Security and content filtering inside the access point.
For regional ISPs, MVNOs, public Wi-Fi and corporate networks. The decision happens before traffic leaves the local network. No dedicated appliance, no diverting traffic to the cloud and no breaking the user's encryption.
Supplied by Padtec, with the Ring Zero engine built in and management by NetExperience.
In May 2026, Padtec, a Brazilian manufacturer listed on B3, announced this technology for its line of Wi-Fi 6 and Wi-Fi 7 enterprise access points, in partnership with Dominus Cyber. The certified models today are the Edgecore EAP101, EAP102, EAP105 and OAP101.
Read the official announcement ↗Three things that have already happened to you
If you run an access network in Brazil, you probably recognize at least two of them.
A blocking order arrives and someone has to carry it out by hand
In 2026, through September, the Ministry of Finance ordered 57,691 illegal betting addresses blocked, and the blocking is carried out by the service provider (Estado de Minas, 25/09/2026). A small provider handles this on the edge router, one by one, with no record of what was done.
A subscriber complains about content and you have no answer
Schools, city halls, hotels and companies want control over what goes through their Wi-Fi. Without a tool at the edge, the answer is always the same: it can't be done, or buy an appliance.
Link bandwidth spent on things nobody asked for
Ads, trackers and telemetry cross the whole backhaul only to be discarded at the end. You pay to carry traffic the user never wanted.
All three have the same cause: the decision about traffic happens far from where the traffic starts. With the check on the access point, the blocking rule is applied from the dashboard in bulk at the points with the gateway, control can be sold as a service, and what is dropped never uses the link.
Four types of network, the same decision at the edge
The same technology solves different problems depending on who runs the network.
ISPs and regional carriers
- Filtering and blocking applied on the access point, without rerouting traffic to a central appliance
- Events and crowded venues, with the radio profile sized in the project
- Policy per customer and per SSID, to sell secure Wi-Fi as a plan
- One dashboard for the whole access point fleet
MVNOs
- Blocking of phishing, scams and operator-defined categories, without decrypting traffic
- The same browsing policy at every Wi-Fi point
- Wi-Fi network visibility by location and region
- Bulk provisioning and batch actions across the whole fleet
Public hotspots and smart cities
- Citizen Wi-Fi isolated from the video surveillance and sensor network
- Ads blocked at the access point, keeping bandwidth for browsing
- Content filtering on the AP itself, with tender compliance checked during the project
- Central dashboard by neighborhood or municipality
Corporate networks and IoT
- Microsegmentation: guests isolated from medical records, POS terminals, cameras and smart TVs
- Bandwidth savings without buying a new link
- Web filter built into the AP, with no separate web filtering appliance
- Multi-site: hospitals, bank branches, hotel chains, franchises and industry
The path of a request
The gateway runs as an in-kernel application on the access point. The decision happens before traffic leaves the local network, and the use of encrypted DNS and bypass VPNs can be blocked.
The client joins the Wi-Fi network
VLAN assigned dynamically through 802.1X, keeping visitors away from critical systems.
DNS, TLS/SNI and HTTP are read on the AP
Analysis of connection metadata, without deep packet inspection (DPI). The user's encryption stays intact.
Allow, or drop it right there
Threats, trackers, ads and inappropriate content never consume link bandwidth.
The engine decides on the AP. The dashboard proves it in the browser.
These are two different jobs. One runs in milliseconds inside the access point. The other is the screen your team opens every day.
Inspects and decides at the edge
In-kernel application on the access point. It reads DNS, TLS/SNI and HTTP metadata, without decrypting, and drops whatever matches the policy before the traffic uses the link. Brazilian technology, born at LabLua at PUC-Rio.
Provisions, shows and proves
Cloud platform that controls the whole fleet: policy, provisioning, visibility of what was blocked and reports to hand over to the end customer.
Per customer, SSID or AP group
Different rules per customer, SSID or access point group, applied in bulk across the fleet, without configuring devices one by one.
Role-based portals
ISP, IT team, building manager, installer and end user. Each one sees what concerns them, without sharing administrator credentials.
The whole fleet on one screen
Bulk provisioning, automatic radio management, self-healing and packet capture. No need to open one screen per site.
REST API and webhooks
IPv4 and IPv6, with network events sent to the management system you already use.
Real screen Secure Wireless Gateway on the NetExperience dashboard, in the Dominus Cyber lab. In the test, the profile blocks a messaging service, which is why it shows among the most blocked destinations. IP addresses hidden.
The equipment arrives ready for the dashboard
The access point leaves Padtec with the inspection engine already built in. Dominus delivers and operates the NetExperience platform, where policy is defined, the fleet is managed and blocking is proven.
Models today: Edgecore EAP101, EAP102 and EAP105, for indoor use with Wi-Fi 6 and Wi-Fi 7, and OAP101, for outdoor use. The list grows as new devices pass certification. Since everything runs on the open TIP OpenWiFi standard, the hardware is not proprietary.
Planned for 2027: switches and a gateway with the Secure Wireless Gateway, managed in the same NetExperience dashboard.
How this differs from a DNS filter or a UTM appliance
Three architectures for the same problem, side by side.
| SWG on the access point | DNS filter | UTM appliance | |
|---|---|---|---|
| Where the decision happens | On the AP itself, at the edge | At the resolver, outside the network | On a central device |
| Dedicated hardware | None | None | Required |
| Blocks encrypted DNS and bypass VPNs | Yes | Usually, no | Depends on DPI |
| Breaks the user's encryption | No | No | With TLS inspection on, yes |
| Link bandwidth savings | Yes, ads and trackers stopped at the AP | Partial | Depends on topology |
| Vendor dependency | TIP OpenWiFi standard | Varies | High |
The row that decides is the one about encrypted DNS and bypass VPNs. A DNS filter solves a lot, until the device uses DNS over HTTPS or opens a tunnel. Then the query no longer goes through your resolver and the policy stops applying. On the access point, the decision also uses the destination declared in the TLS handshake, and encrypted DNS and bypass VPNs can be blocked as a rule. What travels inside an authorized tunnel stays outside the inspection. The table compares typical architectures; the features of each product vary by vendor.
A Brazilian company, with a name and an address.
Dominus Cyber delivers security management and operations at the access layer, the point of the network where the subscriber connects and where the operator usually has neither visibility nor control.
In Brazil, we represent NetExperience and Ring Zero Networks. On the NetExperience platform the policy is defined, the fleet is provisioned and blocking is proven. The Ring Zero inspection engine was born at the LabLua lab of PUC-Rio and was selected in 2024 for OpenRAN@Brasil, a program coordinated by RNP and CPQD. It ships embedded in the access points of Padtec.
What people ask before signing
Do I need to replace my access points?
Yes, at the points that will get the gateway. The access points come from Padtec, with the inspection engine already built in and ready to join the dashboard. Today the models are the Edgecore EAP101, EAP102, EAP105 and OAP101, and the list grows as new devices pass certification.
You don't need to cover everything at once. The usual path is to start where security matters most and expand later, with the new devices working alongside what is already installed.
How do I run this day to day?
Through the management platform, in the browser. Policy per customer, SSID or AP group, bulk provisioning, visibility of what was blocked and reports to hand over to the end customer.
There are role-based portals, so your field team and the end customer get access without administrator credentials. There is also a REST API and webhooks, to integrate with the system you already use.
Do you see what my subscriber accesses?
Not the content. The decision uses the name queried in DNS and the destination declared in the TLS handshake, without opening the sessions.
The activity report is optional per profile. When on, it shows the domains accessed per device. When off, blocking still applies and browsing is not recorded. For connection providers, article 14 of the Marco Civil da Internet forbids keeping records of access to applications, so the setup for each case is defined in the project.
What if the device uses encrypted DNS or a VPN?
That is the difference from a DNS filter. When the query no longer goes through your resolver, the DNS filter stops working. On the access point, the decision continues based on the destination declared in the TLS handshake, and the use of encrypted DNS and bypass VPNs can be blocked as a rule.
How does licensing work?
Per access point, with density tiers defined during sizing. The final price depends on the size of the fleet and the operating model, and comes with the technical assessment. We don't publish a price list because ISP projects and corporate projects are designed very differently.
How does it start, in practice?
First the technical assessment, which is free: you tell us how many points you need to cover and what the scenario is, and we return the sizing, what would be blocked at the edge and how equipment supply fits in.
Then a phased rollout, carried out with the partner that supplies and installs the equipment, with a policy defined together that can be reversed. No step requires stopping operations.
Who helps when something goes wrong?
Support has three levels and a single entry point. The first contact is whoever supplied and installed the equipment, who handles power, cabling, placement and restarts.
Anything beyond that comes to Dominus, which works on the platform: advanced configuration, radio diagnostics, session analysis, remote traffic capture and firmware update management. If the cause is a firmware or platform failure, we escalate to NetExperience, the platform vendor, and return the answer the same way.
Start with the technical assessment.
Tell us how many points you need to cover and what the scenario is. We return the project design and a sample of what would be blocked at the edge. No commitment and no cost.
Security and content filtering inside the access point.
For regional ISPs, MVNOs, public Wi-Fi and corporate networks. The decision happens before traffic leaves the local network. No dedicated appliance, no diverting traffic to the cloud and no breaking the user's encryption.
Supplied by Padtec, with the Ring Zero engine built in and management by NetExperience.
In May 2026, Padtec, a Brazilian manufacturer listed on B3, announced this technology for its line of Wi-Fi 6 and Wi-Fi 7 enterprise access points, in partnership with Dominus Cyber. The certified models today are the Edgecore EAP101, EAP102, EAP105 and OAP101.
Read the official announcement ↗Three things that have already happened to you
If you run an access network in Brazil, you probably recognize at least two of them.
A blocking order arrives and someone has to carry it out by hand
In 2026, through September, the Ministry of Finance ordered 57,691 illegal betting addresses blocked, and the blocking is carried out by the service provider (Estado de Minas, 25/09/2026). A small provider handles this on the edge router, one by one, with no record of what was done.
A subscriber complains about content and you have no answer
Schools, city halls, hotels and companies want control over what goes through their Wi-Fi. Without a tool at the edge, the answer is always the same: it can't be done, or buy an appliance.
Link bandwidth spent on things nobody asked for
Ads, trackers and telemetry cross the whole backhaul only to be discarded at the end. You pay to carry traffic the user never wanted.
All three have the same cause: the decision about traffic happens far from where the traffic starts. With the check on the access point, the blocking rule is applied from the dashboard in bulk at the points with the gateway, control can be sold as a service, and what is dropped never uses the link.
Four types of network, the same decision at the edge
The same technology solves different problems depending on who runs the network.
ISPs and regional carriers
- Filtering and blocking applied on the access point, without rerouting traffic to a central appliance
- Events and crowded venues, with the radio profile sized in the project
- Policy per customer and per SSID, to sell secure Wi-Fi as a plan
- One dashboard for the whole access point fleet
MVNOs
- Blocking of phishing, scams and operator-defined categories, without decrypting traffic
- The same browsing policy at every Wi-Fi point
- Wi-Fi network visibility by location and region
- Bulk provisioning and batch actions across the whole fleet
Public hotspots and smart cities
- Citizen Wi-Fi isolated from the video surveillance and sensor network
- Ads blocked at the access point, keeping bandwidth for browsing
- Content filtering on the AP itself, with tender compliance checked during the project
- Central dashboard by neighborhood or municipality
Corporate networks and IoT
- Microsegmentation: guests isolated from medical records, POS terminals, cameras and smart TVs
- Bandwidth savings without buying a new link
- Web filter built into the AP, with no separate web filtering appliance
- Multi-site: hospitals, bank branches, hotel chains, franchises and industry
The path of a request
The gateway runs as an in-kernel application on the access point. The decision happens before traffic leaves the local network, and the use of encrypted DNS and bypass VPNs can be blocked.
The client joins the Wi-Fi network
VLAN assigned dynamically through 802.1X, keeping visitors away from critical systems.
DNS, TLS/SNI and HTTP are read on the AP
Analysis of connection metadata, without deep packet inspection (DPI). The user's encryption stays intact.
Allow, or drop it right there
Threats, trackers, ads and inappropriate content never consume link bandwidth.
The engine decides on the AP. The dashboard proves it in the browser.
These are two different jobs. One runs in milliseconds inside the access point. The other is the screen your team opens every day.
Inspects and decides at the edge
In-kernel application on the access point. It reads DNS, TLS/SNI and HTTP metadata, without decrypting, and drops whatever matches the policy before the traffic uses the link. Brazilian technology, born at LabLua at PUC-Rio.
Provisions, shows and proves
Cloud platform that controls the whole fleet: policy, provisioning, visibility of what was blocked and reports to hand over to the end customer.
Per customer, SSID or AP group
Different rules per customer, SSID or access point group, applied in bulk across the fleet, without configuring devices one by one.
Role-based portals
ISP, IT team, building manager, installer and end user. Each one sees what concerns them, without sharing administrator credentials.
The whole fleet on one screen
Bulk provisioning, automatic radio management, self-healing and packet capture. No need to open one screen per site.
REST API and webhooks
IPv4 and IPv6, with network events sent to the management system you already use.
Real screen Secure Wireless Gateway on the NetExperience dashboard, in the Dominus Cyber lab. In the test, the profile blocks a messaging service, which is why it shows among the most blocked destinations. IP addresses hidden.
The equipment arrives ready for the dashboard
The access point leaves Padtec with the inspection engine already built in. Dominus delivers and operates the NetExperience platform, where policy is defined, the fleet is managed and blocking is proven.
Models today: Edgecore EAP101, EAP102 and EAP105, for indoor use with Wi-Fi 6 and Wi-Fi 7, and OAP101, for outdoor use. The list grows as new devices pass certification. Since everything runs on the open TIP OpenWiFi standard, the hardware is not proprietary.
Planned for 2027: switches and a gateway with the Secure Wireless Gateway, managed in the same NetExperience dashboard.
How this differs from a DNS filter or a UTM appliance
Three architectures for the same problem, side by side.
| SWG on the access point | DNS filter | UTM appliance | |
|---|---|---|---|
| Where the decision happens | On the AP itself, at the edge | At the resolver, outside the network | On a central device |
| Dedicated hardware | None | None | Required |
| Blocks encrypted DNS and bypass VPNs | Yes | Usually, no | Depends on DPI |
| Breaks the user's encryption | No | No | With TLS inspection on, yes |
| Link bandwidth savings | Yes, ads and trackers stopped at the AP | Partial | Depends on topology |
| Vendor dependency | TIP OpenWiFi standard | Varies | High |
The row that decides is the one about encrypted DNS and bypass VPNs. A DNS filter solves a lot, until the device uses DNS over HTTPS or opens a tunnel. Then the query no longer goes through your resolver and the policy stops applying. On the access point, the decision also uses the destination declared in the TLS handshake, and encrypted DNS and bypass VPNs can be blocked as a rule. What travels inside an authorized tunnel stays outside the inspection. The table compares typical architectures; the features of each product vary by vendor.
A Brazilian company, with a name and an address.
Dominus Cyber delivers security management and operations at the access layer, the point of the network where the subscriber connects and where the operator usually has neither visibility nor control.
In Brazil, we represent NetExperience and Ring Zero Networks. On the NetExperience platform the policy is defined, the fleet is provisioned and blocking is proven. The Ring Zero inspection engine was born at the LabLua lab of PUC-Rio and was selected in 2024 for OpenRAN@Brasil, a program coordinated by RNP and CPQD. It ships embedded in the access points of Padtec.
What people ask before signing
Do I need to replace my access points?
Yes, at the points that will get the gateway. The access points come from Padtec, with the inspection engine already built in and ready to join the dashboard. Today the models are the Edgecore EAP101, EAP102, EAP105 and OAP101, and the list grows as new devices pass certification.
You don't need to cover everything at once. The usual path is to start where security matters most and expand later, with the new devices working alongside what is already installed.
How do I run this day to day?
Through the management platform, in the browser. Policy per customer, SSID or AP group, bulk provisioning, visibility of what was blocked and reports to hand over to the end customer.
There are role-based portals, so your field team and the end customer get access without administrator credentials. There is also a REST API and webhooks, to integrate with the system you already use.
Do you see what my subscriber accesses?
Not the content. The decision uses the name queried in DNS and the destination declared in the TLS handshake, without opening the sessions.
The activity report is optional per profile. When on, it shows the domains accessed per device. When off, blocking still applies and browsing is not recorded. For connection providers, article 14 of the Marco Civil da Internet forbids keeping records of access to applications, so the setup for each case is defined in the project.
What if the device uses encrypted DNS or a VPN?
That is the difference from a DNS filter. When the query no longer goes through your resolver, the DNS filter stops working. On the access point, the decision continues based on the destination declared in the TLS handshake, and the use of encrypted DNS and bypass VPNs can be blocked as a rule.
How does licensing work?
Per access point, with density tiers defined during sizing. The final price depends on the size of the fleet and the operating model, and comes with the technical assessment. We don't publish a price list because ISP projects and corporate projects are designed very differently.
How does it start, in practice?
First the technical assessment, which is free: you tell us how many points you need to cover and what the scenario is, and we return the sizing, what would be blocked at the edge and how equipment supply fits in.
Then a phased rollout, carried out with the partner that supplies and installs the equipment, with a policy defined together that can be reversed. No step requires stopping operations.
Who helps when something goes wrong?
Support has three levels and a single entry point. The first contact is whoever supplied and installed the equipment, who handles power, cabling, placement and restarts.
Anything beyond that comes to Dominus, which works on the platform: advanced configuration, radio diagnostics, session analysis, remote traffic capture and firmware update management. If the cause is a firmware or platform failure, we escalate to NetExperience, the platform vendor, and return the answer the same way.
Start with the technical assessment.
Tell us how many points you need to cover and what the scenario is. We return the project design and a sample of what would be blocked at the edge. No commitment and no cost.