The ISP operating system for MikroTik networks

Every ISP operation,
in one pane.

The network, the subscribers, the money and the address space — one cloud dashboard instead of four tools that each know a quarter of your business and none of which can act on the others.

Helix NMS+ is a traditional MikroTik network management system with the plus built in: billing and an ISP back office, Splynx integration, IPAM, AI insight, and — arriving next — agentic orchestration, Kronos DNS security and SD-WAN.

One dashboard over the whole operationA single console pane showing the router fleet, subscriber billing and address space together rather than in separate tools.cloud.helixnms.comFleet82 routersSubscribersbilling liveAddress spaceIPAM
82
MikroTik routers under management, in production
63
reached over a managed tunnel — no public IP required
2
countries billing subscribers on it today
v6 + v7
both RouterOS dialects, verified on real hardware

NMS, plus

What the plus actually stands for.

A network management system tells you a router is down. It cannot tell you that the customer behind it paid this morning, that the address it holds was never recorded anywhere, or that another system is about to bill them again. Those are the questions that cost an ISP money, and every one of them needs two halves of the business in the same place.

What the plus in NMS+ stands forA MikroTik network management core surrounded by billing, Splynx integration, IPAM, AI insight, Kronos security and SD-WAN. The list beside this figure states which of them are available today and which are upcoming.NMS coremonitor · configurebackup · upgradeBilling & BSSSplynxIPAMAI insightKronosSD-WAN

Below is the whole of it, with the honest state of each part beside it. Available now means built, reachable and in production use. Early access means built and reachable, with little or no production mileage yet. Upcoming means designed and not built — named here because an ISP plans in years and a roadmap you cannot see is one you cannot plan against.

We publish the difference rather than smoothing it over. You are being asked to hand a system your entire network; a vendor who blurs that line before you buy will blur it afterwards too.

MikroTik NMS core

Monitoring, telemetry, syslog, configuration baselines, backups with diffs, and firmware orchestration with downgrade blocking and a low-flash pre-flight.

Available now

Private-IP device management

Routers behind carrier NAT reached over a Helix-managed OpenVPN tunnel the device brings up itself. 63 of the live fleet run this way.

Available now

Billing and ISP BSS

Plans, subscriptions, invoices, cash desk, bank reconciliation and credit notes — provisioning the router as part of the same act. Live today: 303 subscriptions and 76 invoices on one tenant.

Available now

Dunning and auto-suspend

Overdue escalation and reminders, off unless you turn them on. The suspension half currently cuts a PPPoE subscriber and not a static or DHCP one — the enforcement rules for those are built and not yet armed on any device.

Early access

Splynx integration

Full API integration: tariff and subscriber import, automated cohort migration, payments read back, and dual-mode running while both systems are live.

Available now

IPAM

Address-space inventory, allocation under a per-block lock, discovery from the routers themselves, and an ICMP liveness view. Built and hardened; not yet carrying a production estate.

Early access

AI insight

Per-device analysis in the console, plus a time-of-day-aware traffic baseline that refuses to score a series it has too few samples for.

Early access

Agentic orchestration

An agent that PLANS and never touches a router: it emits an intent, the existing policy layer admits or refuses it, and the existing queue executes and audits it.

Upcoming

Helix Kronos security

DNS policy and filtering as a managed tier — a resolver plane with licence-gated threat feeds, and a read-only firewall snapshot taken before anything is written.

Upcoming

SD-WAN and WireGuard

Per-tenant tunnel namespaces, WireGuard alongside the existing OpenVPN planes, and policy routing across sites. Additive by design — no forced cutover of remote CPE.

Upcoming

The hard part nobody else solves

Your routers do not have public IPs. That is fine.

Most MikroTik management tools assume they can dial the router. On a real subscriber estate that assumption fails immediately: CPE sits behind carrier NAT, addresses are dynamic, and the customer’s own router is the one you most need to reach when something breaks.

Helix inverts it. During enrolment the device runs a single generated script that brings up an outbound encrypted tunnel — carrying its own certificate — and from that moment Helix manages it exactly as if it were directly addressable: configuration, backups, firmware, telemetry, Winbox, port forwards. No static IP. No port forward on the customer’s side. No site visit.

Sixty-three of the eighty-two routers on the live fleet are reached this way today. Certificates are per-device and revocation is real: deleting a device revokes its certificate at the next nightly rebuild, and regenerating one revokes its predecessor.

Two OpenVPN planes run side by side, because RouterOS v6’s client speaks a narrower set of algorithms than v7 — so v6 hardware is admitted without weakening the plane that carries everyone else.

Upcoming: WireGuard alongside the existing planes, per-tenant tunnel namespaces, and SD-WAN policy routing across sites. Additive by design — a forced cutover of remote CPE over the very tunnel being replaced is a self-inflicted outage, so existing devices stay where they are.

Reaching a router that has no public addressThree subscriber routers behind carrier NAT each open an outbound encrypted tunnel to Helix, which manages them as if they were directly addressable.CPE 110.0.0.2 · no public IPCPE 210.0.0.3 · no public IPCPE 310.0.0.4 · no public IPcarrierNATHelix NMS+manages all three directly

Splynx

Integrated, migrated, or both at once.

Helix speaks to Splynx over its API as a first-class integration rather than a CSV bridge. Connect an instance with a signature-auth key and Helix reads tariffs, customers, services and payments directly.

Automated migration runs in stages you control: import the tariff catalogue as plans, dry-run the subscriber migration and read the result before anything is written, then apply in cohorts filtered by tariff — so a corporate cohort and a residential one move separately, on different days.

Dual-mode operation is the part that matters during a real cutover. Splynx keeps billing and enforcement; Helix runs in observe mode, reading and reporting and refusing to cut anyone off. Every automated path that could suspend a subscriber consults that gate — including the paths that cut service by removing an account rather than by suspending it.

Placement is observed, not inferred: which router a subscriber sits on is determined from the routers themselves — a live session, or a per-client queue — never from an administrative field. A subscriber no device claims is refused by name rather than guessed onto a router, because a wrong device means that client cannot be suspended and their usage is read from somebody else’s queue.

Any subscriber both systems would invoice is named, with their Splynx service id, on every billing run — so the duplicate is a line in a report rather than a phone call from the customer.

Running alongside Splynx during a migrationSplynx keeps billing and enforcement while Helix reads subscribers, tariffs and payments over the API. Helix reports any subscriber both systems would bill and withholds its own enforcement until the operator hands it over.Splynxstill billingstill enforcingHelix NMS+reading · reportingenforcement withheldcustomers · tariffspayments read backDouble-billing detectornames every subscriber both systems would invoice

Billing

The money half is not an afterthought.

Recurring plans, ad-hoc invoices for installations and arrears, a cash desk, bank-statement reconciliation, credit notes, wallets, and dunning you configure rather than inherit.

Manual billing is first-class

Not every ISP collects by card. Raise an invoice by hand, take payment at the desk, paste a bank statement and see exactly what parsed before anything is written — a row that cannot be read is reported with its line number rather than silently dropped.

Five service models, provisioned properly

PPPoE, static public IP, DHCP reservation, dedicated VLAN and hotspot. Each writes the objects that service actually needs — a lease, an ARP pin, a shaping queue, a bridge VLAN entry — tags them as ours, and tears down only what it tagged.

Disconnection stays your decision

Automated suspension ships switched off. An organisation that has never chosen a policy is treated as not having chosen one, rather than as having agreed to a default — because a row nobody wrote is not a decision anybody made.

Outages can credit themselves

An outage the monitoring half observed can raise a credit note in the billing half, under a policy you set. With no policy configured it withholds rather than guessing: an issued credit is money off a ledger, and a withheld one is recoverable.

Currency is never assumed

An organisation states what it prices in before it can raise an invoice, and Helix refuses rather than defaulting. A default prints the wrong currency on a document that leaves the building.

Multi-tenant to the row

Every device, customer, plan and invoice belongs to exactly one organisation, checked on every request. Working across tenants needs an active agreement naming both parties — a pending one authorises nothing.

Built from the estate up

Written by people who had to run the fleet.

These are not design preferences. Each one is a defect that reached production somewhere and is now a rule.

RouterOS is two dialects wearing one name

Commands v7 accepts are refused outright by v6, and a v7-only integration silently does nothing on older hardware rather than failing loudly. Every device-facing change here is verified on both dialects, on real routers, before it ships.

Sessions are a scarce, shared resource

A router's API session limit defaults to 20 and is shared with the operator's own Winbox. Fleet operations run under bounded concurrency with one session per device, so a sweep can never lock you out of your own equipment.

Empty is not the same as unknown

A reading that could not be taken is shown as unknown, never as zero. Telemetry gaps render as gaps. A failed load says it failed rather than rendering an empty list that reads as "there is nothing here".

The device is the source of truth

A subscription is marked active only once the router confirmed it. If the device was unreachable, the intent is recorded and retried and the console says so — instead of showing a green status over a line that was never provisioned.

What is not settled yet.

Helix NMS+ is pre-GA and in live production use. Some capabilities are proven on real hardware across a live fleet; some are proven only in test. We publish the difference.

  • The features list on this site is filtered. It shows only what is built and reachable by a user. Unfinished and unreachable work is tracked under separate statuses and none of it is published there — so a capability on that page is one you can use.
  • Early access means early. IPAM and AI insight are built and hardened and have little production mileage. They are labelled that way here rather than counted as shipped.
  • Upcoming means not built. Agentic orchestration, Kronos and SD-WAN are designed and scheduled, not delivered. No date is printed on this page, because a date we cannot keep is worse than none.
  • Automated disconnection ships switched off. Turning it on across a live fleet is a decision with a support queue attached, and it stays yours.

See it against your own estate.

The most useful first conversation is a read-only look at your routers: what they run, what they expose to the internet, which of them could not be upgraded remotely today, and which subscribers your systems disagree about. Nothing is written to any device to produce it.