Skip to content

Managed Receiver Service

rxnet

The signal firewall for monitoring centres.

rxnet is a hosted platform that sits between the systems sending you alarm and lone-worker signals and the monitoring platform you already run, Patriot or otherwise. It's built so you can separate signal delivery from signal processing without opening your network to do it.

For a monitoring centre, that boundary is the whole point. You keep what you already run, you keep control of what reaches it, and every signal on the way through gets validated, processed and, where you hold the key, sealed before it lands. Nothing about it asks you to trust a third party with a way in.

What it does

  • A signal firewall

    rxnet sits in front of your monitoring platform and checks every signal before it gets near it. Frontend ports can carry a bearer key that the receiver checks in constant time, and unkeyed ports are refused by default. Each payload is checked against the format the port expects before it's accepted; anything that doesn't match is rejected with a 400 and raises an alarm event of its own, rather than being passed through unexamined. A disabled port is refused before the body is even read.

  • One signal, several actions

    A signal doesn't have to just land and wait for you to notice it. rxnet's signal processor validates and structures every inbound payload, then runs the backend workflow built for that signal type. One provider can send several different payload types, and each is handled on its own terms. That workflow can carry out multiple actions for a single signal, defined to match how your centre needs that signal type handled. Your monitoring platform gets a signal that's already been made sense of, not a stream of raw payloads to sort out.

  • Encrypted until it's yours

    Where your organisation holds a sealing key, rxnet seals signals the moment they arrive. The platform holds only the public half of that key pair. It can seal a signal, but it can't open one. The private key is generated and held exclusively inside your environment; Broadstack never holds it, receives it, or sees it in transit. An on-premises decoder in your network is the only place a sealed signal becomes plaintext again.

  • More than a receiver

    rxnet doesn't stop at delivery. The web interface gives you a signal list, an individual signal view, a stream viewer and a system log, so you can see what's moving through the platform and how. Frontend ports carry scheduled reports, and an alarm watcher opens and closes alarms on its own, including when a port itself starts refusing traffic. You get management and reporting tools running alongside the monitoring, not bolted on afterwards.

  • One fixed way in

    rxnet runs in an environment Broadstack manages in Australia, kept separate from your own network. The on-premises delivery worker dials outward to the platform over a mutually authenticated link. There's no inbound entry point for anything on the other end to use. No third-party system, integrator or vendor gets a direct route into your monitoring centre network. The only door is the one you built, and it only opens outward.

Security starts before the signal arrives

rxnet sits in front of your monitoring platform, not beside it. Every signal that reaches it is checked before it goes anywhere near your monitoring software: validated against what a real payload from that port should look like, and, where a port carries a bearer key, checked against it in constant time. Get either wrong and the signal doesn't get through: a bad payload is rejected with a 400 and raises an alarm event of its own, and a disabled port is refused before Broadstack even reads what was sent.

None of that is the only layer. TLS termination, request size limits and per-source rate limiting sit in front of the receiver, a web application firewall sits in front of that, and the edge network handles reverse proxying and DDoS mitigation before traffic gets anywhere near Broadstack's infrastructure. Each layer does one job, and each one has to be satisfied before a signal reaches the next.

You don't have to build any of that into your own network to get it. rxnet gives your monitoring platform the benefit of a defended edge without asking you to run one.

Keep bad actors at arm's length

The safest thing your monitoring network can do with a third-party integration is not talk to it directly. rxnet gives every signal source a single, fixed address to deliver to, never a path into your network. The on-premises worker that pulls signals through does the connecting itself, dialling out to the platform over a mutually authenticated link. There's no inbound entry point on your side for anything to find, misuse or scan for.

Payload encryption pushes that distance further. Where your organisation holds a sealing key, rxnet seals a signal on arrival using only the public half of that key pair. The platform can seal; it can't open. The private key lives in your environment and nowhere else. Broadstack doesn't hold it, doesn't see it, and doesn't need to. A signal only becomes readable once it reaches the decoder inside your own network.

A vendor holding a direct line into your monitoring network is a liability whether or not anything ever goes wrong with it. rxnet removes the line altogether.

Do more than just receive signals

Receiving a signal and doing something useful with it are two different jobs, and most delivery paths only do the first. rxnet's signal processor validates and structures every inbound payload, then runs the workflow built for that signal. One provider can send several different payload types over the same port, and each one is handled on its own terms rather than dropped into your monitoring platform to sort out.

That processing shows up as tools, not just a pipe. The web interface gives you a signal list, an individual signal view, a stream viewer and a system log, so your team can see what's moving through the platform without waiting for it to land. Frontend ports carry their own scheduled reports, and an alarm watcher raises and clears alarms on its own, including when a port itself starts refusing traffic, which is exactly the moment you want to know about without a customer telling you first.

rxnet is built to sit in the path permanently, not just to hand signals off. The processing and the visibility come from the same platform, not a second tool bolted on afterwards.

Protect yourself from rogue AI agents

More of what talks to a monitoring platform now isn't a person. Third-party systems increasingly hand signal delivery to automated processes and AI agents that act on their own initiative, faster and more persistently than a human sender would. The real risk in that isn't a scripting error: it's a system that's been compromised, or one acting outside what it was built to do, using a legitimate connection to try to go further than it should.

rxnet's checks catch the everyday version of that: a malformed payload, or a request without the right key on a port set to require one, is rejected before it reaches your monitoring software, whoever or whatever sent it. A well-formed, correctly keyed request from a compromised or misbehaving agent would pass those same checks. Format and authentication aren't a judgement on intent, and we don't claim they are.

What actually stops that agent is having nowhere to go. The on-premises worker dials outward to the platform over a mutually authenticated link, and there is no inbound entry point into your network for anything on the other end to use. Whatever a rogue agent sends, and however well it's formed, it has no route from rxnet into your monitoring centre network. That protection comes from the architecture, not from rxnet reading minds.

Availability, residency and operational practice

99.99% platform availability
The hosted platform is covered by a 99.99% monthly availability commitment with service credits, set out in the Service Level Agreement. The on-premises component isn't included in this figure.
Australian data residency
Storage and processing stay within Australia, committed to in the Service Level Agreement. Access to that data is limited to personnel in Australia, enforced as a technical control.
You hold the only private key
Where encryption is enabled, the private key is generated and held exclusively in your environment. Broadstack never holds it, receives it or sees it in transit. Only your on-premises decoder can turn a sealed signal back into plaintext.
Daily vulnerability scanning
Broadstack scans its internet-facing systems and online services for vulnerabilities every day, and scans every dependency on every build. Remediation periods run by severity, starting at 48 hours for a critical finding on an internet-facing system.
Host-level detection and monitoring
Broadstack's hosts run managed detection and response, intrusion detection and prevention, file integrity monitoring and configuration assessment.
Direct incident notification
If a security incident is identified, Broadstack notifies your nominated security contact by email and by phone.

Documents

The rxnet agreement points to each of these by address. A published document states its version and the date it took effect.

Talk to us about rxnet

Tell us about your monitoring platform and your signal volumes. We'll walk you through where rxnet sits in front of it and what changes on your side.

Talk to Broadstack