Exclusive Access · Invitation Only
Home Features Pricing Releases Docs Marketplace Sign in Get Started
CENVERO/STRATUM capability index
Complete capability set

Every feature, one platform

The complete Cenvero Stratum capability set — from high-performance networking and the zero-trust firewall to NAT, failover IPs, BGP and gateway HA.

Categories
  • High-Performance Networking
    • In-kernel packet processing Traffic is filtered and forwarded in the kernel fast path, before it touches user space.
    • Source-IP blocklist Block traffic from specific addresses right at the network edge, each with an optional expiry.
    • MAC & VLAN lockdown Lock every port to approved hardware addresses and VLANs.
    • Zero-downtime reloads Change networking rules without dropping a single connection.
  • IP Address Management
    • Address pools IPv4 and IPv6 pools with automatic dual-stack assignment and release.
    • Conflict detection Overlapping or already-used addresses are rejected before they cause problems.
    • Per-tenant address space Separate address ranges for each tenant.
    • Full visibility See every lease and allocation at a glance.
  • DHCP & DNS
    • DHCP server Hand out addresses per network with automatic renew and expiry, plus flood protection.
    • Authoritative DNS Run your own zones and records — A, AAAA, CNAME and more.
    • Split answers Give internal and external clients different DNS answers.
    • Filtering & caching Sinkhole unwanted domains, sign responses, cache, and forward upstream.
  • Routing & NAT
    • Static & policy routing Programmable routing tables with policy-based rules.
    • Outbound NAT Lets tenant traffic reach the internet from shared addresses.
    • Inbound port forwarding Expose internal services to the outside with port forwards.
    • Dual-stack support IPv4 and IPv6 routing and NAT, including NAT66, side by side.
    • Shared public IP Source-NAT masquerade lets many private tenants share a single public address to reach the internet.
    • Hairpin NAT Reach an internal service through its own public address from inside the same network.
    • NAT64 IPv6-only clients can reach IPv4-only services through the gateway.
    • Ping through the gateway Tenants can ping hosts on the internet, with replies tracked back to the right sender.
    • Live rule management Add, list and remove rules while everything keeps running.
  • Overlay Networks
    • VXLAN overlays Stretch a single Layer-2 network across hosts and racks over your existing IP fabric.
    • Tenant isolation Each overlay carries its own segment so tenants never see each other’s traffic.
    • Spans the whole cluster Workloads on different physical hosts share one virtual network as if they were side by side.
    • In-kernel encapsulation Overlay packets are wrapped and unwrapped in the kernel datapath.
    • Geneve tunnels Standards-based Geneve overlay tunnels can run alongside VXLAN for flexible encapsulation.
    • Virtual routing & forwarding Separate routing tables per VRF keep overlapping tenant networks isolated.
  • Anti-Spoofing
    • IP-to-MAC binding Every port is locked to its approved address pair, so nobody can impersonate another host.
    • ARP protection Forged ARP replies are dropped at the edge, stopping man-in-the-middle attacks.
    • IPv6 NDP guard Neighbour-discovery spoofing on IPv6 is blocked the same way as ARP on IPv4.
    • Enforced in the datapath Anti-spoof checks run inline on every packet, not as an afterthought.
    • IPv6 RA-guard Rogue router advertisements from tenant ports are dropped, stopping gateway hijacking.
    • DHCP snooping Tenant ports can never pose as the address server, for both DHCP and DHCPv6.
  • Connection Tracking
    • Stateful inspection Only packets belonging to a known, allowed connection are let through.
    • Automatic return traffic Replies to outbound flows are recognised and admitted without extra rules.
    • Flow table Active connections are tracked across the datapath with automatic ageing.
    • Backs the firewall & NAT The same connection state powers stateful firewalling and address translation.
  • Failover & Floating IPs
    • Portable IPs Assign movable IPs to any host in the cluster.
    • Automatic failover A floating IP moves to a healthy host the moment one fails.
    • Instant takeover Traffic reroutes to the new host within milliseconds.
    • Cluster-wide ownership Which host owns each IP is replicated across the whole cluster.
  • BGP Edge Routing
    • Advertise your networks Peer with upstream routers and announce your VM networks.
    • Smart path selection The best route to each destination is chosen automatically.
    • Route filtering Control exactly which routes you import and export.
    • Resilient peering Lossless restarts and sub-second detection of neighbour failures.
    • RPKI origin validation Received routes are checked against signed RPKI data, and invalid origins are rejected.
    • EVPN address family Exchange MAC and VTEP reachability for the VXLAN overlay as BGP routes.
  • Gateway High Availability
    • Redundant gateways A standby gateway takes over automatically if the active one fails.
    • Fast failure detection A dedicated heartbeat spots failures in under a second.
    • Failover & failback Automatic failover, with operator-controlled failback when you choose.
    • One owner per IP Exactly one gateway owns each virtual IP at any moment.
  • Zero-Trust Firewall
    • Layered policy Rules from network-wide down to a single VM, evaluated by priority.
    • Default-deny Nothing passes unless you allow it, with stateful connection tracking throughout.
    • Rich matching Match on address, network, port, protocol, hardware address or domain.
    • Scheduled rules Turn rules on and off by day and time.
    • Domain-based rules Allow or block by domain name, kept in sync automatically.
    • Conflict detection Overlapping or contradictory rules are caught before they apply.
    • Presets & batch apply Web, database, mail and game-server presets applied all at once.
    • Hardware binding Bind ports to specific devices, hard or soft.
    • Per-source connection limits Cap how many connections any single source can open, blocking abusers automatically.
  • Intrusion Detection
    • Traffic anomaly detection Suspicious traffic patterns are spotted as packets flow through the platform.
    • Early threat signal Get alerted to probing and abnormal behaviour before it becomes an incident.
    • Works with the firewall Detection sits alongside the zero-trust firewall for layered defence.
    • Tied into alerting Detections surface through the same alerting and event stream as everything else.
  • Load Balancing
    • Virtual IPs High-speed load balancing spread across your backends.
    • Balancing algorithms Round-robin, least-connections, weighted and source-hash.
    • Stable backend selection Consistent hashing keeps each client on the same backend.
    • Health checks Unhealthy backends are removed automatically, with fast return paths.
    • Layer-7 HTTP balancing Route HTTP traffic by host and path, with optional TLS termination at the balancer.
  • Bandwidth & Usage
    • Bandwidth limits Per-VM upload and download limits, shared pools and burst allowances.
    • Monthly quotas Usage caps that reset automatically each month.
    • Usage-based billing Byte and packet accounting with 95th-percentile calculation.
    • Flow records & export Per-connection stats with CSV and JSON export.
  • Clustering & Virtual Networks
    • Virtual networks Isolated networks that span every host in the cluster.
    • Resilient cluster state Leader election and replicated state keep the cluster consistent.
    • Everything replicated Addresses, blocklists, peers, floating IPs and tenants stay in sync cluster-wide.
    • Compute & gateway nodes Run a node as a VM host or as a traffic gateway.
  • Multi-Tenancy & Isolation
    • Tenant management Create tenants with their own quotas and usage tracking.
    • Scoped API keys Generate, validate, expire and revoke keys per tenant.
    • Private networks Isolated networks with controlled membership.
    • Container networking Attach containers to the same managed networks, firewall and address pools as VMs.
    • Workload portability The same networking model applies whether a workload is a VM or a container.
  • Interfaces & Hardware
    • Network-card management Physical network cards are detected and given stable names.
    • Link bonding Combine multiple links for redundancy or more throughput.
    • Consistent packet sizes Matching packet sizes across bonded links and virtual networks.
    • Tamper protection Changes to managed interfaces made outside the platform are detected and reconciled back to their intended configuration.
    • Interface lockdown An optional kernel-level guard blocks out-of-band deletion of managed interfaces in real time.
    • Optional hardware offload Where the network card supports it, packet processing can offload to hardware, while software stays the default.
  • Observability
    • Metrics & dashboards Prometheus-compatible metrics for your dashboards and alerting.
    • Alerting Threshold alerts with actions, cooldown and history.
    • Live events A real-time event stream across the whole system.
    • Audit log A structured record of every management action.
    • Event webhooks Push signed event notifications to your own endpoints, each carrying an HMAC signature.
  • Platform & Lifecycle
    • Backup & restore Full and config backups with schedules and retention.
    • Self-update Signed, pull-based updates the agent verifies against its baked-in publisher key before applying.
    • Self-healing Automatic checks and repair for disk, memory, database and networking.
    • Always-on supervision An independent watchdog restarts the platform if it ever stalls.
  • Account TLS & Private CA
    • Per-account certificate authority Each account gets its own private CA, so certificates from one account never trust another.
    • Automatic node certificates Nodes are issued signed leaf certificates the moment they activate — no manual key wrangling.
    • Auto-trust Every node automatically trusts its own account CA, so internal traffic is encrypted out of the box.
    • Automatic renewal Certificates renew themselves before they expire, with no downtime or operator action.
    • Domain-change re-signing Change a node’s domain and a fresh certificate is issued and rolled out automatically.
  • Plugins & Developer Program
    • Signed plugins Extend the platform with plugins that are cryptographically signed and verified before they run.
    • Built-in store Discover and install plugins from a built-in store right inside the platform.
    • Developer program Approved developers receive their own signing certificates to build and publish plugins.
    • Publish to the marketplace Ship your plugin to other operators through the marketplace.
    • Revocation A signed revocation list instantly disables any compromised or withdrawn plugin.
  • Security
    • Signed end-to-end Configs, licenses, plugins and binaries are all cryptographically signed.
    • Brute-force protection Repeated failed logins are locked out.
    • Request validation Body-size and content-type limits on every API.
    • Anti-tampering Time-drift and clock-spoofing checks keep the platform honest even offline.
  • Single Sign-On
    • SAML 2.0 sign-on Your team can sign in through any SAML identity provider, kept off until an admin turns it on.
    • OpenID Connect sign-on Sign in through any OpenID Connect provider, with new accounts created as plain customers.
    • Role-based access Scope operator accounts to admin, operator, billing or read-only roles.
  • Licensing & Activation
    • Hardware-bound licences Each licence is tied to the machine it runs on and cannot be copied elsewhere.
    • Per-machine activation Activate node by node, with each activation recorded against your licence.
    • Silent auto-renewal Licences renew quietly in the background so coverage never lapses.
    • Key regeneration Roll a node’s key when you need to, without losing its activation.
    • Guided onboarding New nodes pull their full configuration on first contact and are ready in minutes.
    • Revocation A signed revocation list lets you retire a licence instantly across the fleet.
  • Billing & Wallet
    • Plans & billing cycles Choose a plan and a monthly, quarterly, semi-annual or annual cycle.
    • Account wallet Keep a balance on file to cover renewals and new orders.
    • Automatic renewal payments Renewals are paid from your wallet automatically, with an invoice issued ahead of time.
    • Discount coupons Apply percentage or fixed-amount coupon codes at checkout.
    • PDF invoices Every paid order generates a downloadable, numbered PDF invoice.
    • Order & proof workflow Place an order, submit payment proof, and get your licence once it’s verified.
  • APIs, CLI & Onboarding
    • Full API access REST, gRPC, WebSocket and a local control socket.
    • Command-line control Manage every feature from one command-line tool.
    • Scriptable activation License-gated install + activation that drops straight into automation.
    • Bulk operations Create many firewall rules or DNS records in a single API request.
High-Performance Networking

High-Performance Networking

01

In-kernel packet processing

Traffic is filtered and forwarded in the kernel fast path, before it touches user space.

02

Source-IP blocklist

Block traffic from specific addresses right at the network edge, each with an optional expiry.

03

MAC & VLAN lockdown

Lock every port to approved hardware addresses and VLANs.

04

Zero-downtime reloads

Change networking rules without dropping a single connection.

IP Address Management

IP Address Management

01

Address pools

IPv4 and IPv6 pools with automatic dual-stack assignment and release.

02

Conflict detection

Overlapping or already-used addresses are rejected before they cause problems.

03

Per-tenant address space

Separate address ranges for each tenant.

04

Full visibility

See every lease and allocation at a glance.

DHCP & DNS

DHCP & DNS

01

DHCP server

Hand out addresses per network with automatic renew and expiry, plus flood protection.

02

Authoritative DNS

Run your own zones and records — A, AAAA, CNAME and more.

03

Split answers

Give internal and external clients different DNS answers.

04

Filtering & caching

Sinkhole unwanted domains, sign responses, cache, and forward upstream.

Routing & NAT

Routing & NAT

01

Static & policy routing

Programmable routing tables with policy-based rules.

02

Outbound NAT

Lets tenant traffic reach the internet from shared addresses.

03

Inbound port forwarding

Expose internal services to the outside with port forwards.

04

Dual-stack support

IPv4 and IPv6 routing and NAT, including NAT66, side by side.

05

Shared public IP

Source-NAT masquerade lets many private tenants share a single public address to reach the internet.

06

Hairpin NAT

Reach an internal service through its own public address from inside the same network.

07

NAT64

IPv6-only clients can reach IPv4-only services through the gateway.

08

Ping through the gateway

Tenants can ping hosts on the internet, with replies tracked back to the right sender.

09

Live rule management

Add, list and remove rules while everything keeps running.

Overlay Networks

Overlay Networks

01

VXLAN overlays

Stretch a single Layer-2 network across hosts and racks over your existing IP fabric.

02

Tenant isolation

Each overlay carries its own segment so tenants never see each other’s traffic.

03

Spans the whole cluster

Workloads on different physical hosts share one virtual network as if they were side by side.

04

In-kernel encapsulation

Overlay packets are wrapped and unwrapped in the kernel datapath.

05

Geneve tunnels

Standards-based Geneve overlay tunnels can run alongside VXLAN for flexible encapsulation.

06

Virtual routing & forwarding

Separate routing tables per VRF keep overlapping tenant networks isolated.

Anti-Spoofing

Anti-Spoofing

01

IP-to-MAC binding

Every port is locked to its approved address pair, so nobody can impersonate another host.

02

ARP protection

Forged ARP replies are dropped at the edge, stopping man-in-the-middle attacks.

03

IPv6 NDP guard

Neighbour-discovery spoofing on IPv6 is blocked the same way as ARP on IPv4.

04

Enforced in the datapath

Anti-spoof checks run inline on every packet, not as an afterthought.

05

IPv6 RA-guard

Rogue router advertisements from tenant ports are dropped, stopping gateway hijacking.

06

DHCP snooping

Tenant ports can never pose as the address server, for both DHCP and DHCPv6.

Connection Tracking

Connection Tracking

01

Stateful inspection

Only packets belonging to a known, allowed connection are let through.

02

Automatic return traffic

Replies to outbound flows are recognised and admitted without extra rules.

03

Flow table

Active connections are tracked across the datapath with automatic ageing.

04

Backs the firewall & NAT

The same connection state powers stateful firewalling and address translation.

Failover & Floating IPs

Failover & Floating IPs

01

Portable IPs

Assign movable IPs to any host in the cluster.

02

Automatic failover

A floating IP moves to a healthy host the moment one fails.

03

Instant takeover

Traffic reroutes to the new host within milliseconds.

04

Cluster-wide ownership

Which host owns each IP is replicated across the whole cluster.

BGP Edge Routing

BGP Edge Routing

01

Advertise your networks

Peer with upstream routers and announce your VM networks.

02

Smart path selection

The best route to each destination is chosen automatically.

03

Route filtering

Control exactly which routes you import and export.

04

Resilient peering

Lossless restarts and sub-second detection of neighbour failures.

05

RPKI origin validation

Received routes are checked against signed RPKI data, and invalid origins are rejected.

06

EVPN address family

Exchange MAC and VTEP reachability for the VXLAN overlay as BGP routes.

Gateway High Availability

Gateway High Availability

01

Redundant gateways

A standby gateway takes over automatically if the active one fails.

02

Fast failure detection

A dedicated heartbeat spots failures in under a second.

03

Failover & failback

Automatic failover, with operator-controlled failback when you choose.

04

One owner per IP

Exactly one gateway owns each virtual IP at any moment.

Zero-Trust Firewall

Zero-Trust Firewall

01

Layered policy

Rules from network-wide down to a single VM, evaluated by priority.

02

Default-deny

Nothing passes unless you allow it, with stateful connection tracking throughout.

03

Rich matching

Match on address, network, port, protocol, hardware address or domain.

04

Scheduled rules

Turn rules on and off by day and time.

05

Domain-based rules

Allow or block by domain name, kept in sync automatically.

06

Conflict detection

Overlapping or contradictory rules are caught before they apply.

07

Presets & batch apply

Web, database, mail and game-server presets applied all at once.

08

Hardware binding

Bind ports to specific devices, hard or soft.

09

Per-source connection limits

Cap how many connections any single source can open, blocking abusers automatically.

Intrusion Detection

Intrusion Detection

01

Traffic anomaly detection

Suspicious traffic patterns are spotted as packets flow through the platform.

02

Early threat signal

Get alerted to probing and abnormal behaviour before it becomes an incident.

03

Works with the firewall

Detection sits alongside the zero-trust firewall for layered defence.

04

Tied into alerting

Detections surface through the same alerting and event stream as everything else.

Load Balancing

Load Balancing

01

Virtual IPs

High-speed load balancing spread across your backends.

02

Balancing algorithms

Round-robin, least-connections, weighted and source-hash.

03

Stable backend selection

Consistent hashing keeps each client on the same backend.

04

Health checks

Unhealthy backends are removed automatically, with fast return paths.

05

Layer-7 HTTP balancing

Route HTTP traffic by host and path, with optional TLS termination at the balancer.

Bandwidth & Usage

Bandwidth & Usage

01

Bandwidth limits

Per-VM upload and download limits, shared pools and burst allowances.

02

Monthly quotas

Usage caps that reset automatically each month.

03

Usage-based billing

Byte and packet accounting with 95th-percentile calculation.

04

Flow records & export

Per-connection stats with CSV and JSON export.

Clustering & Virtual Networks

Clustering & Virtual Networks

01

Virtual networks

Isolated networks that span every host in the cluster.

02

Resilient cluster state

Leader election and replicated state keep the cluster consistent.

03

Everything replicated

Addresses, blocklists, peers, floating IPs and tenants stay in sync cluster-wide.

04

Compute & gateway nodes

Run a node as a VM host or as a traffic gateway.

Multi-Tenancy & Isolation

Multi-Tenancy & Isolation

01

Tenant management

Create tenants with their own quotas and usage tracking.

02

Scoped API keys

Generate, validate, expire and revoke keys per tenant.

03

Private networks

Isolated networks with controlled membership.

04

Container networking

Attach containers to the same managed networks, firewall and address pools as VMs.

05

Workload portability

The same networking model applies whether a workload is a VM or a container.

Interfaces & Hardware

Interfaces & Hardware

01

Network-card management

Physical network cards are detected and given stable names.

02

Link bonding

Combine multiple links for redundancy or more throughput.

03

Consistent packet sizes

Matching packet sizes across bonded links and virtual networks.

04

Tamper protection

Changes to managed interfaces made outside the platform are detected and reconciled back to their intended configuration.

05

Interface lockdown

An optional kernel-level guard blocks out-of-band deletion of managed interfaces in real time.

06

Optional hardware offload

Where the network card supports it, packet processing can offload to hardware, while software stays the default.

Observability

Observability

01

Metrics & dashboards

Prometheus-compatible metrics for your dashboards and alerting.

02

Alerting

Threshold alerts with actions, cooldown and history.

03

Live events

A real-time event stream across the whole system.

04

Audit log

A structured record of every management action.

05

Event webhooks

Push signed event notifications to your own endpoints, each carrying an HMAC signature.

Platform & Lifecycle

Platform & Lifecycle

01

Backup & restore

Full and config backups with schedules and retention.

02

Self-update

Signed, pull-based updates the agent verifies against its baked-in publisher key before applying.

03

Self-healing

Automatic checks and repair for disk, memory, database and networking.

04

Always-on supervision

An independent watchdog restarts the platform if it ever stalls.

Account TLS & Private CA

Account TLS & Private CA

01

Per-account certificate authority

Each account gets its own private CA, so certificates from one account never trust another.

02

Automatic node certificates

Nodes are issued signed leaf certificates the moment they activate — no manual key wrangling.

03

Auto-trust

Every node automatically trusts its own account CA, so internal traffic is encrypted out of the box.

04

Automatic renewal

Certificates renew themselves before they expire, with no downtime or operator action.

05

Domain-change re-signing

Change a node’s domain and a fresh certificate is issued and rolled out automatically.

Plugins & Developer Program

Plugins & Developer Program

01

Signed plugins

Extend the platform with plugins that are cryptographically signed and verified before they run.

02

Built-in store

Discover and install plugins from a built-in store right inside the platform.

03

Developer program

Approved developers receive their own signing certificates to build and publish plugins.

04

Publish to the marketplace

Ship your plugin to other operators through the marketplace.

05

Revocation

A signed revocation list instantly disables any compromised or withdrawn plugin.

Security

Security

01

Signed end-to-end

Configs, licenses, plugins and binaries are all cryptographically signed.

02

Brute-force protection

Repeated failed logins are locked out.

03

Request validation

Body-size and content-type limits on every API.

04

Anti-tampering

Time-drift and clock-spoofing checks keep the platform honest even offline.

Single Sign-On

Single Sign-On

01

SAML 2.0 sign-on

Your team can sign in through any SAML identity provider, kept off until an admin turns it on.

02

OpenID Connect sign-on

Sign in through any OpenID Connect provider, with new accounts created as plain customers.

03

Role-based access

Scope operator accounts to admin, operator, billing or read-only roles.

Licensing & Activation

Licensing & Activation

01

Hardware-bound licences

Each licence is tied to the machine it runs on and cannot be copied elsewhere.

02

Per-machine activation

Activate node by node, with each activation recorded against your licence.

03

Silent auto-renewal

Licences renew quietly in the background so coverage never lapses.

04

Key regeneration

Roll a node’s key when you need to, without losing its activation.

05

Guided onboarding

New nodes pull their full configuration on first contact and are ready in minutes.

06

Revocation

A signed revocation list lets you retire a licence instantly across the fleet.

Billing & Wallet

Billing & Wallet

01

Plans & billing cycles

Choose a plan and a monthly, quarterly, semi-annual or annual cycle.

02

Account wallet

Keep a balance on file to cover renewals and new orders.

03

Automatic renewal payments

Renewals are paid from your wallet automatically, with an invoice issued ahead of time.

04

Discount coupons

Apply percentage or fixed-amount coupon codes at checkout.

05

PDF invoices

Every paid order generates a downloadable, numbered PDF invoice.

06

Order & proof workflow

Place an order, submit payment proof, and get your licence once it’s verified.

APIs, CLI & Onboarding

APIs, CLI & Onboarding

01

Full API access

REST, gRPC, WebSocket and a local control socket.

02

Command-line control

Manage every feature from one command-line tool.

03

Scriptable activation

License-gated install + activation that drops straight into automation.

04

Bulk operations

Create many firewall rules or DNS records in a single API request.

CENVERO/STRATUM deploy today
Deploy

Ready to deploy?

Every feature is included with each license.