For Managed Service Providers

Managed MikroTik for every client, from one console

mikroHUB is a hosted, multi-tenant platform built for MSPs running MikroTik across many clients. Each client gets its own isolated organization, enforced by Postgres row-level security — while you monitor, back up and report on every fleet from a single cloud console.

One console, many clients

Every client is a separate organization with hard tenant isolation, scoped roles, and a full audit trail — so you can manage dozens of fleets without leaking data between them.

Deliver the service

Monitoring, LTE intelligence, automated backups, alerts and SLA — the operational toolkit you need to run managed MikroTik as a billable service.

Security you can put in front of a client

Plaintext device passwords never touch our database. Credentials live in an encrypted vault (AES-256-GCM), and in zero-trust agent mode the router pushes metrics outbound over HTTPS — so no stored password is needed to monitor it at all. Every fleet stays isolated in its own organization by row-level security.

Combined with scoped roles, MFA on privileged accounts and a full audit log, this is an architecture you can defend in a security questionnaire — and one you can hand a security-conscious client without caveats.

MSP FAQ

How are my clients isolated from each other?

Each client is a separate organization, and every resource is scoped to an org_id. Postgres row-level security enforces the boundary at the database level, so one client can never see another's devices, backups or data.

Can I give a client read-only access?

Yes. Invite the client into their own organization with the viewer role, which grants read-only visibility into their fleet. Your technicians keep admin or owner rights to operate.

How are device passwords protected?

Plaintext passwords never touch our database; credentials are held in an encrypted vault (AES-256-GCM). With zero-trust agent mode, the router pushes metrics outbound over HTTPS and no device password is stored at all.

Can I reach devices behind CGNAT?

Yes. mikroHUB can establish WireGuard tunnels to reach routers behind CGNAT or without a public IP, and agent mode also works outbound-only — so LTE devices without port forwarding are still fully manageable.

Is there an audit trail?

Yes. Every action is logged with user, device, IP address and timestamp, scoped per organization. It gives you an accountable record for both your team and your clients.

Related

Run managed MikroTik like a platform

Bring your first client's fleet onto mikroHUB in minutes. The free plan covers 3 devices with full multi-tenant isolation, monitoring and backups — no credit card required.