The SD-WAN built for the AI era.

Is your network agent‑ready?

Multi-WAN load balancing, encrypted branch-to-branch mesh, and AI governance — enforced at the edge, orchestrated from one portal. Bond any ISPs, govern any frontier AI models or local LLMs.

Four links. Combined capacity.Illustrated example
BRANCHbranch-nyc4 WAN links up
eth0 · fiber280 Mbps
eth1 · cable140 Mbps
eth2 · LTE90 Mbps
eth3 · 5G120 Mbps
BONDED LINK630Mbps combined
Uplink → ← Downlink

280 + 140 + 90 + 120 = 630 Mbps
All four links carry traffic at the same time.

Auto tour · 21 seconds per tab
01
multi_wan
failover, sticky sessions, conntrack helpers
02
branch_mesh
encrypted overlay, on-demand spoke-to-spoke
03
ai_gateway
virtual keys, per-device encryption, audit
04
central_portal
fleet policy, bulk push, firmware batches
ENCRYPTED BRANCH FABRIC

One box per branch.
Every branch from one dashboard.

Caged ships a real SD-WAN router at every site. Multi-WAN by default. Mesh that builds itself between branches. FEC-bonded paths for the flows that can't lose a packet. Firewall, NAT, DHCP, SNMP — every config object pushed from the Portal, no CLI required.

  • → multi-WAN with self-forming branch-to-branch mesh and seamless failover
  • → FEC-bonded WAN paths — turn lossy links into reliable, performance-tier bandwidth
  • → firewall, NAT, DHCP, SNMP, routing — all GUI-driven, all version-controlled, all fleet-pushed
  • → zero-touch provisioning and self-serve licensing — sites online in minutes, without an on-site engineer
Permanent hub links. Direct tunnels when needed.Illustrated example
HQ / CONTROLhq-router
NEW YORKbranch-nyc
AUSTINbranch-aus
LONDONbranch-lon
SAN FRANCISCObranch-sfo
HQ control links Direct branch tunnel

New York ↔ Austin: direct tunnel carrying traffic.

Auto tour · 21 seconds per tab
AI AT THE EDGE

AI traffic, governed at the edge.

One gateway for every model your teams use — frontier-cloud or local. Same policy whether the caller is a person, an app, or an agent. Configure once and your sensitive data never leaves the branch: route the call to a local LLM, or redact PII on-the-fly before the request hits the cloud. Per-key policy, per-call audit, no provider lock-in.

  • → any frontier LLM (OpenAI, Anthropic, …) and any local model — same virtual keys, same policy plane
  • → per-key controls — model allow-lists, usage budgets, endpoint blocks, privacy rules
  • → no provider lock-in — mix providers or migrate freely; the gateway abstracts the choice
  • → PII never leaves the branch — route to a local model, or scrub sensitive fields on-device before egress; per-policy choice
Build the rules. Save and push to branches.Illustrated example
claims-teamSaved & pushed
Allowed modelsclaude-sonnet-4-6 · gpt-4o · gpt-4o-mini
Blocked APIsfine-tuning · embeddings
Monthly budget$2,400 used / $2,500 cap
PrivacyRedact PII before cloud access
Assigned toclaims-team · 12 virtual keys
NEW YORKActive
AUSTINActive
LONDONActive
SAN FRANCISCOActive
Saved policy Active at branch

Policy saved and pushed. 14 branches synced, 12 virtual keys updated.

14 branches · 4 shown · snapshot, rollback, diff · failed delivery enters the retry queue

Auto tour · 21 seconds per tab
// trusted by
ESPN
Marriott
Kaiser Permanente
Lockheed Martin
NASA
Cornell University
NASCAR
U.S. Army
START WITH ONE SITE

Run a pilot at
one branch.

Drop a Caged AI box at a single site. Bring your existing WAN links. Bring your existing AI providers. Replace it inside a month — or keep going.