Structural Precision
Built for
Meraki Natives.
NET Backup Vault is an API-native ecosystem engineered specifically for the Cisco Meraki Dashboard, ensuring 100% config fidelity with every operation.
Granular Restore
Surgically recover from accidental deletions or misconfigurations at the individual feature level without affecting the rest of your environment.

Target Vector 01
Adaptive Drill-down
Navigate through 19 configuration types from Security Appliances to Wireless profiles with precise API mapping.
Target Vector 02
Selective Integrity
Pick specific firewall rules or SSIDs. Our engine calculates all dependencies to ensure a clean sync.
Target Vector 03
API-Native Sync
Pushes changes directly via Meraki API v1. Verify final state against vault checksums in real-time.
Atomic Restore
Eliminate the risk of partial failures. Every restore is wrapped in a fail-safe rollback engine.

Target Vector 01
Pre-flight Check
We capture a point-in-time snapshot of your current state before making a single change.
Target Vector 02
All-or-Nothing
Batched operations. If step 9 fails, steps 1 through 8 are automatically reverted in seconds.
Target Vector 03
State Verification
Final post-restoration audit confirms live config matches intended vault data exactly.
Automated Backups
Define your retention, set your frequency, and let our engine manage your Meraki history on autopilot.

Target Vector 01
Interval Precision
Schedule backups down to 15-minute windows for mission-critical orgs.
Target Vector 02
Retention Logic
Auto-archiving and pruning policies keep your storage costs optimized without losing critical history.
Target Vector 03
Drift Detectors
Get real-time alerts when your live Meraki environment drifts from your last protected version.
NET Backup Vault
vs alternatives
Most Meraki estates are protected by one of three things: the Dashboard on its own, a script somebody wrote, or a tool built for equipment you can SSH into. Here is what each of them does on the day a configuration has to come back.
Scroll to compare
| Capability | NET Backup Vault | Meraki Dashboard alone | Your own API scripts | General config-backup tools |
|---|---|---|---|---|
| Getting the configuration out | ||||
| Point-in-time copy of a whole organization The Dashboard keeps a change log, which records what changed, not the state to go back to. Scripts can capture it, if someone writes and keeps maintaining them. Multi-vendor tools reach devices over SSH or TFTP, and Meraki offers no such surface. | Available | Not available | Partial, or only if you build it | Not available |
| Scheduled capture, and capture triggered by a change The scheduler is the easy half of a script. Noticing a change and reacting to it is the half that gets dropped. | Available | Not available | Partial, or only if you build it | Partial, or only if you build it |
| Coverage measured against Cisco's published API surface | Available | Not available | Not available | Not available |
| Alerts when Cisco adds or retires an endpoint The failure nobody sees coming: a backup that still succeeds every night while quietly no longer covering a feature Cisco shipped last month. | Available | Not available | Not available | Not available |
| Getting it back | ||||
| Restore an entire organization | Available | Not available | Partial, or only if you build it | Not available |
| Restore a single network, or a single feature Granularity is where a do-it-yourself restore stops. Writing the capture is a weekend. Writing a restore that puts back one SSID without touching the other forty is not. | Available | Not available | Not available | Not available |
| All-or-nothing restore, rolled back automatically on failure A restore that fails at step nine of twelve leaves the network in a state that matches no backup you hold. | Available | Not available | Not available | Not available |
| Safety snapshot of the target, taken before anything is written | Available | Not available | Not available | Not available |
| Dry run, and a pre-flight compatibility check | Available | Not available | Not available | Partial, or only if you build it |
| Trusting what you hold | ||||
| Per-file SHA-256 manifest, verifiable on demand Without it, a backup is a file you hope is intact. With it, you can prove it. | Available | Not available | Not available | Partial, or only if you build it |
| Structural diff between any two points in time The change log answers who changed something. A diff answers what the configuration actually looked like before and after. | Available | Partial, or only if you build it | Not available | Partial, or only if you build it |
| Full-text search inside every stored backup | Available | Not available | Not available | Partial, or only if you build it |
| Running it for more than one organization | ||||
| Tenant isolation, per-tenant roles, whitelabel branding The Dashboard has organization switching and roles. It has no notion of your customers as separate tenants of your business. | Available | Partial, or only if you build it | Not available | Partial, or only if you build it |
| Backups held in your own storage: Azure Blob or S3 The one row where writing it yourself genuinely wins, because it is your disk either way. NET Backup Vault gives you the same choice without the maintenance. | Available | Not available | Available | Partial, or only if you build it |
| Self-hosted or private-cloud deployment, in a region you choose | Available | Not available | Available | Partial, or only if you build it |
| Immutable, integrity-hashed audit log over backup and restore Meraki audits changes made in the Dashboard. Nothing outside NET Backup Vault audits the backups themselves. | Available | Not available | Not available | Partial, or only if you build it |
16 capabilities, compared against approaches rather than named products, using Cisco's published Dashboard API documentation and the Meraki Dashboard's own documented behaviour as of September 2026. Cisco and Cisco Meraki are trademarks of Cisco Systems, Inc. NET Backup Vault is an independent product, not affiliated with or endorsed by Cisco.
Every capability,
in one place
56 capabilities across capture, integrity, restore, versioning, security, tenancy, storage, and operations. Everything below ships today.
Backup capture
10- On-demand backups
- Scheduled backups with full cron precision
- Backup on change, auto-triggered
- Live backup progress streaming
- Per-API-call outcome tracking
- Completeness verdict on every backup
- Failed-call resilience: one error never voids a run
- Live API coverage measured against Cisco's spec
- Cisco API drift alerts when endpoints are added or retired
- Meraki API version recorded on each backup
Integrity and proof
4- Per-file SHA-256 integrity manifest
- On-demand verification: missing, modified, tampered
- Verification of archived and offloaded backups
- Encrypt-then-verify round trip on every backup
Restore and recovery
11- Full-organization restore
- Network-level restore
- Granular per-feature restore
- Restore to a different existing network, compatibility-checked
- Pre-flight validation before restore
- Dry-run restore
- Atomic restore with per-feature checkpoints
- Automatic rollback when a restore fails
- Pre-restore safety snapshot of the target
- Itemized post-restore report
- Deleted-network recovery Partial
Versioning and visibility
5- Version history for every backup target
- Structural diff between any two backups
- In-app backup content viewer
- Full-text search inside backups
- Edit config files inside a backup, with edit history
Security and encryption
9- Encryption in transit and at rest
- Per-backup unique key, AES-256-GCM envelope encryption
- Master key held outside the database and config
- Meraki API keys stored encrypted
- Multiple API keys per user with instant switching
- Multi-factor authentication
- Single sign-on (OIDC and SAML)
- Role-based access control
- Immutable, integrity-hashed audit logs
Multi-tenancy and MSP
5- Multi-tenant data isolation, independently tested
- Per-tenant whitelabel branding
- Branded login pages per tenant
- Organization switcher with per-org roles
- Offboarding hook: revoking a member disables their schedules
Storage and residency
6- Self-hosted and private-cloud deployment
- Bring your own storage: Azure Blob or S3
- Norway as a backup location
- Regional data-residency choice
- Per-organization retention policy
- ZIP export of backups: single, batch, or all
Operations and alerting
6- Failure alerts by email, webhook, Teams, and Slack
- Backup activity log
- License inventory with missing-license drift tracking
- Device inventory
- Meraki activity-log sync and export
- Device firmware overview
Capabilities marked Partial are available with limitations. Ask us for the specifics that matter to your fleet.