present fabricated device or telemetry data. A sensor that has not reported shows as silent, not as zero — the distinction matters when someone is deciding whether to evacuate a valley.
Flagship deployment

GlacierAI — early warning for glacial hazards

Himalayan glacial lake outburst floods and ice-rock collapses arrive with minutes of warning, in valleys that cross national borders. GlacierAI puts a purpose-built solar sensor node on the face itself — seismic, 60 GHz surface radar and GNSS on one board, with a secure element holding the per-node key — and Aether is the platform behind it.

Nodes publish over MQTT on mutual TLS. Aether ingests, stores, correlates across stations, triangulates the source from arrival times, and routes the alert to civil authorities on both sides of a border — with an audit record of who was told and when. This is the whole IoT path in production, not a slide: ingest, storage, alert routing, API and dashboard.

3
sensing channels in one telemetry frame — radar, GNSS, seismic
QoS 2
exactly-once on the alert topic; a siren must not be missed, or fire twice
≥3
stations to report a triangulated fix — below that it is labelled a baseline, never dressed as one
693 B
crosses a border — derived alert fields only, never raw waveforms

Status: the ingest-to-alert path runs in production and is proven end to end against the firmware’s real wire format. Field nodes are not yet deployed on a mountain — when they are, we will say where.

Wi-Fi Sensing

Every access point
is already a sensor.

A person walking between two radios changes the multipath between them, and the link’s signal moves several dB from sample to sample. A still room does not do that. Aether now reads presence from the links every managed device already maintains — mesh backhaul and associated clients — with no extra radio, no extra traffic and no camera. It ships in the device agent, and it is off until the household turns it on. Motion, then falls, breathing and heart rate as candidates — each with a confidence, none of them a medical device.

Shipped · every chipset
Motion from RSSI variance
One detector per mesh peer and per client, sampled every 500 ms on the device. It learns the empty room’s ambient, rejects outliers, applies hysteresis and a dwell, and reports only the transitions: Learning, Idle, Motion, or Saturated when a peer is too close to sense.
Shipped · CFR-capable radios
Channel state (CSI)
Where the radio can capture the channel frequency response, the same links yield the complex response of every receive chain on 256 subcarriers — about a thousand numbers where RSSI has one. It sees a hand cross a room that RSSI variance cannot. Reported beside RSSI, never merged with it.
Consent
Off by default, on the device
Presence in a home is personal data. Nothing switches sensing on but a setting written on the device itself; when it is off the sampler is never spawned, so the device never computes it. The cloud can read the switch and cannot flip it.
Discipline
Silent means silent
A stalled CSI capture frozen at its last value never outranks a live RSSI reading. A device that stops reporting has no state, not a stale one. The dashboard, the topology map and the 24-hour strip all follow that rule.
What the operator sees

From the channel to the dashboard

Devices report the sensing tree over TR-369 / USP as ValueChange notifications, so the controller stores it through the same path as every other parameter. Aether shows a chip row per device with RSSI and CSI side by side, marks motion on the topology map per link and per direction, keeps a 24-hour strip of transitions with the source recorded, and exposes an events API filtered by sensor.

On the same channel, over half a minute of a link that is not moving, the agent now estimates a breathing rate and a heart rate and raises a fall candidate: a large transient that ends in nobody getting up. Breathing is read from CSI magnitude; heart rate from carrier phase, because a chest wall moves millimetres and at 5 GHz that is about six degrees of phase and almost nothing of power. Each estimate ships with its confidence, and every surface that renders them says what they are: experimental candidates, not a medical measurement. Nothing on the controller alerts, escalates or records them as a clinical observation.

500 ms
RSSI sample period per link, on the device, transitions only over the wire
256
subcarriers per receive chain in each CSI sounding on a QCN9074 radio
−22 dB
CSI motion energy of an empty room, steady within 0.6 dB across a 97-record capture — measured
30 s
window for a vitals estimate: 270 samples zero-padded to a 512-point FFT, magnitude and phase, at most once every 2 s per link

Status: running on our four-node lab mesh since 2026-09-21; CSI on the QCN9074 radios that can capture CFR, RSSI on all of them; vitals and fall candidates in ac-client r40 with the controller views merged 2026-09-22. First observation on motion: the closest pair flips readily and the longer links are quiet — whether that link is over-sensitive or the office is busy needs a controlled walk test, which is next. A vitals estimate needs a still subject inside the link’s own path, which a mesh link between two rooms may never have.

Parental Controls & App Visibility

Most parental controls ask nicely.
Ours drop the packet.

Nearly every “parental control” in this market is a DNS blocklist. DNS filtering is a suggestion: encrypted DNS, a hardcoded resolver, a QUIC connection or a raw IP walks straight past it, and the dashboard still reports the block as applied. Aether compiles policy into the router’s own kernel, per device, and then asks the router what it actually dropped.

Enforcement
1,300+ apps, per device
Over 1,300 application signatures across 30 classes — games, video, social, chat, downloads — compiled to in-kernel match-and-drop keyed to a single device’s MAC, not a household-wide DNS list. One child’s tablet is filtered while the rest of the home is untouched.
Offload-aware
Survives hardware NAT
Hardware flow offload routes traffic around the classifier entirely — filtering configures cleanly, reports healthy, and inspects nothing. Aether disables the offload path on the SoCs where it applies and re-asserts that on every policy push, not once at setup.
Verification
Measured, not assumed
The router reports which rules it enforced. “14 attempts blocked today” is a count the device sent back, not an inference from a policy we hoped applied. A rule that stops matching is visible as enforcement drift.
Privacy
Resale-safe by design
Every device carries a provisioning generation. Re-provision or resell it and usage history starts a new series — the next household cannot inherit the previous occupant’s browsing record, and an erasure request severs it cleanly.
Engines
One policy, every stack
The same rule renders to the on-device filter on OpenWRT, prplOS and QSDK, to the native policy engine on OpenSync, and to whichever classifier a given image ships. Vendor choice stops being a policy decision.
Screen time
Rules that know the day and hour
Policies carry weekday and time-window schedules, so homework hours, bedtimes and weekends are distinct rules rather than one blunt on/off switch — and the schedule is enforced on the device, not by a cloud job that has to reach it first.
Beyond the catalogue
Custom URL, port and payload
When an application is not in the signature set, rules can match on URL, port or layer-7 payload directly — so a regional app, a school platform or something that appeared last week does not have to wait for a signature release.
Honest by default
Coverage gaps are reported
When a platform cannot enforce a rule natively, Aether says so and names what it fell back to. A policy that silently degraded to a weaker control is the failure mode this was built to remove.

Enforcement depth depends on the device: in-kernel app blocking requires a supported OpenWRT, QSDK, prplOS or OpenSync image. On other platforms Aether applies the DNS-layer control and reports the difference rather than hiding it.

App Visibility & Network Intelligence

You cannot govern
what you cannot see.

Blocking is the last step. Before it comes knowing what is actually on the network — which applications, on whose device, at what hour, carrying what risk. Aether classifies traffic on the router itself and receives only the verdict, so the platform learns what an application is without the packets ever leaving the home.

Classification
20 application categories
Streaming, gaming, social, messaging, video conferencing, file sharing, shopping, finance, adult, advertising, VPN/proxy, remote access, IoT and more — resolved per flow, per client, not guessed from a port number.
Risk
Seven threat classes
Malware, phishing, Tor, anonymisers, suspicious protocols and unsafe TLS surface as first-class signals on the flow that carried them — so a risky connection is attributable to a device and a moment, not just a daily total.
Privacy
Inspection stays on the router
Classification happens at the edge. Aether orchestrates and normalises — it performs no in-cloud inspection and never receives subscriber payloads. What crosses the wire is a verdict, not traffic.
Encrypted traffic
Built for a TLS-everywhere network
Modern traffic is encrypted and increasingly hides the hostname that naive classifiers rely on. The edge engines Aether drives are chosen and configured for that reality rather than degrading silently when they meet it.
Normalisation
One schema, any engine
Different silicon ships different classifiers. Aether normalises every verdict into one flow record — same categories, same risk vocabulary, same client identity — so reporting does not fork per vendor and a mixed fleet reads as one fleet.
Attribution
Per client, resale-safe
Every flow resolves to a client the server already knows, never to an identifier the device asserts. Usage history is keyed to a provisioning generation, so a re-provisioned or resold router starts clean instead of inheriting the previous household’s record.

Visibility depth follows the image: platforms with a native classifier report full per-flow application and risk data, and Aether states plainly what a given device can and cannot see rather than presenting a partial picture as a complete one.

Platform Support

Every device platform.
One control plane.

We ship one agent — ac-client, for OpenWRT and QSDK-derived images. Every other platform here already runs its own, and Aether terminates what is already on the device. Running something not listed? Firmware development is our other business — OpenWRT, OpenWiFi, wlan-ap, RDK-B and QSDK, plus camera and IoT firmware on embedded Linux. Agent implementation, platform HALs and full firmware builds for OEM, ODM and custom hardware, priced per device.

OpenWiFi
✓ native agent, nothing to install
✓ Full uCentral protocol
✓ OTA firmware (owfms)
✓ Zero-touch provisioning
✓ Real-time telemetry
OpenWrt
✓ ac-client agent (TR-369)
✓ cfg80211 / nl80211
✓ 1,500+ router models
✓ opkg package install
✓ Post-quantum TLS
✓ Device.Cellular (ModemManager)
QSDK
✓ ac-client agent (TR-369/USP)
✓ TR-181 → UCI mapping
✓ qca-wifi driver targets
✓ On-device app filtering
✓ IPQ5018 factory images
✓ TR-069 migration path
RDK-B
✓ Parodus / WRP (zero install)
✓ USP over MQTT MTP
✓ Comcast/Cox/Charter CPE
✓ No firmware changes
✓ CcspHalExtFetch bridge
OpenSync
✓ native agent, nothing to install
✓ OVSDB control plane (10 tables)
✓ Plume-lineage CPE
✓ Native app policy (FSM)
✓ Flow telemetry (FCM)
✓ OpenSync mesh onboarding
✓ Validated against real ovsdb-server
prplOS
✓ native agent, nothing to install
✓ TR-181 data model bus
✓ prplMesh EasyMesh
✓ Intel, Broadcom CPE
✓ Multi-vendor mesh
Competitive Comparison

Why operators choose Aether
over the alternatives.

Capability Aether OpenWiFi Xmidt Cisco Meraki Juniper Mist Plume Cloud Nokia Altiplano
Open source OpenWrt agent✓✓✓✗✗✗✗
OpenWiFi / OpenWrt✓✓✗✗✗✗✗
QSDK support✓✗✗Partial✗✗Partial
RDK-B support✓✗✓✗✗✓✗
prplOS / EasyMesh✓✗✗✗✗✗Partial
AI RF optimization✓✗✗✓✓✓Partial
Federated ML✓✗✗✗✗✗✗
IoT fingerprinting✓✗✗✓✓✓✗
DNS content filtering✓✗✗✓✓✓✗
Subscriber mobile app✓✗✗✗✗✓✗
NETCONF / YANG✓✗✗✗✗✗✗
SNMP (v1/v2c/v3)✓✗✗✗✗✗✗
gNMI streaming telemetry✓✗✗✗✗✗Partial
O-RAN A1 / VES✓✗✗✗✗✗✗
Cellular / FWA CPE (RSRP, RSRQ, SINR)✓✗✗✗✗✗Partial
All 4 USP MTPs (WS, MQTT, STOMP, CoAP)✓✗✗✗✗✗✗
O-RAN O1 (NETCONF-backed)✓✗✗✗✗✗Partial
Post-quantum TLS✓✗✗✗✗✗✗
TMF Open API (BSS/OSS)✓✗✗PartialPartial✗✓
On-premise deploymentLicensed✓✓✗✗✗✓
Per-device SaaS feeNoneNoneNone~$6–18/mo~$4–12/mo~$2–5/mo~$3–8/mo

Every Aether row ships today. Licensed means available under separate licence. Competitor pricing is list-price estimate; verify against your own contracts.

Roadmap

8 phases to full parity.
Running today. Hardening for scale.

PHASE 1 Foundation Hermes core uCentral + WRP M1–M3 PHASE 2 Security PKI + PQ-TLS Multi-tenant RBAC M3–M5 PHASE 3 Mesh & TR-369 Meridian + 1905.1 USP / prplOS M5–M8 PHASE 4 Observability Pheme + Event Bus Dashboards M7–M10 PHASE 5 AI Engine Prometheus RF optimizer M9–M12 PHASE 6 Subscriber App Aether Home Cross-platform mobile M10–M13 PHASE 7 Security Suite Argus + Aegis OpenSync native port M12–M16 PHASE 8 GA Release Federated ML TMF API + BSS/OSS M15–M18 M0 M18 Key Milestone: M18 — Feature parity with Plume Cloud, Nokia Altiplano, and Cisco Meraki Single binary · multi-protocol ingest · 5 device platforms · Post-quantum security · On-premise or cloud Team growth path: 4 engineers → 8 engineers → 14 engineers (GA)
Technology

Built on the right foundations.
From the ground up.

Runtime
Memory-safe async runtime
Async-first, memory-safe, zero-cost abstractions. Async HTTP/WebSocket server with a lock-free connection registry.
Database
Distributed SQL
Compile-time query validation via sqlx over the PostgreSQL wire protocol. Deploys against PostgreSQL or CockroachDB for distributed SQL and horizontal scale-out — same code either way.
Streaming
Event Streaming
Telemetry ingestion, an immutable audit journal with rollback, webhook and pub/sub fan-out, and SSE streams — over a clustered MQTT 5.0 broker.
Concurrency
Lock-free registry + Channels
Lock-free concurrent registry for device endpoints. Async channels between internal modules with zero shared-state overhead.
Security
Post-Quantum TLS
X25519 + ML-KEM-768 hybrid (NIST FIPS 203). PKI automation for automated cert issuance and OTT provisioning.
Messaging
MQTT Broker
Clustered MQTT 5.0 broker for USP MQTT MTP and OpenSync device connectivity. Scales to millions of topics.
Privacy
PII Vault
PII vault with GDPR-native data access API. Subscriber data isolated from telemetry store. CCPA compliant.
Efficiency
Delta Config
JSON Patch (RFC 6902) over full config diffs. 200 bytes instead of 50 KB per update.
Pricing

Simple, transparent pricing.
No per-device AI tax.

Founding-partner pricing. These rates are locked for the life of your contract. Start today with a 7-day free trial — cancel any time.

Home
Aether Residential
$5 / home / mo
For households. Up to 5 devices. Parental controls, security, and the Aether Home app.
  • ✓ Up to 5 devices
  • ✓ Aether Home app
  • ✓ Aegis DNS filtering
  • ✓ IoT device identification
  • ✓ Parental controls
  • ✓ Network map & speed test
Get Started
Operator
Aether Operator
$0.50 / device / mo
For operators running Aether as a managed service. All 10 protocols, mesh, and events — no AI tier lock.
  • ✓ All 10 protocols (Hermes)
  • ✓ Meridian mesh management
  • ✓ Pheme event delivery
  • ✓ Post-quantum TLS
  • ✓ Managed cloud — EU / US residency
  • ✓ Business-hours email support
Get Started
Wholesale
Aether Telecom
$0.15 / device / mo
For national telcos and wholesale operators. A volume rate for very large fleets, from 25,000 devices.
  • ✓ Everything in Pro
  • ✓ Volume wholesale rate
  • ✓ Fleet-wide federated ML
  • ✓ Dedicated onboarding & tuning
  • ✓ 99.95% SLA at GA
Contact Sales
Enterprise
Aether Enterprise
$0.20 / device / mo
For Tier 1 operators, OEMs, and system integrators requiring BSS/OSS integration and a 99.99% SLA at GA.
  • ✓ Everything in Pro
  • ✓ TMF Open API integration
  • ✓ Federated ML fleet-wide
  • ✓ OEM / ODM firmware — OpenWRT, RDK-B, QSDK
  • ✓ OEM / white-label branding
  • ✓ Dedicated engineering pod
  • ✓ 99.99% SLA at GA + 24/7 support
Contact Sales
Get Started

Ready to unify your
wireless infrastructure?

Start in minutes with a 7-day free trial. Founding-partner rates are locked for the life of your contract.

Get Started → Carrier pricing