You are handing us the keys to your plant. Here is what we do with them.
What RadixOLT does with your OLT credentials, how sign-ins and tenancy are enforced, how a change to your network is made and checked, and what leaves the platform. Where something is not built yet, it says so.
Your OLT credentials
The most sensitive thing you give us is a login to the equipment your subscribers depend on. It is treated that way.
Encrypted field by field
OLT logins, SNMP communities, Telegram bot tokens and RADIUS API secrets are encrypted with AES-256-GCM before they reach the database. The key is held in the server’s environment, not in the database beside them.
Never sent back out
No endpoint in the product returns a stored password, community or token. Fetching an OLT returns its username and nothing else, and a secret, once saved, is not shown again, not even to the admin who typed it.
Never written to a log
A Telegram bot token travels in the request address, so when a send fails only the kind of error is logged, never the address. A verification code is logged only on a server with no mail configured, which is a development setup.
Used for one session at a time
RadixOLT opens at most one CLI session per OLT, shared between scheduled sweeps and the interactive terminal. Four concurrent logins once wedged a live chassis for over a minute; one is the rule now.
Accounts and sessions
| What RadixOLT does | |
|---|---|
| Passwords | Hashed with bcrypt. A wrong current password on a change does not sign you out. |
| Access tokens | Short-lived: 15 minutes. They carry the tenant and role every request is checked against. |
| Staying signed in | A refresh token: 256 random bits, stored only as a SHA-256 hash, and replaced on every use. Seven days without use and it lapses. |
| A stolen token | A refresh token presented twice is the signature of a copy, and revokes the whole chain it belongs to. |
| Role changes | A renewed session is rebuilt from the account as it is now, so a demoted or deleted user cannot renew past the change. |
| Two-factor sign-in | Planned, and not available yet. |
Tenancy and roles
Enforced on the server, not by hiding menu items.
Your data is scoped on every request
Each list and detail query takes the ISP from the signed token, never from what the browser sends. Only a Super Admin can cross between ISPs, and only by asking for one explicitly.
Four roles
Super Admin, ISP Admin, Operator and Viewer. The sidebar hides what a role cannot use and the server refuses it independently.
Scoped accounts
An Operator or Viewer can be limited to a list of OLTs, and then sees only those OLTs, their ONUs and their customers.
Where the lines are
Terminal access stops at Operator. Credentials and alert contacts stop at ISP Admin, because a bot token is a secret.
Changes to your network
RadixOLT can reboot, disable, delete and authorize ONUs, edit uplink VLANs and save configurations, depending on the platform. Each of those is built to fail loudly rather than quietly.
It asks first, and says what will happen
Every write is confirmed in a dialog that names the OLT, the port or subscriber, and the consequence, and records what was done as a job you can look up afterwards.
The device decides whether it worked
Writes are read back from the chassis. A command the OLT accepted and ignored is reported as a refusal, and the OLT’s own refusal sentence is shown to you rather than a generic error.
Writes use the CLI unless proven otherwise
A write runs over SSH or Telnet unless an SNMP form has been verified on that platform for that one command. Opening SNMP for a reboot does not open it for a delete.
The terminal has a stop sign
Commands that can drop a subscriber need a second, explicit confirmation naming the OLT and its address. A terminal session itself is not recorded yet, and the confirmation says so.
What leaves the platform
Only what a feature you switched on needs, to the party that feature talks to.
| Goes to | What is sent | When |
|---|---|---|
| Your OLTs | SNMP reads and CLI commands | On the sweep you schedule, and when you act |
| Telegram | Alert messages, to the bot and chat you configured | When an alert is raised, on plans with Telegram delivery |
| Your RADIUS server | API requests with the login you gave | Every 30 minutes, when Link Radius Server is switched on for your ISP |
| Google’s geocoding service | Customer addresses, to place them on the map | Only on ISPs with the plant map: once per address, refreshed after 30 days |
| Sign-up codes to you, and enquiries from this site to our support inbox | Sent through our mail provider |
A RADIUS server address has to be public HTTPS. Loopback, private, link-local and carrier-grade NAT ranges are refused in the connection itself, checked against the address actually dialled, so a typed address cannot be used to reach inside our network.
Sign-up
A trial is created only after the email address is proven with a six-digit code, stored hashed, good for 15 minutes and for ten guesses. Temporary and free mailboxes are refused, because a domain claim means nothing if anyone can send from it. One trial per operator is enforced on hashed email, phone, ISP name and domain, and sign-ups from one network are capped per day.
Where it runs
RadixOLT is a hosted service. It is also containerised and can be installed inside your own network, for OLTs whose management addresses must never be reachable from outside. A Site Agent that dials out from your LAN, so an OLT with no public route can stay that way on the hosted service, is planned and not built.
Data that could not be read is shown as not read, never as healthy: a port whose state the platform cannot report reads “not reported”, and a reading hours old is labelled with its age.
Reporting a vulnerability
Write to support@radixolt.com with “Security” in the subject. Please give us a chance to fix an issue before you publish it. The same contact is published in security.txt.
How personal data is handled is set out in the privacy policy.