The SD-WAN built for the AI era.
Is your network agent‑ready?
Multi-WAN load balancing, encrypted branch-to-branch mesh, and AI governance — enforced at the edge, orchestrated from one portal. Bond any ISPs, govern any frontier AI models or local LLMs.
280 + 140 + 90 + 120 = 630 Mbps
All four links carry traffic at the same time.
New York ↔ Austin: direct tunnel carrying traffic.
o4-mini denied. Model not allowed by the eng-readonly policy.
One box per branch.
Every branch from one dashboard.
Caged ships a real SD-WAN router at every site. Multi-WAN by default. Mesh that builds itself between branches. FEC-bonded paths for the flows that can't lose a packet. Firewall, NAT, DHCP, SNMP — every config object pushed from the Portal, no CLI required.
- → multi-WAN with self-forming branch-to-branch mesh and seamless failover
- → FEC-bonded WAN paths — turn lossy links into reliable, performance-tier bandwidth
- → firewall, NAT, DHCP, SNMP, routing — all GUI-driven, all version-controlled, all fleet-pushed
- → zero-touch provisioning and self-serve licensing — sites online in minutes, without an on-site engineer
New York ↔ Austin: direct tunnel carrying traffic.
Traffic is striped across fiber, cable, and LTE.
3 paths · 7% average raw loss · 12 ms jitter · 0% effective loss in this example
Validate the versioned settings before pushing to the fleet.
1,284 sites · 4 shown · snapshot, rollback, and retry queue on failure
AI traffic, governed at the edge.
One gateway for every model your teams use — frontier-cloud or local. Same policy whether the caller is a person, an app, or an agent. Configure once and your sensitive data never leaves the branch: route the call to a local LLM, or redact PII on-the-fly before the request hits the cloud. Per-key policy, per-call audit, no provider lock-in.
- → any frontier LLM (OpenAI, Anthropic, …) and any local model — same virtual keys, same policy plane
- → per-key controls — model allow-lists, usage budgets, endpoint blocks, privacy rules
- → no provider lock-in — mix providers or migrate freely; the gateway abstracts the choice
- → PII never leaves the branch — route to a local model, or scrub sensitive fields on-device before egress; per-policy choice
Policy saved and pushed. 14 branches synced, 12 virtual keys updated.
14 branches · 4 shown · snapshot, rollback, diff · failed delivery enters the retry queue
o4-mini denied. Model not allowed by the eng-readonly policy.
Tenant-scoped · no plaintext keys · 365-day retention
Clean and scrubbed requests reach the cloud. Sensitive data stays with the local model.
claims-team · caged_sk_…f30a · policy chooses per call
multi-wan load balancer
Bond wired or wireless WAN internet connections into one resilient uplink. Each WAN is monitored and dynamically weighted for load balancing, with per-rule traffic routing plus advanced firewalling.
↗encrypted branch mesh
Full-mesh overlay control plane. On-demand spoke-to-spoke tunnels created when traffic between branches is detected, torn down when idle. Dynamic weights across multiple paths.
↗ai api gateway
OpenAI and Anthropic out of the box. Local LLM endpoints on the same policy plane. Create and manage AI API proxy endpoints on devices you own and control, with traffic governance and optional PII firewalling.
↗centralized portal
Device inventory, zero-touch config, bulk config push with retry queue and DLQ, firmware batch upgrades with validate/execute gates, snapshot and rollback. Self-serve licensing. Single dashboard for all.
↗
Run a pilot at
one branch.
Drop a Caged AI box at a single site. Bring your existing WAN links. Bring your existing AI providers. Replace it inside a month — or keep going.