Network | SIMSY
Network Infrastructure

Enterprise-grade cellular infrastructure

SIMSY operates a cloud-native mobile core network with agreements across multiple carriers in over 140 countries. This is not resold carrier connectivity.

Global carrier network

Global Coverage

Agreements with multiple carriers in over 140 countries, providing access to approximately 600 networks worldwide.

Multi-Network UK

UK coverage across all major carriers with automated failover. No single carrier dependency.

Automated Failover

If a device's primary network degrades, the platform automatically switches to an alternative carrier.

Multiple SIM Types

Physical SIM, eSIM (QR code delivery within minutes), and ruggedised IoT SIM for industrial environments.

Network technologies

4G LTE
3G
2G
NB-IoT
LTE-M
Data, SMS, and Voice

SIM-to-SIM private networking

Multiple devices join a shared private IP space. Traffic between them is reflected at the SIMSY network layer and never reaches the public internet. No VPN, no tunnels, no fixed IPs, no infrastructure beyond the SIM.

Each device gets a private IP from a configurable subnet
Devices communicate directly as if on the same LAN
Default-deny for external traffic: inbound connections blocked
Configurable per group, per device, per routing policy
Scales from 2 SIMs to enterprise fleets with no topology changes
No VPN, no tunnels, no fixed IPs required

Traffic segregation at the network layer

A single SIMSY SIM can simultaneously maintain multiple independent data sessions, each with a completely different APN, routing policy, IP address, and network configuration. Traffic is segregated at the cellular network layer, not by firewall rules or VLANs.

Vehicle example

Telematics on one APN (private VPN to data centre), OTA updates on another (strict firewall), infotainment on a third (rate-limited internet breakout). All three active simultaneously. A compromised infotainment system physically cannot reach telematics or OTA.

Industrial example

OT on a private SCADA-only APN (drop all other traffic at network layer), IT on a separate APN with internet for firmware updates and remote management.

Network identity as authentication

Every SIM has a network identity. The SIMSY Edge API is called from the device over its cellular connection. The network identifies the calling SIM session and returns data scoped to that device. No tokens required. Devices retrieve their complete identity and configuration at boot, and write sensor data, status, and heartbeats back to the network.

Direct cloud transit

Wireguard (Active)

SIMSY routing policy sends traffic through a Wireguard tunnel terminating on EC2 in AWS (or Azure, GCP). SIM device traffic enters the cloud VPC privately with no internet transit.

AWS Direct Connect (Roadmap)

Direct Connect into AWS eu-west-2 (London). Up to 50 customer VPCs from a single SIMSY Direct Connect. Regulatory-grade private connectivity.

Cloudflare Zero Trust Integration

SIM-connected devices authenticate to Cloudflare Access-protected services using Service Tokens stored in the SIMSY KV store. WARP Connector and cloudflared on Teltonika enable LAN device access through Cloudflare Tunnel with full SSO.

URL locking and IP whitelisting

URL locking restricts device communication to approved endpoints only
IP whitelisting ensures only authorised addresses can communicate
Configurable per device, per group, per routing policy

Talk to us about network requirements

Tell us about your deployment and we will design the right network architecture.