A tool that holds your switch passwords should explain itself.
Here is how Switch Manager Pro works, in plain English — including the parts it can’t protect against.
How we reach your switches
A small agent runs as a Windows service on a machine on your network. It connects out to the portal over HTTPS and asks for work every few seconds, so nothing on the internet needs to reach in and there is no firewall rule to open. It talks to your switches over SSH from inside your network.
The portal never writes switch commands. It sends the name of an operation and its settings; the agent builds the commands from a reviewed catalogue, validates every input, and returns them for approval.
The first time the agent meets a switch it records the switch’s SSH host key. If a different key ever answers at that address, the agent refuses to log in and the portal flags it. Clearing that is a deliberate, recorded action — never automatic.
Where your data lives
The portal and database run in London. Supporting services are in the UK or EU; the full list of sub-processors is in our Data Processing Agreement.
- Configuration backups are encrypted before they are stored. Opening or searching them is limited to people who can change switches, and every view is recorded.
- We never store MAC address tables, ARP tables, switch logs or SNMP output.
- Finding a device by MAC address is done by the agent on site; only the matching line comes back.
- Alert emails name the switch and the time window — never config text. You read the change in the portal.
Passwords and secrets
Switch logins, and secret values in a change such as a new admin password or SNMP community, are stored encrypted. The agent fetches them for one command, while that command is running, within a short window — and they are never written into the command history, which is kept.
Opening a PuTTY session from the portal uses a single-use ticket that expires in 90 seconds. The installer on your PC redeems it, and the password is handed to PuTTY in a temporary file that is deleted once PuTTY has read it — never on a command line, where other programs could read it.
How a change is controlled
- Previewed exactly. You approve the literal commands for each switch, and those are what run.
- Saved only if clean. If the switch rejects any line, the configuration isn’t saved.
- School hours. Anything that can interrupt the network needs a recorded reason between 08:00 and 16:00 on weekdays.
- Schedules re-check. A scheduled change is checked again when it fires, and cancelled rather than sent if it is more than 30 minutes late.
- Recurring runs are bound to what you approved. If the commands a schedule would send ever differ from the ones you approved, it doesn’t run and you’re emailed.
- Bulk runs are paced. Each switch waits its turn, and the run stops if too many fail.
- Unproven operations are refused. Anything not yet verified on real hardware for that OS is marked for a lab check and the agent won’t send it.
The offline installer
The installer has no licence key. On first run it shows a code, and someone in your organisation approves it from the portal, signed in as themselves — so your single sign-on applies and no password is typed into the program. That laptop then holds a signed lease that works offline for 14 days and renews itself when online.
- Each approval uses one of your organisation’s seats. Revoke a seat and that laptop locks the next time it goes online, and within 14 days regardless.
- The activation is tied to that computer and encrypted for that Windows account. A copy made to work anyway is detected on renewal and the seat is revoked.
- The installer only listens on the laptop itself, behind a random access key, and site profiles drop passwords unless you choose to keep them.
What we don’t claim
Nothing that runs offline can stop someone who modifies the program itself. A modified installer loses renewal and anything recorded against your organisation, but we won’t pretend it can’t exist.
Change alerts come from comparing nightly backups, so we see that a config changed and roughly when — not who typed it at the console. We don’t yet draw topology, update firmware or roll back a config for you.
Questions a security review needs answered? Ask us directly.