Change everything.
Break nothing.

Kavros pushes a configuration change to every MikroTik you own — with a diff you read before it lands, a rollback that fires by itself, and proof from each site that the service came back.

Self-hosted. Runs on your hardware, credentials never leave your network.

AVROS
all124
up121
down2
drift1
NameModelRouterOSUptime
border-tll-01CCR2004-16G7.20171d
core-tll-02CCR1009-7G7.22.284d
pop-tbs-01RB5009UPr+S+7.19
pop-mil-04hAP ac²7.23.312d
pop-rix-07hEX S7.22.26d

One view

Every site on one map, and the state of each one.

A router that answers, a router that answers badly and a router that stopped answering are three different facts. Kavros keeps them apart, on a map you can open on a phone in a taxi, and it never asks a router a question to find out - the answer is already there.

sites34across nine countries
devices124one inventory, one search
average score86hardening baseline
last change4mdiffed and recorded
answering answering badly stopped answering

The problem

Forty routers, four cities, one rule.

You paste it into the first WinBox window and hope. Somewhere around the twelfth you have lost track of which ones took it, and the only way to find out is to open them one at a time.

That is how a Friday afternoon turns into an outage. It is also why most fleets still run a RouterOS from two years ago — the upgrade is a night of manual work with no way back.

Before it lands

You read the change in the language the router speaks.

No abstraction, no summary. The diff is the exact command list Kavros will send, and automatic checks refuse the whole batch if it would cut management access.

border-tll-01 · 10.10.0.118 commands · 3 devices in this wave
/ip firewall mangle
- set [find comment="kv:policy:030"] dst-address-list=EU-CORE
+ add chain=prerouting action=mark-routing new-routing-mark=EU-CORE \
    dst-address-list=PARTNER-NETS passthrough=no comment="kv:policy:031"
/system scheduler
+ add name="kv-confirm" start-time=startup on-event="/system script run kv-rollback"
Blocking check passed — the management subnet 10.10.0.0/24 is still accepted by rule kv:policy:000 after this change.

After it lands

Proof from the site, not a green tick from the panel.

Kavros probes the services your subscribers actually use, from each POP, and separates reachable from reachable but leaving through the wrong uplink — the failure nobody else reports, and the one that costs you the support call.

SiteWhatsAppInstagramYouTubeBankingSpeedtest
Site 04 · West Europe
Site 09 · South Caucasus
Site 17 · South Europe
Site 23 · South America
Site 31 · Southeast Asia
reachable reachable, wrong path down

What the fleet is carrying

A score you can act on, and a graph that is not a guess.

Every device is read against a hardening baseline - open management services, default SNMP strings, MAC access left on every interface, a firewall with nothing dropping on input. Each finding says what it found, quotes the line it found it on, and where it is safe, offers to fix it.

Fix it means: the router writes a backup of itself, the exact command for that finding is sent, and the setting is read back. If the device does not confirm the new value, nothing is recorded as fixed. What is safe to automate is a closed list in the code - never the API, Winbox or SSH services, never a firewall rule, never an account.

Securityread 2 minutes ago, live
62site score · 1 high, 1 medium, 1 low
high
SNMP community is 'public'

Anyone who reaches the port reads the configuration.

medium
MAC-Winbox reachable on every interface

allowed-interface-list is unset, which means all.

Fix it
low
NTP client is disabled

A drifted clock breaks the log trail across the fleet.

Fix it
WAN trafficether1 + ether3, summed
down 1.9 TB up 610 GB 1h24h7d

How it hangs together

The links, drawn from what the routers see.

Neighbour discovery, routing adjacencies and the tunnels each device reports, drawn as one graph. When a link stops being reported, the graph shows the gap where it used to be - which is usually the first honest answer to why a site went quiet.

core-a core-b agg-1 agg-2 agg-3 site-04 site-09 site-17 site-23 site-31 site-38

What Kavros does

Three things, done properly.

Everything else in the product exists to make these three trustworthy.

01

You see it first

Real RouterOS commands, blocking checks that refuse a dangerous batch outright, and a confirmation with a countdown before anything is sent.

02

It comes back on its own

Risky changes are armed before they are applied. If you do not confirm within the window, the router restores itself. Nothing to undo by hand at two in the morning.

03

Partial success is a first-class result

Waves, automatic pause when the error rate climbs, failures grouped by cause, and a button that retries only what actually failed.

And the rest of it

The work you do by hand today.

Free for good. You pay only when Kavros starts changing the network for you.

InventoryModel, RouterOS version, uptime, CPU and memory, on a schedule.
BackupsExports with a readable diff between any two points, and restore.
UpgradesInstalled versus available, rolled out in canary waves.
CredentialsEncrypted at rest. One click opens WinBox already connected.
AuditWho changed what, where, when, and the exact commands sent.
LogsSyslog from the whole fleet, with alerts that survive rotation.
HardeningEvery device scored against a baseline, with a one-click fix where it is safe.
TrafficWhat crossed each WAN, by the hour, the day and the week.
TopologyLinks between devices, drawn from what the routers report.
NotificationsA message when a device drops, a backup fails or a config drifts.
Roles and sitesAn engineer in one country sees that country, and nothing else.
The panel backs itself upDatabase, archives and monitors, sealed nightly and copied off the host.

How it is sold

Looking is free. Changing the whole network safely is not.

Billed per site, not per device — growing your network does not quietly grow your bill. Runs on your own hardware, so credentials and configs never leave your premises.