SNAPguard
Plugs in.Dials out.Provisioned.
The appliance we put in the venue: an outbound WireGuard tunnel back to Stampede, so the whole network is provisioned remotely with nothing exposed.
Powering 2,500+ UK venues




















Someone else’s network.
Every venue is a different router, a different ISP and a cupboard of switches installed by a different contractor. The usual way to manage any of it remotely was to ask the venue to open a port: a security problem, an IT problem and a support problem at once, dead the moment the ISP changes the address.
It dials out.
The opposite of asking a venue to open a port: a device that reaches out to us and never needs anything reaching in.
The box reaches out
SNAPguard holds an outbound WireGuard tunnel to a regional endpoint. Nothing is forwarded, nothing is exposed, and a changing public address never matters.
Config comes down the pipe
Networks, bandwidth policy, portal certificates and firmware are pushed over the RouterOS API, as if we were stood in the cupboard.
Four networks, tagged
Guest, staff, payments and cameras each get their own tagged network, so a card reader never shares a broadcast domain with a guest phone.
The venue, drawn.
What the box actually does to a comms cupboard, on one drawing.
No port-forwarding and no inbound rules. The box initiates the connection, so a NAT or a changing IP is never an obstacle.
Networks, bandwidth policy, portal certificates and firmware are pushed over the tunnel. Nobody drives to the venue for a config change.
Guest, staff, payments and cameras get their own tagged networks, so a card reader never shares a broadcast domain with a guest phone.
The box can scan the venue network and report what is on it: access points, speakers, printers, cameras, payment terminals.
The spec.
What the box carries so the venue never has to think about any of it.
Outbound WireGuard
The box initiates a WireGuard tunnel to us and holds it open. Nothing forwarded, nothing exposed, and the venue’s public address can change as often as it likes.
Regional endpoints
Tunnels terminate on regional servers, each with its own address space, so a venue connects to infrastructure near it and can be re-homed without touching the hardware.
RouterOS provisioning
Once the tunnel is up the box is configured over the RouterOS API as if we were stood in the cupboard.
VLAN templates
Guest, staff, VLAN trunk, IoT and cameras built from templates, tagged and isolated from each other by default.
Controller mirroring
Where a venue runs UniFi or Omada, the networks are mirrored into the controller so the access points broadcast the right thing.
Portal certificates
Hotspot certificates are deployed down the tunnel, so the captive portal is served properly without anyone handling a cert by hand.
Bandwidth policy
Per-network bandwidth allocation, so a busy guest network never starves the till or the card machine.
Network inventory
The box scans the venue network and reports what is on it: access points, speakers, printers, cameras, payment terminals.
Hands-on, honestly.
The activation wizard in connect makes the visit short. It does not remove it, and we would rather tell you that now.
Detect the existing setup, record the line speed, and find the switch nobody knew about before it finds you.
Create the networks from templates: guest, staff, payments, cameras, each tagged and isolated.
Push the same networks into UniFi or Omada where there is a controller, so every AP broadcasts the right thing.
Join each network with a real phone, check the address it gets, and confirm the portal actually appears.
Odd cabinet? Ask.
Setup questions, odd cabinets and awkward switches welcome. The fastest way to find out if your venue is straightforward is to ask, and our team has seen most cupboards by now.
