Cloud AAA control plane

Secure every access request.
Manage every policy decision.

Bring identities, devices, and access rules into one operating view. SpherAAA helps network teams make consistent, auditable decisions across enterprise, ISP and service-provider environments.

Cloud + On-Prem Enterprise Security Developer Ready

Built on a policy engine proven in carrier-grade 4G authentication infrastructure since 2016.

99.98% Auth success rate
89ms Avg policy decision
12.4k Active sessions
Authentications, last 12h
RADSEC
62%
802.1x
31%
RADIUS
7%

24/7

Expert Support

5 Min

Deployment

$0

Setup Cost

Works across your existing network stack
Cisco MikroTik Ubiquiti pfSense Enterprise WLAN

For MSPs

Isolate every client environment on one platform. One dashboard, per-tenant policy and billing data, zero cross-account leakage.

For ISPs

Handle high-volume subscriber authentication with RADSEC and dynamic peer discovery, without standing up your own RADIUS cluster.

For Enterprise IT

Centralize workforce, guest, and device authentication; apply access policies across wired and wireless networks; connect identity and business systems; and choose cloud or self-hosted operations.

Platform capabilities

Everything needed to run modern AAA at scale

From protocol handling to identity-driven automation, SpherAAA brings security, flexibility, and observability into one platform.

Protocols & Security

Advanced Protocol Coverage

RADSEC, UDP/TCP, and 802.1x with EAP-TLS support including TLS 1.3, plus TTLS/PEAP/AKA and dynamic peer discovery, so you're not stuck re-architecting when a new device type shows up.

RADIUS Proxy Fabric

Proxy, route, and chain requests across distributed AAA endpoints with centralized policy logic.

Integrated PKI

Issue and manage EAP certificates with built-in SCEP/OCSP capabilities, no separate CA to run.

Policy & Automation

Integrate With Anything

Built-in Entra ID support out of the box, plus a scriptable HTTP client to call any identity provider, CRM, or internal API during policy evaluation. Not locked to one vendor's connector list.

REST API Integrations

Connect CRM, billing, portals, and service systems through modern JSON endpoints.

Operations & Visibility

Multi-Tenant Isolation

Run many customer environments from one platform while keeping data, flows, and credentials separated, built for MSPs managing multiple clients.

OpenSearch Analytics

Investigate auth/accounting events and trends with deep dashboard visibility. Find the failing device in seconds, not by grepping logs.

Dev Sandbox

Validate policy changes in isolated QA, TEST, and STAGE environments using built-in 802.1X test clients before deploying to production.

About SpherAAA

Telecom-grade foundation.
Cloud-native execution.

SpherAAA started in 2016 as part of a 4G core architecture. It supports Diameter and Radius interfaces and is built to run both on-prem and in cloud SaaS deployments.

Designed by senior telecom engineers to keep pace with strict security requirements and fast-changing business rules. The same authentication core that handled carrier-scale 4G subscriber traffic now runs your RADIUS and 802.1x policy, hardened by a decade in production before it ever reached a web dashboard.

Since 2016

Production-focused AAA engineering.

Cloud + On-Prem

Choose deployment by compliance needs.

One policy layer. Every deployment. Operational
Carrier core Production-grade identity signals
PolicyLogic Rules that adapt to your business
Secure access RADIUS, RADSEC, and 802.1x

Built to carry telecom discipline into the everyday work of network and security teams.

Pricing

Start free. Stay free.

Everything you need to validate SpherAAA on a single site, on us.

"Devices" = unique client MAC addresses (laptops, phones, IoT sensors, etc.) authenticating via your NAS each billing month.

Cloud deployment
Cloud AAA (Managed)
$0/mo
  • Free forever
  • Restricted to 50 unique devices
  • Every feature included
  • Ticketing support
Get started free
No credit card required
Or deploy on your own infrastructure
On-premise deployment
On-Premise (Self-Hosted)
Plan-based pricing
  • Runs on your own site, on your hardware and network
  • Full data sovereignty, nothing leaves your premises
  • Multi-tenant isolation for MSPs
  • Tailored licensing and SLA support
Get Started
Installed and run at your site
FAQ

Answers before you deploy

The most common questions we receive from engineering and operations teams.

SpherAAA is built in Java, independent from open-source RADIUS forks, and uses MongoDB for backend storage.
JavaScript enables fast policy iteration and simpler onboarding for developers integrating external systems and identity rules.
RADSEC is RADIUS over TLS, encrypting traffic in transit and improving trust and transport security.
Starter and Business are billed monthly or annually with no long-term commitment, cancel anytime from the portal.
EAP-TLS, including TLS 1.3, EAP-TTLS, EAP-PEAP, and EAP-AKA Identity are supported for secure enterprise access scenarios.
Yes. We provide standalone and on-premise deployment models for organizations with strict governance requirements.
Yes. SpherAAA includes Swagger UI to accelerate API development and integration testing.
Most teams point one NAS at SpherAAA in a QA environment, validate the policy logic against real traffic, then cut over site by site. On-prem and cloud deployment options let you migrate at your own pace.
Contact

Let's design your AAA architecture together

Tell us your environment details and we'll propose the right deployment model, policy strategy, and rollout plan.

Email

info@spheralogic.net

Response Time

Typically within 1 business day

Send us a message

Share a few details and we'll get back with the right next step.

CAPTCHA Image

Ready to stop managing RADIUS by hand?

Spin up a free environment in minutes, no credit card or sales call required.