Goal-Driven Software-Defined Branch
The whole branch — connectivity, security, LAN, and assets — on one control plane
CraftBranch is a goal-driven, multi-vendor Software-Defined Branch platform. It converges the five things every branch runs — SD-WAN, security (SSE/SASE), firewall, switching & WiFi, and branch asset management — into a single control plane. Rather than logging into a controller per box per site, operators declare the outcomes each branch owns — application experience, security posture, uptime — and the platform holds them true with zero-touch provisioning and approval-gated remediation. It is multi-vendor by design, correlating across all five pillars so one branch incident is one story, not five disconnected tools.
Platform Overview
| Category | Multi-vendor Software-Defined Branch — SD-WAN + SSE/SASE + firewall + switch/WiFi + branch asset management |
| Control model | Declare branch goals (app experience, security posture, uptime) → the platform holds them, approval-gated |
| Buyer | CISO / infrastructure — a single converged control plane vs. stacked point tools |
| Multi-vendor | Overlay across leading SD-WAN, firewall, and switch/AP vendors |
| Positioning | One control plane for the whole branch — connectivity, security, LAN, wireless, and assets correlated together |
| Delivery | SaaS or on-prem · augments existing branch hardware |
The Converged Stack — Five Pillars
SD-WAN — application-aware routing, secure overlay to regional points of presence, failover to cellular backup, tiered service classes with per-application SLA
Security — SSE / SASE — ZTNA, secure web gateway, CASB, DLP, TLS inspection; identity federation, posture check, per-user/-device policy
Firewall & Threat — stateful firewall, IPsec VPN, policy-based rules; intrusion prevention, anti-malware, DNS security, threat intelligence feeds
Switch & WiFi (LAN) — L2/L3 switching, VLANs, port and PoE management; WiFi 6/6E, guest isolation, per-SSID policy
Branch Asset Management — device inventory, lifecycle & warranty, firmware/version posture, config compliance, audit trail
Orchestration & Correlation
The platform's orchestration layer correlates across all five pillars, so a branch problem is diagnosed once — not chased through five separate consoles. When a WAN path issue is detected, the platform isolates whether the cause is connectivity, LAN, or security, proposes a fix (such as failing critical traffic to a backup path), and — on approval — applies the change and verifies recovery, logging the full incident end to end.
Zero-touch & honest autonomy — devices ship to the branch, self-register, and pull their configuration with no on-site engineer required. Known-safe actions execute on approval from a queue; every action is authenticated, tenant-isolated, and fully logged.
Interfaces & Integration
| Category | Protocols / Integrations |
|---|---|
| Device management | NETCONF/YANG, REST APIs, SNMP, SSH/CLI adapters (multi-vendor) |
| SD-WAN fabric | Secure overlay, sub-second failover, regional PoP interconnect |
| Security stack | ZTNA, secure web gateway, CASB, identity federation, threat-intel feeds |
| ITSM & ops | ServiceNow/Jira ticketing, Slack/Teams, webhook events |
| Northbound | REST, webhooks, event export to SIEM/OSS |
Multi-Vendor Interoperability
One control plane across mixed branch hardware — augments what's already installed, no rip-and-replace. The platform integrates with leading SD-WAN, next-generation firewall/SSE, and multi-vendor switch/access point platforms.
Deployment & Scale
| Deployment models | Cloud-managed SaaS, on-premise orchestrator, hybrid |
| Onboarding | Zero-touch — golden-config templates, bulk provisioning, drift detection & auto-remediation |
| Platform | Cloud-native, multi-tenant, horizontally scalable, high-availability |
| Rollout | Performance-guaranteed pilot on a handful of branches → fleet rollout |
Security & Governance
| Orchestration security | Authenticated, tenant-isolated, PII-masked, fully audit-logged |
| Access control | RBAC, SSO/SAML, MFA, least-privilege action scopes, segregation of duties |
| Action safety | Dry-run, approval gates, rollback, immutable audit trail, maintenance windows |
| Branch security | ZTNA, secure web gateway, CASB, firewall/IPS, TLS inspection, guest isolation |
Standards & compliance
IETF NETCONF/YANG, IPsec, BFD · IEEE 802.11 (WiFi 6/6E), 802.1X, 802.1Q · SASE / SSE (ZTNA, SWG, CASB, DLP) · SAML / OIDC · TLS 1.2+ · RBAC & audit for regulated environments.
Prefer the PDF?
Download the printable datasheet from the resources library.
See CraftBranch against your network.
Book a demo or scope a proof of concept with our engineering team.