ewusOS: the gateway operating system that runs on every EWUS gateway.
One core. Five segments.
Three sizes of hardware.
What changes between gateways is which module is licensed on top, and which hardware tier it runs on.
Architecture
One core, on the box, under every segment.
Traffic arrives, passes through the gateway, and is decided there. The Base-20 is on every gateway whatever the licence. What changes between segments is the one module that sits on top.
Both address families, equally. Anything that works for IPv4 works identically for IPv6, filtering, accounting and bypass detection included. That is a property of the core, not a feature of one module, which is why it sits here and not in the Base-20 list.
Every gateway, talking to one cloud, live.
Box 1
Box 2
Box 2
Box 3
ISP & Telco · Box 3
Same ewusOS everywhere. Only the segment, and hardware tier, change.
Enforcement happens on the device, not in the cloud.
What cloud-DNS filtering can't do
It sees one router IP, not one person. It can only allow or block a domain, never guarantee bandwidth for an exam or a call.
What ewusOS does instead
Runs on the gateway, sees every packet. Filtering and bandwidth apply per device, enforced locally, working even offline.
Where the decision happens
Five other places this job gets done.
No product names and no scores. Each row is what follows from where a thing runs: a resolver that answers domain lookups cannot reserve bandwidth, and software installed on a phone cannot protect a camera. Position decides capability.
| Approach | Decides | Can see | Cannot do from there |
|---|---|---|---|
| Consumer router firmware | On the box | Addresses on the local network | Tell one person from another. Every device looks like a lease. |
| Cloud-managed gateway | In the cloud | Whatever the box reports upward | Decide anything while the link to the cloud is down. |
| DNS-only filtering | At the resolver | One address for the whole building, and only domain lookups | Reserve bandwidth, act per person, or see traffic that is not a lookup. |
| Security software on each device | On the device it is installed on | That one device | Cover a camera, a printer, a TV or a card terminal, none of which can run it. |
| ISP subscriber management | In the provider core | Up to the subscriber line | See past the subscriber's own router, where most complaints begin. |
| ewusOS | On the gateway | Every packet, per person and per device | Enforce locally, and keep enforcing when the cloud is unreachable. |
Each of these is good at the job its position suits. A resolver is the cheapest way to block a known bad domain everywhere at once. Software on a laptop is the only thing that can see inside that laptop. The gateway is simply the one place that sees the line, the devices behind it, and the people using them at the same time.
The Base-20: twenty core features, on every box, every licence
Routing at full speed
Hardware-accelerated NAT so filtering never becomes the bottleneck.
Modern connectivity
Current Wi-Fi standards, or a purpose-built wired gateway.
Dual-WAN failover
A second line is designed to take over automatically. Not yet available on shipping hardware.
Monetisation infrastructure blocked
Known scam and fraud infrastructure blocked at the network level. Coverage grows with every feed update.
Real per-device identity
Every device is named, owned and tracked.
Schedules that hold
Bedtime or study hours enforced at the network, not an app.
Bufferbloat-free QoS
Calls and games stay smooth even when the connection is busy.
Unknown-device alerts
A new device joins, you know immediately, with a one-tap removal.
Show all twenty
Network 5
- 01Routing and NAT with hardware offload
- 02Wi-Fi 6 with WPA3 on Box 1; a wired gateway on Box 2 and 3
- 04VLANs with an isolated guest network
- 13One-click quality of service, including bufferbloat control
- 16WireGuard VPN server for remote access (in development)
Security 4
- 05Name-lookup protection: malware, phishing and scam destinations
- 06Adult-content filter, applied at the line
- 07Safe Search enforcement
- 15Unknown-device alert with one-tap quarantine
Identity 3
- 08Per-device identity: name, owner and history
- 09People and their devices told apart, rather than every address treated as a person
- 10Identity that survives randomised hardware addresses
Control 2
- 11Schedule rules: bedtime, study, or your own windows
- 12One-tap pause, per device, per person, or the whole line
Management 3
- 14Usage analytics per device, per category, per time
- 17Three ways to configure it: mobile app, web interface and command line
- 20Cloud dashboard, with full local control if the cloud is unreachable
Resilience 3
- 03Dual-WAN failover, second line on any port or a USB mobile connection
- 18Over-the-air updates, dual-image with automatic rollback
- 19Self-healing fail-open, with a hardware watchdog
Five segments. Each one is the Base-20, plus what its world needs.
Home: EWUS HomeShield
Age-appropriate profiles, in development. Priority for calls and schoolwork over background streaming. A weekly summary in plain language, and a scam shield for elders. The three tiers, in full →
Property: EWUS AnyB
Every resident connects with their own identity. Per-resident plans approved with one tap on WhatsApp. Bulk onboarding for move-in day.
Campus: EWUS AnyB for coaching & institutes
Class-time rules that match reality. Faculty, students and visitors each get access built for their role. Guaranteed bandwidth during exams.
Business: EWUS Secure
Intrusion detection that updates itself. Two internet lines run active-active. Management kept off the guest network.
Provider: EWUS Network
Subscriber authentication and accounting that drops into existing billing systems. Per-subscriber shaping.
Three tiers. One OS underneath, always.
One codebase across every hardware tier. Modules are activated by licence, not by shipping a separate forked build.
The home gateway
A compact Wi-Fi router built for a household, the HomeShield hardware.
The property gateway
A wired gateway for PGs, hostels and campuses, with Box 1 units as access points.
The business & ISP gateway
Higher-capacity hardware for businesses and small ISPs, same OS.
Now pick the world it runs in.
The core is the same everywhere. What changes is the one module on top, and the box underneath. Tell us which of the five you are, and we will show you that combination.
EWUS Technologies builds intelligent network gateways, and ewusOS, the gateway operating system that runs on all of them. About EWUS