Your internet fails.
Your network doesn't notice.

smart.router turns a MikroTik into a self-healing edge: three lines live at once, failover in seconds, a cloud head-end that can always reach it, and an app that brings you home from anywhere.

console · illustrationsample data
Site A · fiber + Starlinkup
active WANstarlink
rtt via head-end32 ms
Site B · wireless + LTEup
active WANwireless
Site C · cable + Starlinkfailing over
01:13:52 site C: cable down, penalty 120 → switched to starlink
01:13:53 site C: 0 packets lost, phone session kept
01:19:40 site C: cable healthy 6 min → switched back

Three things, one product

Each piece already runs in the field on real ISP customers. smart.router makes them one system anyone can enrol into in five minutes.

01 · ON THE ROUTER

Multi-line failover that grades the line, not the internet

Up to three WAN links active at once. Rules decide which traffic takes which line. Two independent anchors per link, ICMP verdicts only, fast out and slow back, so a flaky line can't flap you.

02 · IN THE CLOUD

A head-end that stays reachable when the ISP isn't

Every router dials out over WireGuard to a head-end outside any carrier's address space. CGNAT, Starlink, LTE: it doesn't matter. Management never dies at the exact moment failover works.

03 · IN YOUR POCKET

VPN back home from anywhere

One tap in the app. Choose split (just your home network) or full tunnel. The phone talks to the cloud, the cloud talks to the house. Nothing is ever exposed inbound.

Enrolment is the only door

No hand-built peers, no drift. The head-end generates the server config, the router script and the phone config from one source of truth.

Claim it in the app

Name the site, type its LAN. You get a one-time claim code.

Paste once into RouterOS 7

One block of script. Keys, tunnel, firewall, reporting. Re-running it is safe.

It appears. It stays.

The site shows up with its active line and round-trip. Add a phone, pick split or full, done.

Built from outages, not slides

The architecture rules are each traceable to a real failure on a real network: outbound-only, tenant isolation by construction, one generator for both sides of every tunnel, endpoints pinned out the real NIC every pass, health from ICMP across the transit, elapsed seconds in every timer.

0.0%packet loss across two live failover switches
5h40mcarried unprompted on Starlink during an ISP outage
32 msaverage Starlink round-trip to the head-end
10kcustomers per head-end in the design envelope
head-end · agg1AWS, outside every ISP site Afiber · starlink · lte site Bbehind CGNAT your phoneanywhere dials outdials outVPN back nothing inbound, ever · per-tenant pools · one generator, both sides

Two customers, one architecture

The head-end is tenant-blind. An ISP enrols the same way a homeowner does. That is the point.

For ISPs and MSPs

Reach every customer router you manage, on whatever path it's using right now. Give customers a Starlink or LTE backup that actually works, without losing your own door in. Failover QA you can prove with numbers, not "it seemed fine".

For homes and small sites

Keep working through the outage. Get home to your cameras, NAS and smart-home from any network, without opening a single port. Switch between "just my house" and "everything through my house" with one toggle.