Data sheet
2026-09-09
NetCloud Private is a customer-hosted Wireless WAN management solution for organizations that require strict control over data location, security, and operations. Purpose-built for agencies, regulated enterprises, and industrial operators that deploy Ericsson Cradlepoint 5G/LTE routers and adapters across vehicle fleets, fixed sites, and IoT networks, it delivers cloud-like operational consistency within trusted, private environments while supporting a defense-in-depth posture. By running on premises or in a customer-selected in-country/national cloud, NetCloud Private helps meet data residency, privacy, and governance requirements while simplifying large-scale router lifecycle management and reducing exposure to third-party cloud attack surfaces.
Ericsson NetCloud Private combines the operational efficiency of a modern cloud platform with the control, security, and data residency assurances of a customer-hosted solution. It centralizes the full lifecycle of Ericsson Cradlepoint 5G/LTE routers and adapters while enabling organizations to meet privacy, compliance, and governance mandates in trusted, on-premises or in-country environments—reducing external dependencies and supporting validated encryption options when paired with FIPS 140-3 certified routers.
Policy and Governance Alignment – Customer-defined operational policies can be enforced consistently across distributed fleets and locations to support privacy, data residency, and regulatory obligations.
Customer-Controlled Deployment – Install and operate the management platform in a controlled environment—on premises, in a private cloud, or in a preferred in-country/national cloud—so you retain end-to-end control of infrastructure, and operational policies.
Data Residency – Keep management plane data within approved national boundaries and facilities to align with privacy mandates and regulatory requirements, and to support sovereignty and operational governance needs. Retain local oversight of data handling, access, and operational controls in alignment with organizational governance models.
Management-Plane Isolation – Centralized management and telemetry are kept within your trusted environment; no reliance on external public cloud services helps minimize the attack surface and supports operations in restricted networks.
Protected Management Traffic – TLS and mTLS encryption help keep device management and telemetry data secure during monitoring, configuration, and troubleshooting.
Validated Encryption Options – When used with compatible Ericsson Cradlepoint routers that have FIPS 140-3 certifications, NetCloud Private supports validated encryption options to help secure sensitive data transport in line with standards and agency mandates.
Identity Management Options – NetCloud Private is designed to support customer-provided identity providers, allowing organizations to integrate with their existing identity management solutions.
Access Control and Accountability – Role-based access control (RBAC), change-controlled workflows, and audit-friendly operational practices support governance, facilitate oversight, and help satisfy internal and external compliance requirements.
Enhanced Security Posture – A self-hosted architecture places the management plane and associated operational data under your direct control, enabling strict enforcement of data location, access, and policy, and supporting separation of duties and least-privilege administration.
Management-Plane Isolation – Centralized management and telemetry are kept within your trusted environment; no reliance on external public cloud services helps minimize the attack surface and supports operations in restricted networks.
Foundational Security – Through the use of Ericsson NetCloud STREAM protocol the following is provided:
Validated Encryption Options – When used with compatible Ericsson Cradlepoint routers that have FIPS 140-3 certifications, NetCloud Private supports validated encryption options to help secure sensitive data transport in line with federal standards and agency mandates.
Access Control and Accountability – Role-based access control (RBAC), change-controlled workflows, and audit-friendly operational practices support governance, facilitate oversight, and help satisfy internal and external compliance requirements.
Policy and Governance Alignment – Customer-defined security and operational policies can be enforced consistently across distributed fleets to support privacy, data residency, and regulatory obligations.
Centralized Device Lifecycle – Onboard, register, configure, monitor, troubleshoot, and manage distributed 5G/LTE routers and adapters from a single, customer-hosted platform.
Monitoring and Visibility – Gain insights through alerts, diagnostics, logs, and cellular health metrics to improve situational awareness and accelerate issue resolution, while keeping sensitive operational data within your environment.
Centralized Management – Manage large numbers of routers and adapters across vehicles, branches, remote sites, and IoT deployments with consistent security policies and controls.
Reduced Operational Overhead – Centralized workflows and visibility improve efficiency and help teams meet mission timelines while maintaining a strong security posture.
Controlled, Scheduled Updates – Keep devices up to date with approved firmware and security updates under your authority, aligning updates to organizational risk management practices.
Fleet-Wide Management – Manage large numbers of routers and adapters across vehicles, branches, remote sites, and IoT deployments with consistent security policies and controls.
Policy-Driven Operations – Centralized, policy-based configuration helps ensure reliable, repeatable operations while adhering to internal governance and external regulations.
Reduced Operational Overhead – Centralized workflows and visibility improve efficiency and help teams meet mission timelines while maintaining a strong security posture.
Role-Based Access Control – Align user permissions and administrative roles with organizational governance models to protect sensitive functions and data and support least-privilege principles.
Operational Oversight – Maintain local authority over access policies, data handling, and enforcement mechanisms, including approvals for configuration and change management.
Auditability – Processes and controls support documentation and verification of changes for regulated environments, aiding inspections and compliance assessments.
Dependable Wireless WAN – Support reliable, resilient cellular networking that keeps essential operations connected for mission-critical use cases while maintaining management-plane control on premises or in-country.
Mission Continuity – Enable always-available operations by eliminating dependencies on external public clouds when policy dictates, helping to mitigate third-party availability and security risks.
Visibility into Cellular Performance – Cellular health monitoring improves reliability and helps optimize connectivity across diverse deployments without exposing telemetry to untrusted environments.