Network (Wi-Fi, switch, gateway)
Coverage planning, VLAN segmentation, PoE power and uplinks, all monitored and alerted.
AI-Managed Service
We read raw device activity through official UniFi APIs, send it over encrypted channels to our own cloud platform, and analyse it 24/7 with SIEM and our own AI platform to find failing hardware and arrange replacement before it fails — from SMEs to multi-site enterprises.
Service at a glance
Traditional IT maintenance starts with a fault report; before that call, the provider knows nothing about device health and the time has already been spent on recovery rather than prevention.
AI-managed service starts with data: device activity is read continuously and compared against a long-term baseline for each device. When a disk, power supply, switch port or wireless coverage starts to drift, we receive the signal before the customer notices and arrange repair or replacement before the hardware actually fails — cutting unplanned downtime.
How it works
Every layer deliberately avoids placing third-party software inside a customer network.
UniFi's official APIs provide device activity records, alerts and status — no agent installed and no inbound port opened.
Records travel to our cloud platform over encrypted channels, encrypted in transit and at rest, visible only to authorised engineers.
SIEM correlates events across devices instead of looking at a single alert; anomalies become visible immediately.
Correlation results are computed together with each device's long-term baseline, so anomalies surface without manual inspection.
The platform recommends practical improvements — repositioning devices, separating high-traffic equipment or replacing a wearing disk.
When disk, power or link trends decline, we arrange repair or replacement before the hardware fails, reducing downtime.
Service scope
You own the equipment; we monitor how it runs — with the same engineering team from installation to daily operation.
Coverage planning, VLAN segmentation, PoE power and uplinks, all monitored and alerted.
Cameras, NVR and disk health, and recording retention; offline or interrupted recording is flagged immediately.
Card, PIN and mobile entry plus video intercom — permissions, schedules and records managed together.
Firewall rules, site-to-site VPN and outbound monitoring; the Security Hardening add-on feeds device data into SIEM with a monthly security review report.
VPN and individual accounts replace shared passwords, so access can be revoked the day someone leaves.
Traffic, logins and device state are logged centrally and analysed continuously, with proactive email or mobile alerts.
Access control and intercom currently have no public API, so they appear in telemetry only as connected clients and switch PoE ports — we state this plainly rather than guessing.
The API reads UniFi management data only: device state, activity records, alerts and configuration. Managed service never touches files, email or business systems, and never reads CCTV image content.
Service tiers
Monthly fees are per device endpoint with a minimum; minimum 12-month term, fixed monthly fee, and you own the hardware.
24/7 remote monitoring and alerts, firmware and security updates, configuration backup, unlimited remote support and monthly reports, plus hardware health and recording retention checks. From HK$800/month.
Everything in Basic plus a 1-hour SLA response, unlimited emergency site visits, 24-hour device replacement, quarterly reviews and CCTV health monitoring. From HK$2,000/month.
VLAN segmentation review, firewall rule audit and outbound connection monitoring, with SIEM analysis and a monthly security review report. +HK$500/month.
Onboarding
Hover over each bar to see what happens in that phase.
Choose your tier · 1 wk Authorise access · 1 wk Baseline & first report · 1 wk Follow-up & monthly reporting · 1 wk
The first month establishes the baseline; alert thresholds are still being tuned until it stabilises.
You keep control of access and privacy
We install no third-party agent on your network and open no inbound ports, so the managed service itself adds no attack surface. After authorising access you remain the owner of the devices and can remove GNS from the same screen in UniFi Site Manager at any time — once removed, our read access ends immediately.
Practical benefits
Problems are queued for repair before they become failures; even when hardware does fail, replacement is already arranged.
Disk, fan and power wear is visible in trends, so replacement is decided by condition rather than by failure.
Unexpected logins, configuration changes and new devices all leave records that are correlated.
A fixed per-endpoint monthly fee means hardware failures do not land as a surprise cost in one quarter.
Devices, events and how they were handled are recorded; the Security Hardening add-on adds a monthly security review report.
Each intervention also reduces the chance of the next failure rather than only resolving today's issue.
Brand partnership: SI Partner Programme
GNS is a Hong Kong reseller, systems integrator and managed service provider for international brands: local sales, system integration, 24/7 managed service, engineering delivery and new-business development in government, rail, logistics and education. Explore the SI and MSP Partner Programme →
FAQ
Traditional maintenance starts after a failure; we intervene before one. We read device activity continuously through official UniFi APIs, send it to our cloud platform, and use SIEM for 24/7 correlation against each device's long-term baseline. When a disk, power supply or link starts to drift, we arrange repair or replacement proactively instead of waiting for a fault report.
SIEM (security information and event management) centralises events from different devices and finds correlations. A single alert may be noise; when repeated failed logins, configuration changes and a new device appear together, correlation shows this is one incident to handle.
No. The API reads UniFi management data only: device state, activity records, alerts and configuration. Managed service never touches files, email or business systems and never reads CCTV image content. Records are encrypted in transit and visible only to authorised engineers.
No. We read data directly through official APIs, so there is no agent on your network and no inbound port to open — which also reduces the attack surface the managed service itself introduces.
The fee buys continuous comparison and ready capability: device baselines, alert thresholds, update scheduling, event records and SLA commitments all accumulate on quiet days. A month without incidents is the mechanism working as intended.
The first month exists to tune thresholds. We compare against each device's long-term baseline rather than a single fixed value, and an engineer reviews before anything is dispatched — both conditions must apply for a signal to become actionable.
Trend comparison needs history: disk, power and wireless coverage drift usually takes months to show direction. With a baseline month followed by accumulated trends, 12 months is the shortest period in which managed and unmanaged outcomes can genuinely be compared. Fees are fixed and continue monthly after the term.
We handle continuous monitoring, baseline comparison, update scheduling and hardware replacement planning; your IT team keeps day-to-day use, accounts and business systems. Every change and action appears in the monthly report, so both sides work from one list.
Bring your device list and floor plan and we can run a free site assessment, then recommend the tier and a fixed monthly fee.