# Unimus > Unimus is a Network Configuration Management (NCM) system for backup, change management, auditing, and automation of network device configurations. Developed since 2016 by NetCore j.s.a. Designed by network engineers for network engineers; deployed by teams from home labs, MSPs and telco to large enterprise networks. Unimus is easy to deploy, simple to use, yet covers the full NCM feature set, from configuration backup and change management through to network-wide automation and compliance. Managing over a million devices across thousands of networks world-wide, Unimus is trusted by some of the most advanced and secure networks around the world. ## Key facts - Category: Network Configuration Management (NCM), network automation, configuration backup, change management, configuration auditing, configuration compliance - Vendor: NetCore j.s.a. - Deployment: on-premise, self-hosted; supports Windows, Linux, Unix; x86, x64, ARM; Docker - Architecture: web-based GUI, REST API, agentless (no software installed on managed devices), optional distributed Unimus Core nodes for segmented networks and distributed polling - Free tier: 10 devices, permanent, no time limit, all features except Configuration / Runtime Compliance and SAML / OIDC - Paid tiers: - Per-Device (Standard / Advanced), up to 1000 devices, yearly billing - Unlimited (Standard / Advanced), yearly billing, unlimited devices - Air-gap support: Offline Mode is available on the Unlimited (Enterprise) tier - Compliance frameworks supported in the Compliance module: ISO 27001, NIS2, SOC 2; also supports validation against custom internal policies - Vendor neutrality: Unimus is completely vendor-agnostic, allowing you to easily manage a diverse network from a single system - Device support: broad support across major networking vendors (400+ device types, 150+ vendors); see the wiki for the full list ## Features **Configuration management** - Configuration Backup - automated backups with customisable flows; versioned configuration history; export options for archive and audit - Change Management - automatic change tracking with graphical configuration diffs between any two revisions; REST API integration for change workflows - Change Notifications - automatic change detection with delivery via email, Slack, or Pushover; custom filters; integration with SIEM or ticketing platforms **Configuration search and auditing** - Configuration Auditing - network-wide configuration search by keyword or regular expression; saved searches; advanced filtering and export for audits or reports - Runtime State Auditing - automated collection of runtime data via custom diagnostic command sets; aggregated device output for live state visibility **Configuration compliance** - Configuration Compliance - verify device configurations against custom rules or industry standards (NIS2, ISO 27001) using a Compliance Engine that evaluates backups, diffs, and search results; compliance status notifications - Runtime State Compliance - live validation of runtime state against predefined policies; instant violation notifications via email, Slack, or Pushover **Network automation** - Automatic Device Discovery - point Unimus at an IP or a subnet and it discovers devices and automatically identifies vendor, model, and device type, with no manual classification required (no need to tell Unimus "this is a Cisco Catalyst 9300" - it figures it out); scheduled network scans; NMS inventory sync for automated device lifecycle management - Config Push Automation - perform configuration changes easily across the entire network at scale in a single action, without writing scripts or code (push a new VLAN, ACL update, credentials rotation, or firmware update to thousands of devices at once); ad-hoc or scheduled, zero-touch execution; intelligent grouping of device responses for review - Config & State Pull Automation - scheduled or on-demand collection of configuration and runtime state, globally or per device; REST API integration for workflow automation **Network operations and scalability** - In-App Device CLI Access - built-in web terminal emulator with integrated remote access gateway; secure direct CLI to network devices from the Unimus UI; replaces separate SSH jump hosts - Distributed Architecture - multi-tenancy, distributed device polling via Remote Cores in Zones, high availability for larger or geographically distributed networks ## Security and certifications - Fully on-premises deployment: no configuration data leaves your network - Agentless: no software installed on managed network devices - Data at rest: device credentials and API tokens encrypted with AES-128-CBC + PKCS5 using a user-defined key; application-layer encryption of sensitive data before database storage; the database is fully under customer control - Data in transit: SSH to managed devices; Remote Core to Server traffic uses AES-256 over TCP with a Pre-Shared Key (PSK); the only outbound connection from a standard Unimus deployment is HTTPS (TLS) to the licensing server on TCP 443 - Access management: Role-Based Access Control, Object Access Policies, Multi-Factor Authentication, SSO, LDAP, RADIUS, SAML, OpenID / OIDC; full system access history with authentication context - Unimus certifications: ISO 9001:2015, ISO 22301:2019, ISO/IEC 27001:2022, PCI DSS Merchant Compliance - Penetration testing: third-party penetration tests on the Web GUI and API; summary reports at https://security.netcore.software ## Integrations and API - REST API: full-featured API covering configuration, automation, and reporting operations - Notifications and alerting: email, Slack, Pushover (used by Change Notifications and Compliance modules) - SIEM and ticketing platforms: change alerts and overviews integrate downstream - Network Monitoring System (NMS) inventory sync for device lifecycle automation - Authentication and identity providers: SAML, OpenID / OIDC, LDAP, RADIUS, MFA ## Use cases - Network engineering teams - day-to-day configuration backup, change review via diffs, root-cause investigation, and in-app CLI access - MSP / hosting partners - usage-based monthly billing, white-labeling, multi-tenancy, 24/7 support - ISPs and telcos - distributed polling across segmented networks, central management of large device counts - Enterprise security and compliance - configuration auditing, change governance, and compliance validation aligned with ISO 27001, NIS2, and SOC 2 - Air-gapped, government, and regulated deployments - Offline Mode on the Unlimited (Enterprise) tier ## Primary pages - [Homepage](https://unimus.net/) - product overview and design principles - [Features](https://unimus.net/features) - full feature inventory grouped by category - [Pricing](https://unimus.net/pricing) - tier comparison, FAQ, payment options - [NIS2 & Network Security](https://unimus.net/network-security) - compliance use cases and capability detail - [Unimus Security](https://unimus.net/unimus-security) - Unimus's own security architecture, encryption, and certifications - [Download](https://unimus.net/download) - install packages and platform support - [Get started](https://unimus.net/getstarted) - 3-step onboarding ## Related properties - [Documentation wiki](https://wiki.unimus.net/) - [Blog](https://blog.unimus.net/) - [Community forum](https://forum.unimus.net/) - [Customer portal](https://portal.unimus.net/) - account, license, and billing management