Stop hand-editing NAS configs and vendor RADIUS dictionaries. Write your access policy once in PolicyLogic, and SpherAAA enforces it across all RADIUS and RADSEC - on cloud or on-prem.
Built on a policy engine proven in carrier-grade 4G authentication infrastructure since 2016.
Expert Support
Deployment
Setup Cost
Isolate every client environment on one platform. One dashboard, per-tenant policy and billing data, zero cross-account leakage.
Handle high-volume subscriber authentication with RADSEC and dynamic peer discovery, without standing up your own RADIUS cluster.
Enforce 802.1x and MFA policy tied to Entra ID, with an audit trail your security team can actually query in OpenSearch.
From protocol handling to identity-driven automation, SpherAAA brings security, flexibility, and observability into one platform.
RADSEC, UDP/TCP, and 802.1x (EAP-TLS/TTLS/PEAP/AKA) with dynamic peer discovery - so you're not stuck re-architecting when a new device type shows up.
Proxy, route, and chain requests across distributed AAA endpoints with centralized policy logic.
Issue and manage EAP certificates with built-in SCEP/OCSP capabilities - no separate CA to run.
Program authentication and accounting workflows in PolicyLogic - change access rules the way you ship code, not the way you file a change request.
Read Policy DocsBuilt-in Entra ID support out of the box - and a scriptable HTTP client to call any identity provider, CRM, or internal API during policy evaluation. Not locked to one vendor's connector list.
Connect CRM, billing, portals, and service systems through modern JSON endpoints.
Run many customer environments from one platform while keeping data, flows, and credentials separated - built for MSPs managing multiple clients.
Investigate auth/accounting events and trends with deep dashboard visibility - find the failing device in seconds, not by grepping logs.
Test policy changes in isolated QA, TEST, and STAGE environments before they touch PROD traffic.
SpherAAA started in 2016 as part of a 4G core architecture. It supports Diameter and Radius interfaces and is built to run both on-prem and in cloud SaaS deployments.
Designed by senior telecom engineers to keep pace with strict security requirements and fast-changing business rules. The same authentication core that handled carrier-scale 4G subscriber traffic now runs your RADIUS and 802.1x policy - hardened by a decade in production before it ever reached a web dashboard.
Production-focused AAA engineering.
Choose deployment by compliance needs.
Everything you need to validate SpherAAA on a single site, on us.
"Devices" = unique client MAC addresses (laptops, phones, IoT sensors, etc.) authenticating via your NAS each billing month.
Multi-tenant isolation for MSPs, dedicated infrastructure, and tailored licensing for enterprise scale and compliance requirements.
Talk to SalesThe most common questions we receive from engineering and operations teams.
Tell us your environment details and we'll propose the right deployment model, policy strategy, and rollout plan.
info@spheralogic.net
Typically within 1 business day
Share a few details and we'll get back with the right next step.
Spin up a free environment in minutes - no credit card, no sales call required to get started.