The browsing filter that runs inside the access point.
The Secure Wireless Gateway is an application that runs in the access point kernel, the core of the device's system, and inspects DNS, TLS/SNI and HTTP on the AP itself. The decision to allow or drop happens before traffic leaves the local network, with no dedicated appliance and without breaking the user's encryption.
In May 2026, Padtec, a Brazilian manufacturer listed on B3, announced this technology for its line of Wi-Fi 6 and Wi-Fi 7 enterprise access points, in partnership with Dominus Cyber. The certified models today are the Edgecore EAP101, EAP102, EAP105 and OAP101.
Read the official announcement ↗How a request is evaluated
The request is evaluated in sequence inside the access point. If nothing matches the lists, it goes through. If it matches, it is dropped right there, without using link bandwidth.
The name is resolved
The DNS query is read on the AP itself and compared with the active lists before it goes out to the resolver.
SNI reveals the destination
In HTTPS sessions, the SNI field of the TLS handshake shows where the connection is going without decrypting anything.
Allow or drop
With no match, traffic flows normally. With a match, it is dropped at the edge and does not use the link.
Two layers, one operation
One decides in milliseconds inside the access point. The other is the dashboard your team opens every day. Dominus provisions the fleet, defines the policy together with your team and runs the platform day to day.
Inspects and decides at the edge
Application that runs in the kernel of the access point itself. Brazilian technology, born at LabLua at PUC-Rio and selected in 2024 for OpenRAN@Brasil, coordinated by RNP and CPQD.
- Reads DNS, TLS/SNI and HTTP metadata
- Does not decrypt session content
- Drops traffic before it uses the link
- Blocks encrypted DNS and bypass VPNs
Provisions, shows and proves
Cloud platform that controls the whole fleet.
- Policy per customer, SSID or AP group
- Role-based portals, no shared credentials
- Bulk provisioning, RRM and self-healing
- REST API and webhooks, IPv4 and IPv6
Secure Wireless Gateway screens
Screenshots of the NetExperience dashboard in the Dominus Cyber lab, with two EAP101 access points.
IP and MAC addresses and user data have been hidden.
Six practical effects of deciding at the edge
They all come from the same architecture choice: processing on the access point instead of sending traffic somewhere else.
No separate appliance
No need for a web filter or a dedicated appliance. The function comes inside the access point, on the same device that serves the Wi-Fi.
Privacy preserved
The analysis uses metadata. No user session is decrypted to make the decision.
Link savings
Trackers, ads and unwanted traffic are stopped before they cross the backhaul and the uplink.
Open standard
Runs on the open TIP OpenWiFi standard. The hardware is not proprietary, so your operation is not tied to a single vendor.
Licensing per AP
Cost per access point, with a density tier defined during sizing. The calculation does not depend on the company's headcount.
Centralized management
One dashboard for the whole fleet: policy, AP status and what was blocked, without opening one screen per site.
Specifications for the current version
Numbers and limits of the current product version. Cases outside this range go through engineering validation.
| Inspected protocols | DNS, TLS/SNI and HTTP |
| Analysis method | Connection metadata. No deep packet inspection and no breaking of encryption. |
| Where it runs | In-kernel application on the access point itself, at the access layer. |
| Policy rules | By category, by service or by protocol, with lists updated continuously. |
| Network segmentation | VLAN assigned dynamically through 802.1X or by individual password (MPSK). |
| Bypass | Blocking of encrypted DNS and bypass VPNs, according to NetExperience documentation. |
| Activity report | Optional per profile. When off, blocking continues and browsing is not logged. |
| Licensing | Per access point, with the license activated in the dashboard and a density tier defined during sizing. |
| Hardware standard | TIP OpenWiFi. |
| Certified hardware | Edgecore EAP101, EAP102 and EAP105 (indoor, Wi-Fi 6 and Wi-Fi 7) and OAP101 (outdoor), supplied by Padtec. The list grows as new models pass certification. See the equipment |
| Planned for 2027 | Switches and a gateway with the Secure Wireless Gateway, managed in the same dashboard. |
| Management | Single dashboard for policy, monitoring and blocking events. |
What the gateway does not do
If your case falls into one of these points, let's talk before moving on.
It does not decrypt traffic
The decision uses metadata. The content of HTTPS sessions stays closed, including to the network operator. The destination shows up in the activity report, if it is turned on.
It does not replace a firewall or EDR
It works at the Wi-Fi access layer. Whatever protects the core, the perimeter and the endpoint is still needed.
It does not inspect payloads
If the requirement is to analyze packet content, this gateway alone does not meet it and the design needs another layer.
It does not see inside a VPN tunnel
The bypass VPN service can be blocked. What travels inside an authorized tunnel is outside the reach of inspection.
The two questions that come next
One answers whether it fits your scenario. The other compares it with what you already use.
Segments served
What changes for regional ISPs, MVNOs, public hotspots and corporate networks. The same technology, four different problems.
See the four scenarios →Side-by-side comparison
SWG on the access point against a DNS filter and a UTM appliance, line by line, including where the DNS filter does just as well.
See the table →Want to see this on your network?
We size how many points your scenario needs and show what would be blocked at the edge. No commitment.
The browsing filter that runs inside the access point.
The Secure Wireless Gateway is an application that runs in the access point kernel, the core of the device's system, and inspects DNS, TLS/SNI and HTTP on the AP itself. The decision to allow or drop happens before traffic leaves the local network, with no dedicated appliance and without breaking the user's encryption.
In May 2026, Padtec, a Brazilian manufacturer listed on B3, announced this technology for its line of Wi-Fi 6 and Wi-Fi 7 enterprise access points, in partnership with Dominus Cyber. The certified models today are the Edgecore EAP101, EAP102, EAP105 and OAP101.
Read the official announcement ↗How a request is evaluated
The request is evaluated in sequence inside the access point. If nothing matches the lists, it goes through. If it matches, it is dropped right there, without using link bandwidth.
The name is resolved
The DNS query is read on the AP itself and compared with the active lists before it goes out to the resolver.
SNI reveals the destination
In HTTPS sessions, the SNI field of the TLS handshake shows where the connection is going without decrypting anything.
Allow or drop
With no match, traffic flows normally. With a match, it is dropped at the edge and does not use the link.
Two layers, one operation
One decides in milliseconds inside the access point. The other is the dashboard your team opens every day. Dominus provisions the fleet, defines the policy together with your team and runs the platform day to day.
Inspects and decides at the edge
Application that runs in the kernel of the access point itself. Brazilian technology, born at LabLua at PUC-Rio and selected in 2024 for OpenRAN@Brasil, coordinated by RNP and CPQD.
- Reads DNS, TLS/SNI and HTTP metadata
- Does not decrypt session content
- Drops traffic before it uses the link
- Blocks encrypted DNS and bypass VPNs
Provisions, shows and proves
Cloud platform that controls the whole fleet.
- Policy per customer, SSID or AP group
- Role-based portals, no shared credentials
- Bulk provisioning, RRM and self-healing
- REST API and webhooks, IPv4 and IPv6
Secure Wireless Gateway screens
Screenshots of the NetExperience dashboard in the Dominus Cyber lab, with two EAP101 access points.
IP and MAC addresses and user data have been hidden.
Six practical effects of deciding at the edge
They all come from the same architecture choice: processing on the access point instead of sending traffic somewhere else.
No separate appliance
No need for a web filter or a dedicated appliance. The function comes inside the access point, on the same device that serves the Wi-Fi.
Privacy preserved
The analysis uses metadata. No user session is decrypted to make the decision.
Link savings
Trackers, ads and unwanted traffic are stopped before they cross the backhaul and the uplink.
Open standard
Runs on the open TIP OpenWiFi standard. The hardware is not proprietary, so your operation is not tied to a single vendor.
Licensing per AP
Cost per access point, with a density tier defined during sizing. The calculation does not depend on the company's headcount.
Centralized management
One dashboard for the whole fleet: policy, AP status and what was blocked, without opening one screen per site.
Specifications for the current version
Numbers and limits of the current product version. Cases outside this range go through engineering validation.
| Inspected protocols | DNS, TLS/SNI and HTTP |
| Analysis method | Connection metadata. No deep packet inspection and no breaking of encryption. |
| Where it runs | In-kernel application on the access point itself, at the access layer. |
| Policy rules | By category, by service or by protocol, with lists updated continuously. |
| Network segmentation | VLAN assigned dynamically through 802.1X or by individual password (MPSK). |
| Bypass | Blocking of encrypted DNS and bypass VPNs, according to NetExperience documentation. |
| Activity report | Optional per profile. When off, blocking continues and browsing is not logged. |
| Licensing | Per access point, with the license activated in the dashboard and a density tier defined during sizing. |
| Hardware standard | TIP OpenWiFi. |
| Certified hardware | Edgecore EAP101, EAP102 and EAP105 (indoor, Wi-Fi 6 and Wi-Fi 7) and OAP101 (outdoor), supplied by Padtec. The list grows as new models pass certification. See the equipment |
| Planned for 2027 | Switches and a gateway with the Secure Wireless Gateway, managed in the same dashboard. |
| Management | Single dashboard for policy, monitoring and blocking events. |
What the gateway does not do
If your case falls into one of these points, let's talk before moving on.
It does not decrypt traffic
The decision uses metadata. The content of HTTPS sessions stays closed, including to the network operator. The destination shows up in the activity report, if it is turned on.
It does not replace a firewall or EDR
It works at the Wi-Fi access layer. Whatever protects the core, the perimeter and the endpoint is still needed.
It does not inspect payloads
If the requirement is to analyze packet content, this gateway alone does not meet it and the design needs another layer.
It does not see inside a VPN tunnel
The bypass VPN service can be blocked. What travels inside an authorized tunnel is outside the reach of inspection.
The two questions that come next
One answers whether it fits your scenario. The other compares it with what you already use.
Segments served
What changes for regional ISPs, MVNOs, public hotspots and corporate networks. The same technology, four different problems.
See the four scenarios →Side-by-side comparison
SWG on the access point against a DNS filter and a UTM appliance, line by line, including where the DNS filter does just as well.
See the table →Want to see this on your network?
We size how many points your scenario needs and show what would be blocked at the edge. No commitment.