Multi-tenant network configuration management

Prevent outages. Pass audits. With the team you already have.

Cypress NCM replaces manual, error-prone config work with automated guardrails—so a bad change never turns into downtime, every device stays audit-ready, and one team can manage thousands across every site.

Deploys in an afternoon— no inbound firewall changes,  no security-review headache.
One platform for the multi-vendor network you already run
Cisco IOS / IOS-XE Dell OS6 / OS10 Palo Alto Fortinet pfSense Plus
Why teams choose Cypress NCM

Less risk, less manual work, more control

Every capability ladders up to the same outcomes: fewer outages, easier audits, and a network one team can run as it grows.

Recover from a bad change in seconds

Every device is backed up continuously with full history. When a change breaks something, roll back to a known-good config in one click—minutes of downtime instead of hours.

Stay audit-ready, year-round

Continuous compliance checks mapped to NIST, CIS, and DISA STIG turn audit prep from a fire drill into a report you export on demand—and you're alerted the moment a device drifts out of policy.

Roll out new sites without the rework

Standardize on known-good templates and provision devices in bulk, so every location comes up consistent and correct—no copy-paste, no one-off mistakes to chase down later.

Patch with confidence, not crossed fingers

Run guided, verified firmware upgrades across your fleet, with safeguards that keep a flash from stranding a device—so you close vulnerabilities on schedule instead of dreading the maintenance window.

Delegate work without handing over the keys

Let operators run pre-approved tasks instead of raw CLI, and give support browser-based device access—every action scoped to their role, audited, and replayable. Less risk, fewer escalations.

Answer “what changed?” in seconds

A live operations view, searchable logs, and a complete audit trail mean you find the cause of an issue in minutes, not hours—and always know exactly who changed what, and when.

Catch problems before your users do

Daily digests of failed backups and offline devices, plus a weekly activity summary, reach the right inboxes—so small issues get fixed quietly instead of becoming tickets and outages.

Grow sites and customers, not headcount

Run every location—or every customer—from one console, with strict data isolation, your own SSO, and role-based access. Add the next site or tenant without adding the next hire.

Set it up once—it stays current

A single agent per site updates itself automatically and safely, with no manual rollouts to schedule. Your team ships value instead of babysitting infrastructure.

How it works

Live in an afternoon—no security review required

Cypress NCM never dials into your network. A lightweight agent reaches out to the cloud, so there's nothing inbound to expose and nothing to slow down approval.

1

Deploy an agent

Drop a single self-updating binary inside each site. It connects outbound to the cloud over mTLS on port 443—no inbound rules, no VPN, no jump host.

2

Reach your devices

The agent talks to your switches, routers, and firewalls over SSH and REST to back up configs, scan for compliance, provision, and run commands on your behalf.

3

Manage from one console

Your team works in a single multi-tenant web app—backups, compliance, terminals, and reports—with role-based access and a full audit trail.

Outbound-only by default. Agents initiate every connection, verify the cloud's certificate, and self-update with checksum-verified binaries. Device credentials are encrypted at rest and never leave your control.
Security & isolation

Built for teams that can't afford surprises

Every layer—from tenant data to device credentials to the agent link—is isolated and auditable by default.

  • Customer data stays separate—guaranteedTenant isolation is enforced at the database, not just in app code, so you can serve many customers with confidence.
  • Onboard and offboard in minutesBring your own SSO/SAML and assign least-privilege roles scoped to device groups—access follows your directory, not a spreadsheet.
  • Shrink your breach blast radiusDevice secrets are encrypted at rest and agents authenticate with mutual TLS—credentials never sit in plaintext or travel unverified.
  • Walk into any audit with the evidence readyEvery config change, command, and admin action is recorded—who, what, when—and exportable on demand.

See what fewer outages and effortless audits look like

In a 30-minute walkthrough tailored to your environment, we'll show you the time, risk, and headcount Cypress NCM takes off your plate.