B BROCENT

Managed service · Wireless network

You buy the UniFi access points.
The controller is already built.

Register the Ubiquiti UniFi access points you already own into Brocent's managed controller — no server to build, no second hardware Cloud Key to buy. Configuration, monitoring, change execution and firmware upgrades are run by our NOC, with an availability report every month. Haven't bought access points? The same service is available with the hardware included in the subscription.

In one line: The UniFi controller software is free. The hard part is who runs it 24×7, backs it up, upgrades it, and answers for its downtime. That is what this service sells.
controller servers for you to run
0 controller servers for you to run
panel for every site
1 panel for every site
controller availability commitment
99% controller availability commitment
automated availability report
Monthly automated availability report
Hong Kong office AP · AP · AP Singapore office AP · AP · AP Shenzhen office AP · AP · AP Managed UniFi Network controller BROCENT · BCS managed control plane Scoped to your tenant
Your access points stay your assets. Only the control plane moves to us — and it can move back.

Two ways to buy the same service

Bring your own access points, or subscribe with the hardware included

The question that changes the price is who owns the access points. Everything behind them — the controller, the NOC watching it, the change process and the monthly report — is identical in both models.

Model A · Bring your own access points

You already bought UniFi access points

Register them into the controller Brocent already runs. Nothing to build, nothing more to buy, and the hardware stays yours.

  • ✓ Adoption, SSID/VLAN, guest portal and enterprise authentication
  • ✓ 24×7 monitoring, alerts turned into tickets, firmware upgrades in a maintenance window
  • ✓ Daily configuration backup with three-year retention; monthly availability report
  • ✓ The access points remain your assets, and the configuration can be exported if you leave

US$1.20 / AP / month · 12-month contract · excl. tax per access point / month · 12-month contract, excl. tax

See the controller rate →

Model B · Fully managed, hardware included

You would rather not put capital into hardware

Brocent supplies the access points as part of the subscription and keeps them running — no hardware or software investment to build enterprise-class wireless.

  • ✓ No capital investment: subscribe and the network is ready within an hour
  • ✓ Hardware maintenance and replacement included — spare devices delivered and swapped within the agreed SLA, at no extra cost for the repair
  • ✓ The same controller, NOC monitoring, change process and monthly reporting as Model A
  • ✓ Site policy cloned to each new office, so opening a location is a copy, not a rebuild

Custom quote subscription, scoped by sites and access-point count

Talk to a consultant →

Same control plane, same NOC, same report in both models — the only difference is who holds the hardware. Not sure which way round is cheaper for your estate? Send the site and access-point count and a consultant will price both.

The choice, laid out

There are only three ways to run a UniFi controller

The UniFi Network software itself is free — so the real cost isn't the software, it's who keeps it running. Here is what each path actually costs you.

Option 1 · Self-host

Build your own controller

US$0 software the server, the people and the risk are yours

  • ✕ You provide a Java + MongoDB environment (official minimum MongoDB 3.6, bundled); a small network needs roughly 1–1.5 GB of RAM just for this.
  • ✕ You open and harden TCP 8443 / 8080 / 8843 and UDP 3478 / 10001.
  • ✕ Upgrades, backups, hardening and availability are all on you — Ubiquiti's own guidance is not to self-host if you can't keep it running continuously.
  • ✕ A self-hosted install runs UniFi Network only. Protect (video) and Access (doors) are not supported on any self-host path.

Fits teams with a dedicated network engineer who are happy to own that server.

Option 2 · Buy hardware

Buy another Cloud Key

US$239.99 Cloud Key Gen2 Plus retail, one-time · one per site

  • – Works out of the box, but its resources are fixed and it does not scale horizontally.
  • ✕ Single point of failure: if the unit fails, loses power or loses its storage, the management plane goes with it.
  • ✕ Upgrades and backups still need a person, and multiple sites usually means multiple units.
  • – Ubiquiti's own hosted controller is a further option, from US$29/month for up to 1,000 devices — operations still sit with you.
  • ✓ Its one real advantage: if you also want Protect (video) or Access (doors), this is the only path — those apps run only on UniFi OS hardware.

Fits a single site that can accept the management plane going down with that one box.

Option 3 · Brocent-managed ✓

Use the one we already run

US$1.20 / AP / month · 12-month contract · excl. tax priced per access point, per month · monthly availability report included

  • ✓ Nothing to build: no server, no Cloud Key, and no ports opened on your network.
  • ✓ The access points remain your assets — we host the control plane, and you can migrate off it at any time.
  • ✓ Upgrades, configuration backups, change execution and alert response are carried by the NOC.
  • ✓ Logical tenant isolation, a 99% availability commitment, daily configuration backup retained three years, and an automated monthly availability report.

Fits multi-site or cross-market teams, teams with no dedicated network engineer, and anyone who would rather the management plane not live in the office.

Third-party figures are public retail / vendor list prices observed 2026-09-10, shown for comparison only — they are not Brocent quotes. Cloud Key and the official hosted controller are Ubiquiti products. Brocent's own price is in Pricing & options below.

What you get once the access points are adopted

One control panel, covering the whole life of the wireless network

These capabilities come from the UniFi Network controller itself; Brocent configures and operates them for you on the managed instance. You don't have to learn it, and you don't have to maintain it.

Adopt & configure

ADOPT · PROVISION

Device adoption

Power an access point onto the network and the controller discovers and adopts it — no logging into each unit.

SSID & VLAN

Wireless networks and VLAN separation pushed per site or per floor; policy defined once, applied in bulk.

Guest portal

Branded guest authentication with voucher and other methods, guests kept off the internal network.

Enterprise auth

RADIUS / 802.1X supported, so staff connect with an account instead of a shared password.

Monitor & alert

MONITOR · ALERT

Uptime & dropouts

Offline access points, reboot loops and PoE faults watched 24×7 by the NOC and raised as tickets.

Clients & capacity

Client counts, band distribution and congestion per site — the basis for capacity decisions.

RF conditions

Channel utilisation and interference are visible, so "full bars but no internet" gets an actual cause.

Alert to ticket

Alerts don't stop at an inbox — they enter the service desk with someone accountable for closing them.

Change & upgrade

CHANGE · UPGRADE

Firmware upgrades

Executed in batches inside an agreed maintenance window, with a configuration backup taken first — never the whole estate at once.

Configuration backup

Controller configuration backed up daily and retained three years, so a mis-click or a device swap can be rolled back to any day.

Change trail

Who changed what, and when — auditable, so there's a record to hand over when an auditor asks.

New-site cloning

A mature site's policy can be cloned to a new office instead of configured from scratch.

The question a managed service should be asked

One platform, strict tenant boundaries — you only ever resolve your own network

We run logical isolation: not a separate server per client, but tenant boundaries inside the platform that scope both data and permissions. Stating the boundary precisely is more useful than a vague promise of "completely separate" — here is what it actually means.

  1. 01

    The tenant is a hard boundary, not a filter

    Your sites, access points, topology, client records, SSIDs and keys, and logs all belong to your tenant. Every query resolves inside that scope; another client's data never appears in the same view.

  2. 02

    Separate credentials, least privilege

    Your admin accounts resolve only your own tenant. Brocent engineers are authorised per client, and who looked at or changed what, and when, is logged.

  3. 03

    We say where the boundary is

    The underlying platform and runtime are shared — which is also why the per-access-point price can be what it is. If your compliance requires a dedicated instance or a specific data jurisdiction, raise it before the quote and a consultant will scope it, rather than assuming it's included.

  4. 04

    Portable, not locked in

    The access points are assets you bought. On termination the configuration can be exported and devices migrated back to a self-hosted controller — we host the control plane, not ownership of your network.

BROCENT · BCS managed control plane Tenant · Client A Sites & devices Data scope Credentials & rights Tenant · Client B Sites & devices Data scope Credentials & rights Tenant · Client C Sites & devices Data scope Credentials & rights ✕ No path between tenants Shared runtime · highly available · elastic compute · daily backup

Platform commitments

AVAILABILITY

99%

Controller service availability commitment. Runs highly available — not dependent on a single host.

BACKUP

Daily · 3 yr

Configuration backed up daily and retained three years, so a mis-click or a device swap always has a way back.

SCALE

No fixed cap

Elastic compute: capacity is added as your access-point and site count grows — no re-planning because "the controller can't take it".

ISOLATION

Per tenant

Data and credentials scoped by tenant; accounts resolve only their own scope, and engineer access is logged.

What we host, and what we don't

Controller hosting covers UniFi Network; video and door access have to sit on site

UniFi isn't one piece of software — it's several applications. Only UniFi Network (the wireless and switching controller) can be self-hosted or hosted as software, and that is exactly what this service provides. Protect (video), Access (doors) and Talk (telephony) are not included — and that is Ubiquiti's product architecture, not a ceiling on our platform.

IN SCOPE · covered by controller hosting

UniFi Network

  • ✓Access-point adoption, SSID and VLAN, guest portal, RADIUS / 802.1X
  • ✓Central configuration and port management for UniFi switches, on the same control plane
  • ✓Uptime, client and capacity, and RF monitoring, with alerts turned into tickets
  • ✓Firmware upgrades, configuration backup and rollback, change trail
  • ✓Priced per access point — no controller hardware anywhere on your site

OUT OF SCOPE · needs a console on site

UniFi Protect · Access · Talk

  • ✕ They cannot be installed on our servers — or yours. Ubiquiti allows these three applications to run only on its own UniFi OS console hardware (Cloud Key Gen2 Plus, UNVR, Dream Machine and similar).
  • ✕ Ubiquiti's own self-host package, UniFi OS Server, does not change this: it currently covers Network, InnerSpace and Identity — Protect, Access and Talk are not among them.
  • ✕ Access has a physical constraint too: every door needs an Access Hub to actually release the lock, which has to be on site. That cannot be moved to the cloud.
  • → So if you need video or door access: a UniFi OS console goes in your office, and Brocent can specify, supply, deploy and maintain it.
One thing worth knowing, in your favour: UniFi OS Server runs one instance per client, with no multi-tenancy and none of the role separation an MSP needs. That is precisely why we built this management layer ourselves — tenant boundaries, permission tiers, change process and reporting sit on top of it, instead of every client maintaining their own copy. See hardware and maintenance pricing ↓

A change is not "just a quick edit"

Every configuration change runs the same traceable process

Adding an SSID, changing a VLAN, upgrading a batch of firmware — none of it is agreed verbally in a chat group. It goes through a ticket, into a maintenance window, and onto the record.

  1. 01

    Raise

    You submit a change request at the service desk, or a monitoring alert raises one automatically.

  2. 02

    Assess

    An engineer confirms the blast radius and the rollback plan, and proposes a window.

  3. 03

    Confirm

    You approve, then it's scheduled — business-affecting changes are not forced through during working hours.

  4. 04

    Execute

    A configuration backup is taken first, then the change runs in batches inside the window and is verified.

  5. 05

    Record

    The outcome is written to the change record and appears in that period's service report.

What lands in your inbox

Automated reporting: no meeting needed to ask "was the network fine this month?"

Availability monitoring report Monthly

A finding from this period (excerpt from a real report sample):

One access point restarts unpredictably in the Shenzhen office

One of the two access points logged four unexpected restarts, each under two minutes. Power-over-Ethernet delivery is at the edge of budget on the out-of-support access switch that feeds it. Recommendation: move it to a port on the supported switch; if restarts persist, replace the access point under warranty.

PERIOD

1 month

SITES

All managed

DELIVERY

Report Central

A report is a conclusion, not a screenshot

The point isn't a monthly export of graphs. Each period the report states what happened, what it means, and what we recommend doing about it — the wireless content lands in the availability monitoring report, and if you also use configuration management there is a separate configuration report.

See a real sample report →

Reports are delivered through Report Central — the same nine reports every managed client receives; which of them you get follows your scope, and none is billed separately.

Who buys this

Four situations we see

Multi-site / cross-market

"Three locations, each doing its own thing, and nobody can say which access point belongs to whom."

All three sites are adopted into one managed controller; policy is defined centrally and pushed per site. A new location clones an existing configuration.

Result: every site in one panel, and opening a location changes from "configure it all again" to "copy it".

No dedicated network engineer

"IT is just me. When Wi-Fi breaks I reboot the access point and hope."

The control plane is watched 24×7 by the NOC and alerts become tickets automatically. You raise requests at the service desk instead of learning the controller.

Result: no more troubleshooting by reboot — someone is watching it, and someone will change it for you.

Audit / compliance

"The auditor wants proof that guest Wi-Fi is separated from the office network, and wants to see change records."

Guest-to-internal separation is a demonstrable controller configuration; changes run through process with a trail, and each period's report can be attached as evidence.

Result: records exist when asked for, instead of being assembled at the last minute.

New office / relocation

"The new office hands over next month. The access points are bought, but there's no controller."

Access points adopt as soon as they're powered on, and policy clones from an existing site. Where a survey and physical deployment are needed, a professional-services project covers it.

Result: the controller stops being the blocker before opening — and no extra hardware for one more location.

Pricing & options

How this service is priced

Every figure below is the same one a consultant quotes. Controller hosting stands alone — you don't need a Managed IT plan to buy it.

Current offer Managed UniFi Cloud AP Controller — annual offer US$1.20 / AP / month · 12-month contract · excl. tax Promo code — quote it to your consultant: YE26-UNIFIAP Now – Nov 30, 2026

Standalone 24×7 NOC monitoring — for switches, servers and cloud workloads rather than the wireless control plane — starts at US$9/month and is priced separately. All prices exclude local taxes.

Common questions

What you'll ask before signing

What exactly is a UniFi controller, and why does it need hosting?

UniFi access points are configured and monitored centrally by the UniFi Network controller — it holds your SSIDs, VLANs, policies, topology and statistics. The software is free, but it has to run somewhere continuously: either a server you build and maintain (Java + MongoDB, ports opened, upgrades and backups yours), or a hardware Cloud Key on site, or a hosted controller like ours. Brocent already runs one on the BCS platform, so you register the access points you bought and skip the build entirely.

View all FAQs →

Do the access points have to be bought from Brocent?

No. UniFi access points you already own can be adopted directly. If you do need new units we can supply them at published pricing and handle deployment, but that is a separate hardware purchase — controller hosting is priced per access point regardless of where the unit came from.

View all FAQs →

Can Brocent supply the access points as part of the service, instead of us buying them?

Yes — that is Model B. Rather than a hardware purchase, the access points come as part of the subscription: no capital investment to build enterprise-class wireless, the network ready within an hour, and hardware maintenance and replacement included, with a spare delivered and swapped within the agreed SLA at no extra cost for the repair. Everything behind the hardware — controller, 24×7 NOC monitoring, change process, monthly availability report — is identical to Model A. It is custom-quoted, since it scopes by sites and access-point count.

View all FAQs →

Is my network data separated from other clients?

Yes, by logical isolation. The platform runtime is shared — which is part of why the per-access-point price is what it is — but the tenant is a hard boundary: your sites, devices, data, credentials and logs are scoped to your tenant, your accounts resolve only that scope, and Brocent engineer access is granted per client and logged. If your compliance requires a dedicated instance or a specific data jurisdiction, raise it before the quote so a consultant can scope it.

View all FAQs →

The controller is in the cloud — if the office loses internet, can staff still use Wi-Fi?

Yes. UniFi access points keep forwarding traffic using the configuration already pushed to them when the controller is unreachable. What is affected is management and statistics, not staff connectivity. The controller service itself runs highly available with a 99% availability commitment, and configuration is backed up daily with three-year retention.

View all FAQs →

Will a firmware upgrade suddenly take the network down?

Upgrades run in batches inside an agreed maintenance window, with a configuration backup taken beforehand, and never across a whole estate at once during working hours. Each upgrade goes through the same change process as any other change: assessed, confirmed with you, executed, verified and recorded — and the outcome appears in that period's report.

View all FAQs →

Can you host UniFi Protect (video) and Access (doors) too?

No — and neither can anyone else. Ubiquiti allows Protect, Access and Talk to run only on its own UniFi OS console hardware; they are not available as self-hosted or third-party-hosted software, and Ubiquiti's own UniFi OS Server package covers Network, InnerSpace and Identity rather than these. Access additionally needs an Access Hub on site for each door. If you need either, a UniFi OS console goes in your office and Brocent can specify, supply, deploy and maintain it — that is a hardware purchase, not a change to controller-hosting pricing.

View all FAQs →

Can I move off the service later?

Yes. The access points are your assets throughout. On termination the configuration can be exported and the devices adopted back into a controller you run yourself, or into a hardware Cloud Key. We host the control plane; we do not hold ownership of your network.

View all FAQs →

Send us your access-point list and we'll quote it.

Tell us how many sites and how many access points, and you'll get a firm price and a sample report back — not a "let's have a chat" call.