Management panel
Runs in the cloud
Users, groups, speed limits, filtering rules and the captive portal are managed from a single panel. Who signed in to the panel and what they changed is itself logged.
Guest networks for hotels, hospitals, offices, cafés and dormitories: a solid firewall, correct configuration and lawful, protected logging. The management panel and log retention run in the cloud — no server goes into your premises. A setup that gives your guests internet without leaving your corporate network exposed.
Site survey and inventory are free · scope itemised in the quote · fee fixed for 12 months
The heavy side of the system — management and log retention — runs in the cloud on separate services. The only component on your premises is the gateway. Hosting, backing up and patching a server is not your job.
Runs in the cloud
Users, groups, speed limits, filtering rules and the captive portal are managed from a single panel. Who signed in to the panel and what they changed is itself logged.
Separate from the gateway
Access records are collected on a separate service, signed with a timestamp and kept for the period the regulation requires, with integrity preserved.
Sits on site
This is the only component on your premises: it enforces verification, quotas and firewall rules. If your existing enterprise-grade device is suitable, no new hardware is needed.
Scope is narrowed or widened to suit the venue. Exactly which headings are included is written out, one by one, in the quote.
SMS, national e-government identity or social login. Which one fits is decided together, based on venue type and guest profile.
Who connected, when and from which device — every session is recorded with a timestamp and tied to the verified user identity.
Records are signed and stored so they cannot be altered afterwards. Integrity verification is what matters the moment a record is requested.
Records are kept for the period the regulation requires; the period, the responsibility and the access rights are defined in writing at setup.
A guest device cannot see the accounting machine, the printer or the server. Separation is built with a managed VLAN structure, not with physical cabling.
Which network may reach which resource is written rule by rule. The default is deny; every permitted path is documented with its rationale.
Rules can be written at the application layer, not just by port. Known attack patterns are detected and blocked, and port forwarding is managed from the panel.
Staff, guests, management, contractors — each group is defined separately. Speed limits, filtering rules and session policies are written against the group, not user by user.
With Active Directory or LDAP, staff connect using their existing account. Closing an account in the directory closes network access too — no second list to maintain.
Branches are visible from one management panel and users connect at every site with the same credentials. Opening a new branch means copying an existing policy to it.
Personal data is closed to unauthorised viewing; nobody — including your own system administrator — can read or alter records freely. Access rights are defined in writing at setup and every access is logged.
Device configurations are backed up and changes are versioned. When a rule changes, it is clear when, by whom and why.
Guest traffic is capped so it cannot affect corporate traffic. Critical applications get priority, and a single download cannot saturate the line.
Category-based filtering is applied according to your policy and venue type. Domains known to distribute malware are blocked separately.
Session lifetime, re-authentication interval and concurrent device limits are tuned to your venue — length of stay in a hotel, working hours in an office.
The welcome page carries your logo, colours and languages. Campaign announcements or internal notices can be delivered on the same screen.
How many access points are needed is calculated from floor plans, wall structure and concurrent user counts. Coverage gaps are identified before installation.
Alerts fire when an access point drops, the log stream stops or traffic looks abnormal. The point is to see the problem before a guest complains.
Four questions about the internet you hand to visitors. If nothing looks wrong, we will tell you that too.
In Türkiye, venues offering public internet access fall under Law No. 5651, which requires access records to be kept, retained for a defined period and protected against tampering. A consumer router’s guest network does not meet that obligation.
Verified user identity, connect and disconnect times, device identifier and session details. Access records are kept — not the content of the pages visited.
Records are stored timestamped and signed. The point is that a record can be shown, when needed, not to have been altered afterwards.
The people allowed to reach the records are defined in writing at setup. Access requests are themselves logged — it is clear who viewed a record.
For the period the regulation requires. The period and the retention responsibility are set out in the contract; if the regulation changes, the configuration is updated.
What you get at the end is not just working wifi but a written record of what is logged, how it is stored and who can access it. That document is exactly what an inspection asks for. For venues that want the whole network surface reviewed, a cyber security assessment is offered as a separate scope.
One welcome screen with several verification paths behind it. Most deployments run a mix: one method for local guests, another for international ones, and a separate sign-in for staff.
Hotel · café · restaurant
The password is generated by the system and sent to the user’s phone. A familiar flow; in return it costs per message and can be slow on international numbers.
Corporate site · dormitory · public sector
The strongest option on identity — verification completes on the government side. It cannot be used by international guests, so it is usually paired with a second method.
Tourism venue
Where an international guest has no e-government account, access is opened with passport details. A session cannot start with missing or malformed details.
Café · shopping centre · showroom
The lowest-friction option, one tap on a phone. Identity assurance is weaker than the others, so it is used within a mixed setup rather than on its own.
Office · hospital · factory
Staff connect with their existing corporate account; no second user list is maintained. When a leaver’s directory account is closed, network access closes with it.
Hotel · resort
With property management system integration, access opens at check-in and closes at check-out. The front desk does not have to do anything extra.
What the sign-in screen asks for is kept minimal. Every field not needed for verification tires the guest and accumulates data you then have to protect — asking for less is a deliberate design choice here.
The conversation usually starts with “we already have a guest network”. The difference is not in the signal — it is in the record and the separation.
| Item | Consumer router guest mode | Managed hotspot |
|---|---|---|
| User verification | Shared password — nobody knows who connected | Identity verified by SMS, e-government, ID or corporate account |
| Access records | None, or a volatile record wiped on reboot | A timestamped record per session, on a separate service |
| Record integrity | Alterable, unverifiable | Signed retention — later alteration can be detected |
| Exporting records | Not possible on most devices | Filtered by date range and exported as a readable file |
| Guest–corporate separation | One flat network; printers, tills and servers are visible | Separate VLAN segment with client isolation enabled |
| Bandwidth control | A single download can saturate the line | Per-user and per-group speed limits, priority for critical traffic |
| Multiple sites | A separate device, password and problem per branch | One panel; users connect at every site with the same credentials |
| Who responds to a fault | You do | Monitoring and alerting sit with us — problems surface before guests complain |
Each step has a defined output. When the work is done, you hold the map of your own network.
Floor plans, wall structure, existing cabling and concurrent user counts are mapped. How many access points are needed, and where they go, is settled here.
Guest, staff and any special device networks are split into separate segments. Which segment may reach which resource is defined in writing.
Rule sets are applied, the hotspot and captive portal go live, and bandwidth quotas and content filtering are configured. The welcome page is built to your brand.
The user verification method goes live; access logging, timestamping and signed retention are tested end to end. Access rights are defined in writing.
Access point health, log flow and traffic patterns are monitored and alert rules are set. Configuration changes are managed with versioning.
Guest experience leads in a hotel, device isolation in a hospital, protection of corporate resources in an office. The deployment is designed around that priority.
Hotel
Room-based access with sessions limited to the length of stay. With front-desk integration, access opens at check-in and closes at check-out. The welcome page runs in the hotel’s branding and the guest’s language.
Hospital
Patient, staff and visitor networks are kept apart, and the medical device network is isolated in its own segment. Clinical systems are unreachable from the guest side, and critical traffic is prioritised.
Office and private company
Staff device policy, visitor guest access and protection of corporate resources are designed together. File servers, accounting systems and printers are invisible from the guest network; staff access is defined by role.
Café and restaurant
Sign-in has to be short — a customer will not fill in a long form. The welcome page works with one tap on a phone. Card terminals and order tablets are kept on a segment separate from guest traffic, so payments do not stall during the evening rush.
Student dormitory
Usage is long-running and peaks late at night. Without per-user quotas and fair-use rules the network chokes within the first week. Capacity is calculated from concurrent device counts, not from floor area.
Shopping centre and estate management
Common-area guest access, tenant networks and the management network are kept apart. In multi-site properties every location is managed from one panel and records are collected centrally.
Businesses that want to hand over network and systems as a whole combine this deployment with the outsourced IT support package: monitoring, alert handling and hardware maintenance all run under one roof.
Legal logging compliance is not a one-off installation but an obligation that has to run without gaps, so the service is delivered on a 12-month agreement: deployment, log retention, monitoring and maintenance scope are written into the contract, and the agreed fee does not change during the year. At year end, device count, log volume and scope are reviewed together and the agreement is signed again — nothing extends automatically, and continuing is your decision.
The site survey and inventory are free. At the end of it you receive, in writing, how many access points are needed, which of your existing devices can stay and what the scope is — that document stays with you even if you do not accept the quote.
No. What is kept is an access record: verified user identity, connect and disconnect times, device identifier and session details. The content of the pages visited is not recorded. Where content filtering is applied, the blocked category may also be logged; that is agreed in writing at setup.
For the period the regulation requires, with integrity preserved. The retention period, the retention responsibility and who may access the records are defined in writing at setup. If the regulation changes, the configuration is updated accordingly.
SMS, national e-government identity or social login can be used. Which one fits depends on venue type and guest profile: SMS often suits a hotel with mostly international guests, while e-government identity is more practical for organisations working with the public sector.
It is not. Guest mode on a consumer device usually just shares a password; it does not provide verified identity, timestamped access records or tamper-evident retention. For venues offering public internet access, that is exactly what is required.
Most enterprise-grade devices are compatible. After the site survey and inventory, we report what can stay and what needs replacing due to capacity or lack of firmware support. We do not recommend hardware changes you do not need.
Bandwidth quotas and traffic prioritisation keep guest traffic from affecting corporate traffic. VLAN separation also means a problem on the guest side does not spill into the corporate network.
From a small office to hotel and hospital deployments with hundreds of concurrent users. Access point count and placement are calculated in the capacity plan from concurrent user density.
It depends on the state of the existing infrastructure. A firm schedule follows the site survey; most office deployments finish in a single day. In multi-floor hotel and hospital installations, cabling and coverage work drive the timeline.
No. The management panel and the log retention service run in the cloud; you do not host a server, a backup unit or any separate machine. The only component on site is the hotspot gateway. On-premise hosting is possible for organisations that require it — we discuss that during the survey.
Yes. Every location is managed from a single panel and records are collected centrally. A user connects at any branch with the same username and password, so you do not distribute separate passwords per site. Opening a new branch means copying an existing policy to that location.
It does. Staff connect with their existing corporate account and no second user list is maintained. When a leaver’s directory account is closed, network access closes with it. Besides Active Directory, LDAP and in-house user databases can also drive verification.
No. Personal data is closed to unauthorised viewing; nobody — including your own system administrator — can read or alter records freely. Who may reach which record is defined in writing at setup, and every access is itself logged, so it is clear who viewed a record.
Yes. The captive portal is built with your logo, colours and corporate language, and more than one language can be defined. Campaign announcements, internal notices or the privacy notice can be delivered on the same screen.
Concurrent user count, number of locations, access point count and log volume are the drivers. The site survey and inventory are free, and the quote lists exactly which items are included. The fee stays fixed for the 12-month term.
Access point health, log flow and traffic patterns are monitored by us, with alert rules in place. The point is to see the problem before a guest complains. Monitoring, alert handling and configuration maintenance are inside the 12-month agreement.
Fill in the form and we will get back to you within 1 business day on the channel you choose. Your details are used only for this conversation.
Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.
Issued by Cisco · Holder: Devrim Tunçer
A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.
Cisco training certificate · completed January 2023
Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.
For hotels, hospitals, offices and other public-access venues, giving guests internet is not only technical but a legal obligation. In Türkiye, Law No. 5651 requires access logs to be kept, retained for a defined period and protected against tampering.
A consumer router's guest network does not meet that. Our hotspot service sets up user verification, log recording, timestamping and signed retention together.
The guest network is separated from the corporate network with VLANs — a guest device cannot reach the accounting machine. Firewall rule sets and config management sit with us; bandwidth quotas, content filtering and session policies are tuned to your venue.
Room-based access with stay-limited sessions in hotels, patient/staff/guest separation in hospitals, and device policy in offices. The captive portal is branded to you.