CORE

ewusOS: the gateway operating system that runs on every EWUS gateway.

One core. Five segments.
Three sizes of hardware.

What changes between gateways is which module is licensed on top, and which hardware tier it runs on.

Architecture

One core, on the box, under every segment.

Traffic arrives, passes through the gateway, and is decided there. The Base-20 is on every gateway whatever the licence. What changes between segments is the one module that sits on top.

How ewusOS fits togetherTraffic arrives from the internet. It passes through an EWUS gateway, available as Box 1, Box 2 or Box 3. Running on that gateway is ewusOS, which provides the Base-20: network, security, identity, control, management and resilience. On top of ewusOS sits one licensed module: HomeShield, AnyB, Secure or EWUS Network. Everything shown inside the gateway runs on the gateway itself. Below it are the people, devices and subscribers it serves.The internet, and your upstream lineTHE EWUS GATEWAYBox 1, Box 2 or Box 3ewusOSTHE BASE-20, ON EVERY GATEWAY AND EVERY LICENCENetworkSecurityIdentityControlManagementResilienceONE LICENSED MODULE ON TOPHomeShieldAnyBSecureEWUS NetworkEverything above runs on the gateway itself, not in a cloud.The people, devices and subscribers it serves

Both address families, equally. Anything that works for IPv4 works identically for IPv6, filtering, accounting and bypass detection included. That is a property of the core, not a feature of one module, which is why it sits here and not in the Base-20 list.

How it connects

Every gateway, talking to one cloud, live.

EWUS Cloud resolved config · policy · telemetry
ACTIVE 00:00:00 Home
Box 1
ACTIVE 00:00:00 Property
Box 2
ACTIVE 00:00:00 Campus
Box 2
ACTIVE 00:00:00 Business
Box 3
ACTIVE 00:00:00 Provider
ISP & Telco · Box 3

Same ewusOS everywhere. Only the segment, and hardware tier, change.

The core idea

Enforcement happens on the device, not in the cloud.

What cloud-DNS filtering can't do

It sees one router IP, not one person. It can only allow or block a domain, never guarantee bandwidth for an exam or a call.

What ewusOS does instead

Runs on the gateway, sees every packet. Filtering and bandwidth apply per device, enforced locally, working even offline.

Where the decision happens

Five other places this job gets done.

No product names and no scores. Each row is what follows from where a thing runs: a resolver that answers domain lookups cannot reserve bandwidth, and software installed on a phone cannot protect a camera. Position decides capability.

Comparison of five common approaches and ewusOS by where enforcement happens, what each can see, and what its position prevents it from doing.
ApproachDecidesCan seeCannot do from there
Consumer router firmwareOn the boxAddresses on the local networkTell one person from another. Every device looks like a lease.
Cloud-managed gatewayIn the cloudWhatever the box reports upwardDecide anything while the link to the cloud is down.
DNS-only filteringAt the resolverOne address for the whole building, and only domain lookupsReserve bandwidth, act per person, or see traffic that is not a lookup.
Security software on each deviceOn the device it is installed onThat one deviceCover a camera, a printer, a TV or a card terminal, none of which can run it.
ISP subscriber managementIn the provider coreUp to the subscriber lineSee past the subscriber's own router, where most complaints begin.
ewusOSOn the gatewayEvery packet, per person and per deviceEnforce locally, and keep enforcing when the cloud is unreachable.

Each of these is good at the job its position suits. A resolver is the cheapest way to block a known bad domain everywhere at once. Software on a laptop is the only thing that can see inside that laptop. The gateway is simply the one place that sees the line, the devices behind it, and the people using them at the same time.

The foundation

The Base-20: twenty core features, on every box, every licence

Base

Routing at full speed

Hardware-accelerated NAT so filtering never becomes the bottleneck.

Base

Modern connectivity

Current Wi-Fi standards, or a purpose-built wired gateway.

In development

Dual-WAN failover

A second line is designed to take over automatically. Not yet available on shipping hardware.

Base

Monetisation infrastructure blocked

Known scam and fraud infrastructure blocked at the network level. Coverage grows with every feed update.

Base

Real per-device identity

Every device is named, owned and tracked.

Base

Schedules that hold

Bedtime or study hours enforced at the network, not an app.

Base

Bufferbloat-free QoS

Calls and games stay smooth even when the connection is busy.

Base

Unknown-device alerts

A new device joins, you know immediately, with a one-tap removal.

Show all twenty

Network 5

  • 01Routing and NAT with hardware offload
  • 02Wi-Fi 6 with WPA3 on Box 1; a wired gateway on Box 2 and 3
  • 04VLANs with an isolated guest network
  • 13One-click quality of service, including bufferbloat control
  • 16WireGuard VPN server for remote access (in development)

Security 4

  • 05Name-lookup protection: malware, phishing and scam destinations
  • 06Adult-content filter, applied at the line
  • 07Safe Search enforcement
  • 15Unknown-device alert with one-tap quarantine

Identity 3

  • 08Per-device identity: name, owner and history
  • 09People and their devices told apart, rather than every address treated as a person
  • 10Identity that survives randomised hardware addresses

Control 2

  • 11Schedule rules: bedtime, study, or your own windows
  • 12One-tap pause, per device, per person, or the whole line

Management 3

  • 14Usage analytics per device, per category, per time
  • 17Three ways to configure it: mobile app, web interface and command line
  • 20Cloud dashboard, with full local control if the cloud is unreachable

Resilience 3

  • 03Dual-WAN failover, second line on any port or a USB mobile connection
  • 18Over-the-air updates, dual-image with automatic rollback
  • 19Self-healing fail-open, with a hardware watchdog
Licensed modules

Five segments. Each one is the Base-20, plus what its world needs.

Home: EWUS HomeShield

Age-appropriate profiles, in development. Priority for calls and schoolwork over background streaming. A weekly summary in plain language, and a scam shield for elders. The three tiers, in full →

Property: EWUS AnyB

Every resident connects with their own identity. Per-resident plans approved with one tap on WhatsApp. Bulk onboarding for move-in day.

Campus: EWUS AnyB for coaching & institutes

Class-time rules that match reality. Faculty, students and visitors each get access built for their role. Guaranteed bandwidth during exams.

Business: EWUS Secure

Intrusion detection that updates itself. Two internet lines run active-active. Management kept off the guest network.

Provider: EWUS Network

Subscriber authentication and accounting that drops into existing billing systems. Per-subscriber shaping.

Hardware

Three tiers. One OS underneath, always.

One codebase across every hardware tier. Modules are activated by licence, not by shipping a separate forked build.

Box 1

The home gateway

A compact Wi-Fi router built for a household, the HomeShield hardware.

Wi-Fi 6WPA3Hardware routing
Box 2

The property gateway

A wired gateway for PGs, hostels and campuses, with Box 1 units as access points.

Multi-APCaptive portalSite dashboard
Box 3

The business & ISP gateway

Higher-capacity hardware for businesses and small ISPs, same OS.

Dual-WANSubscriber-scaleSite-to-site VPN

Now pick the world it runs in.

The core is the same everywhere. What changes is the one module on top, and the box underneath. Tell us which of the five you are, and we will show you that combination.

Join the waiting list

EWUS Technologies builds intelligent network gateways, and ewusOS, the gateway operating system that runs on all of them. About EWUS