Managed service · Wireless network
You buy the UniFi access points.
The controller is already built.
Register the Ubiquiti UniFi access points you already own into Brocent's managed controller — no server to build, no second hardware Cloud Key to buy. Configuration, monitoring, change execution and firmware upgrades are run by our NOC, with an availability report every month. Haven't bought access points? The same service is available with the hardware included in the subscription.
- controller servers for you to run
- 0 controller servers for you to run
- panel for every site
- 1 panel for every site
- controller availability commitment
- 99% controller availability commitment
- automated availability report
- Monthly automated availability report
Two ways to buy the same service
Bring your own access points, or subscribe with the hardware included
The question that changes the price is who owns the access points. Everything behind them — the controller, the NOC watching it, the change process and the monthly report — is identical in both models.
Model A · Bring your own access points
You already bought UniFi access points
Register them into the controller Brocent already runs. Nothing to build, nothing more to buy, and the hardware stays yours.
- ✓ Adoption, SSID/VLAN, guest portal and enterprise authentication
- ✓ 24×7 monitoring, alerts turned into tickets, firmware upgrades in a maintenance window
- ✓ Daily configuration backup with three-year retention; monthly availability report
- ✓ The access points remain your assets, and the configuration can be exported if you leave
US$1.20 / AP / month · 12-month contract · excl. tax per access point / month · 12-month contract, excl. tax
See the controller rate →Model B · Fully managed, hardware included
You would rather not put capital into hardware
Brocent supplies the access points as part of the subscription and keeps them running — no hardware or software investment to build enterprise-class wireless.
- ✓ No capital investment: subscribe and the network is ready within an hour
- ✓ Hardware maintenance and replacement included — spare devices delivered and swapped within the agreed SLA, at no extra cost for the repair
- ✓ The same controller, NOC monitoring, change process and monthly reporting as Model A
- ✓ Site policy cloned to each new office, so opening a location is a copy, not a rebuild
Custom quote subscription, scoped by sites and access-point count
Talk to a consultant →Same control plane, same NOC, same report in both models — the only difference is who holds the hardware. Not sure which way round is cheaper for your estate? Send the site and access-point count and a consultant will price both.
The choice, laid out
There are only three ways to run a UniFi controller
The UniFi Network software itself is free — so the real cost isn't the software, it's who keeps it running. Here is what each path actually costs you.
Option 1 · Self-host
Build your own controller
US$0 software the server, the people and the risk are yours
- ✕ You provide a Java + MongoDB environment (official minimum MongoDB 3.6, bundled); a small network needs roughly 1–1.5 GB of RAM just for this.
- ✕ You open and harden TCP 8443 / 8080 / 8843 and UDP 3478 / 10001.
- ✕ Upgrades, backups, hardening and availability are all on you — Ubiquiti's own guidance is not to self-host if you can't keep it running continuously.
- ✕ A self-hosted install runs UniFi Network only. Protect (video) and Access (doors) are not supported on any self-host path.
Fits teams with a dedicated network engineer who are happy to own that server.
Option 2 · Buy hardware
Buy another Cloud Key
US$239.99 Cloud Key Gen2 Plus retail, one-time · one per site
- – Works out of the box, but its resources are fixed and it does not scale horizontally.
- ✕ Single point of failure: if the unit fails, loses power or loses its storage, the management plane goes with it.
- ✕ Upgrades and backups still need a person, and multiple sites usually means multiple units.
- – Ubiquiti's own hosted controller is a further option, from US$29/month for up to 1,000 devices — operations still sit with you.
- ✓ Its one real advantage: if you also want Protect (video) or Access (doors), this is the only path — those apps run only on UniFi OS hardware.
Fits a single site that can accept the management plane going down with that one box.
Option 3 · Brocent-managed ✓
Use the one we already run
US$1.20 / AP / month · 12-month contract · excl. tax priced per access point, per month · monthly availability report included
- ✓ Nothing to build: no server, no Cloud Key, and no ports opened on your network.
- ✓ The access points remain your assets — we host the control plane, and you can migrate off it at any time.
- ✓ Upgrades, configuration backups, change execution and alert response are carried by the NOC.
- ✓ Logical tenant isolation, a 99% availability commitment, daily configuration backup retained three years, and an automated monthly availability report.
Fits multi-site or cross-market teams, teams with no dedicated network engineer, and anyone who would rather the management plane not live in the office.
Third-party figures are public retail / vendor list prices observed 2026-09-10, shown for comparison only — they are not Brocent quotes. Cloud Key and the official hosted controller are Ubiquiti products. Brocent's own price is in Pricing & options below.
What you get once the access points are adopted
One control panel, covering the whole life of the wireless network
These capabilities come from the UniFi Network controller itself; Brocent configures and operates them for you on the managed instance. You don't have to learn it, and you don't have to maintain it.
Adopt & configure
ADOPT · PROVISIONDevice adoption
Power an access point onto the network and the controller discovers and adopts it — no logging into each unit.
SSID & VLAN
Wireless networks and VLAN separation pushed per site or per floor; policy defined once, applied in bulk.
Guest portal
Branded guest authentication with voucher and other methods, guests kept off the internal network.
Enterprise auth
RADIUS / 802.1X supported, so staff connect with an account instead of a shared password.
Monitor & alert
MONITOR · ALERTUptime & dropouts
Offline access points, reboot loops and PoE faults watched 24×7 by the NOC and raised as tickets.
Clients & capacity
Client counts, band distribution and congestion per site — the basis for capacity decisions.
RF conditions
Channel utilisation and interference are visible, so "full bars but no internet" gets an actual cause.
Alert to ticket
Alerts don't stop at an inbox — they enter the service desk with someone accountable for closing them.
Change & upgrade
CHANGE · UPGRADEFirmware upgrades
Executed in batches inside an agreed maintenance window, with a configuration backup taken first — never the whole estate at once.
Configuration backup
Controller configuration backed up daily and retained three years, so a mis-click or a device swap can be rolled back to any day.
Change trail
Who changed what, and when — auditable, so there's a record to hand over when an auditor asks.
New-site cloning
A mature site's policy can be cloned to a new office instead of configured from scratch.
The question a managed service should be asked
One platform, strict tenant boundaries — you only ever resolve your own network
We run logical isolation: not a separate server per client, but tenant boundaries inside the platform that scope both data and permissions. Stating the boundary precisely is more useful than a vague promise of "completely separate" — here is what it actually means.
- 01
The tenant is a hard boundary, not a filter
Your sites, access points, topology, client records, SSIDs and keys, and logs all belong to your tenant. Every query resolves inside that scope; another client's data never appears in the same view.
- 02
Separate credentials, least privilege
Your admin accounts resolve only your own tenant. Brocent engineers are authorised per client, and who looked at or changed what, and when, is logged.
- 03
We say where the boundary is
The underlying platform and runtime are shared — which is also why the per-access-point price can be what it is. If your compliance requires a dedicated instance or a specific data jurisdiction, raise it before the quote and a consultant will scope it, rather than assuming it's included.
- 04
Portable, not locked in
The access points are assets you bought. On termination the configuration can be exported and devices migrated back to a self-hosted controller — we host the control plane, not ownership of your network.
Platform commitments
AVAILABILITY
99%
Controller service availability commitment. Runs highly available — not dependent on a single host.
BACKUP
Daily · 3 yr
Configuration backed up daily and retained three years, so a mis-click or a device swap always has a way back.
SCALE
No fixed cap
Elastic compute: capacity is added as your access-point and site count grows — no re-planning because "the controller can't take it".
ISOLATION
Per tenant
Data and credentials scoped by tenant; accounts resolve only their own scope, and engineer access is logged.
What we host, and what we don't
Controller hosting covers UniFi Network; video and door access have to sit on site
UniFi isn't one piece of software — it's several applications. Only UniFi Network (the wireless and switching controller) can be self-hosted or hosted as software, and that is exactly what this service provides. Protect (video), Access (doors) and Talk (telephony) are not included — and that is Ubiquiti's product architecture, not a ceiling on our platform.
IN SCOPE · covered by controller hosting
UniFi Network
- ✓Access-point adoption, SSID and VLAN, guest portal, RADIUS / 802.1X
- ✓Central configuration and port management for UniFi switches, on the same control plane
- ✓Uptime, client and capacity, and RF monitoring, with alerts turned into tickets
- ✓Firmware upgrades, configuration backup and rollback, change trail
- ✓Priced per access point — no controller hardware anywhere on your site
OUT OF SCOPE · needs a console on site
UniFi Protect · Access · Talk
- ✕ They cannot be installed on our servers — or yours. Ubiquiti allows these three applications to run only on its own UniFi OS console hardware (Cloud Key Gen2 Plus, UNVR, Dream Machine and similar).
- ✕ Ubiquiti's own self-host package, UniFi OS Server, does not change this: it currently covers Network, InnerSpace and Identity — Protect, Access and Talk are not among them.
- ✕ Access has a physical constraint too: every door needs an Access Hub to actually release the lock, which has to be on site. That cannot be moved to the cloud.
- → So if you need video or door access: a UniFi OS console goes in your office, and Brocent can specify, supply, deploy and maintain it.
A change is not "just a quick edit"
Every configuration change runs the same traceable process
Adding an SSID, changing a VLAN, upgrading a batch of firmware — none of it is agreed verbally in a chat group. It goes through a ticket, into a maintenance window, and onto the record.
-
01
Raise
You submit a change request at the service desk, or a monitoring alert raises one automatically.
-
02
Assess
An engineer confirms the blast radius and the rollback plan, and proposes a window.
-
03
Confirm
You approve, then it's scheduled — business-affecting changes are not forced through during working hours.
-
04
Execute
A configuration backup is taken first, then the change runs in batches inside the window and is verified.
-
05
Record
The outcome is written to the change record and appears in that period's service report.
What lands in your inbox
Automated reporting: no meeting needed to ask "was the network fine this month?"
A finding from this period (excerpt from a real report sample):
One access point restarts unpredictably in the Shenzhen office
One of the two access points logged four unexpected restarts, each under two minutes. Power-over-Ethernet delivery is at the edge of budget on the out-of-support access switch that feeds it. Recommendation: move it to a port on the supported switch; if restarts persist, replace the access point under warranty.
PERIOD
1 month
SITES
All managed
DELIVERY
Report Central
A report is a conclusion, not a screenshot
The point isn't a monthly export of graphs. Each period the report states what happened, what it means, and what we recommend doing about it — the wireless content lands in the availability monitoring report, and if you also use configuration management there is a separate configuration report.
See a real sample report →Reports are delivered through Report Central — the same nine reports every managed client receives; which of them you get follows your scope, and none is billed separately.
Who buys this
Four situations we see
Multi-site / cross-market
"Three locations, each doing its own thing, and nobody can say which access point belongs to whom."
All three sites are adopted into one managed controller; policy is defined centrally and pushed per site. A new location clones an existing configuration.
Result: every site in one panel, and opening a location changes from "configure it all again" to "copy it".
No dedicated network engineer
"IT is just me. When Wi-Fi breaks I reboot the access point and hope."
The control plane is watched 24×7 by the NOC and alerts become tickets automatically. You raise requests at the service desk instead of learning the controller.
Result: no more troubleshooting by reboot — someone is watching it, and someone will change it for you.
Audit / compliance
"The auditor wants proof that guest Wi-Fi is separated from the office network, and wants to see change records."
Guest-to-internal separation is a demonstrable controller configuration; changes run through process with a trail, and each period's report can be attached as evidence.
Result: records exist when asked for, instead of being assembled at the last minute.
New office / relocation
"The new office hands over next month. The access points are bought, but there's no controller."
Access points adopt as soon as they're powered on, and policy clones from an existing site. Where a survey and physical deployment are needed, a professional-services project covers it.
Result: the controller stops being the blocker before opening — and no extra hardware for one more location.
Pricing & options
How this service is priced
Every figure below is the same one a consultant quotes. Controller hosting stands alone — you don't need a Managed IT plan to buy it.
Controller hosting
Managed UniFi Cloud AP Controller
US$1.20 / AP / month · 12-month contract · excl. tax per access point / month
12-month contract, excl. tax, monthly availability report included. Standing list price is custom-quoted; this is the current offer price.
See the full rate and what's included →Plan add-on
Network & Wireless maintenance
S$113.60 per site / month, up to 10 devices
For clients on a Managed IT Support plan who want switches, gateways and access points maintained together at real per-market rates.
See per-market add-on rates →Fully managed
Wireless with hardware included
Custom quote subscription, by sites and access points
Model B: no capital investment in hardware. Brocent supplies the access points, maintains them, and replaces a failed unit within the agreed SLA at no extra cost for the repair.
Talk to a consultant →Hardware
UniFi access points
US$99 from, per unit
If you still need the access points themselves: published per-model pricing for the units we deploy and maintain.
See hardware pricing →YE26-UNIFIAP Now – Nov 30, 2026 Standalone 24×7 NOC monitoring — for switches, servers and cloud workloads rather than the wireless control plane — starts at US$9/month and is priced separately. All prices exclude local taxes.
Common questions
What you'll ask before signing
What exactly is a UniFi controller, and why does it need hosting?
UniFi access points are configured and monitored centrally by the UniFi Network controller — it holds your SSIDs, VLANs, policies, topology and statistics. The software is free, but it has to run somewhere continuously: either a server you build and maintain (Java + MongoDB, ports opened, upgrades and backups yours), or a hardware Cloud Key on site, or a hosted controller like ours. Brocent already runs one on the BCS platform, so you register the access points you bought and skip the build entirely.
View all FAQs →Do the access points have to be bought from Brocent?
No. UniFi access points you already own can be adopted directly. If you do need new units we can supply them at published pricing and handle deployment, but that is a separate hardware purchase — controller hosting is priced per access point regardless of where the unit came from.
View all FAQs →Can Brocent supply the access points as part of the service, instead of us buying them?
Yes — that is Model B. Rather than a hardware purchase, the access points come as part of the subscription: no capital investment to build enterprise-class wireless, the network ready within an hour, and hardware maintenance and replacement included, with a spare delivered and swapped within the agreed SLA at no extra cost for the repair. Everything behind the hardware — controller, 24×7 NOC monitoring, change process, monthly availability report — is identical to Model A. It is custom-quoted, since it scopes by sites and access-point count.
View all FAQs →Is my network data separated from other clients?
Yes, by logical isolation. The platform runtime is shared — which is part of why the per-access-point price is what it is — but the tenant is a hard boundary: your sites, devices, data, credentials and logs are scoped to your tenant, your accounts resolve only that scope, and Brocent engineer access is granted per client and logged. If your compliance requires a dedicated instance or a specific data jurisdiction, raise it before the quote so a consultant can scope it.
View all FAQs →The controller is in the cloud — if the office loses internet, can staff still use Wi-Fi?
Yes. UniFi access points keep forwarding traffic using the configuration already pushed to them when the controller is unreachable. What is affected is management and statistics, not staff connectivity. The controller service itself runs highly available with a 99% availability commitment, and configuration is backed up daily with three-year retention.
View all FAQs →Will a firmware upgrade suddenly take the network down?
Upgrades run in batches inside an agreed maintenance window, with a configuration backup taken beforehand, and never across a whole estate at once during working hours. Each upgrade goes through the same change process as any other change: assessed, confirmed with you, executed, verified and recorded — and the outcome appears in that period's report.
View all FAQs →Can you host UniFi Protect (video) and Access (doors) too?
No — and neither can anyone else. Ubiquiti allows Protect, Access and Talk to run only on its own UniFi OS console hardware; they are not available as self-hosted or third-party-hosted software, and Ubiquiti's own UniFi OS Server package covers Network, InnerSpace and Identity rather than these. Access additionally needs an Access Hub on site for each door. If you need either, a UniFi OS console goes in your office and Brocent can specify, supply, deploy and maintain it — that is a hardware purchase, not a change to controller-hosting pricing.
View all FAQs →Can I move off the service later?
Yes. The access points are your assets throughout. On termination the configuration can be exported and the devices adopted back into a controller you run yourself, or into a hardware Cloud Key. We host the control plane; we do not hold ownership of your network.
View all FAQs →Send us your access-point list and we'll quote it.
Tell us how many sites and how many access points, and you'll get a firm price and a sample report back — not a "let's have a chat" call.