Distributed by design
One control plane for every site. Lightweight edge intelligence where you need it.
Axon combines a cloud operations layer with site-local agents. The control plane stores telemetry, policy, alerts, baselines and fleet state. Edge agents classify traffic, enforce policy and run bounded diagnostics close to the users affected. If the controller is temporarily unreachable, local forwarding and cached policy keep running.
Inline or passiveAMD64 and ARM64 LinuxPrivate VPNOffline-tolerant policy
The deployment boundary
Raw packets stay local. Axon sends bounded flow and health telemetry to the control plane.
Every agent communicates with the control plane via the private VPN; the control plane sees bounded telemetry from the whole fleet, never raw traffic.
Deployment modes
Where the device sits, exactly.
Axon can be deployed inline or passively, per site or at an aggregation node. Inline, the agent runs as a transparent Layer 2 bridge — no IP renumbering, no DHCP changes. Passively, it observes a SPAN or mirror feed without touching the forwarding path.
In-line bridge
Enforces policy, shapes, and rate-limits.
SPAN / mirror
Observation mode only OR full API integration with existing switches.
IN-LINE BRIDGE
SPAN / MIRROR
The four layers
Small pieces, clear responsibilities.
On-site intelligence
Runs on a small Linux device at the site or aggregation node. In switching mode it uses a bespoke forwarding pipeline, application-aware policy and rate limits. In mirror mode it observes a SPAN feed without touching the forwarding path. Raw packets stay local; Axon publishes bounded flow and health telemetry to the control plane.
Reachable without exposure
A private VPN connects remote agents and deployment services across NAT without exposing management ports to the internet. Access policy limits what an adopted agent can reach.
One operations layer
One place for sites, users, traffic, health, diagnostics, capacity, alerts, policy, agent lifecycle and Simba. Site-scoped access keeps customer and operator data separated.
No forklift required
Axon does not require every device to run an agent. Use SNMP and UniFi integrations to bring existing routers, switches, radios and access points into the same operations view.
Per-site retraining
Models retrain in the cloud, over the private Axon VPN.
The on-device model gets better over time because we retrain it on the telemetry your own fleet produces. Retraining happens in the cloud, on our infrastructure, over the same private Axon VPN that every site is already connected to. Updated models are pushed back to the edge as signed deltas.
- Telemetry travels inside the private VPN — never publicly exposed.
- Models are signed; the Axon agent verifies the signature before hot-loading.
- Operators control opt-in for global model contributions on a per-site basis.
Walk the deployment boundary with us.
In one session, we will map your sites, choose inline or passive per site, and show where your data travels — and where it does not.