General & Platform
COD – General Questions
The COD is a vendor-independent platform that brings your IT infrastructure together in one place — as a single source of truth. Rather than replacing siloed solutions, the COD connects your existing systems and centralizes their control, documentation, and reporting.
For IT departments and service providers that operate heterogeneous infrastructures spread across multiple sites and want to bring operations, documentation, and compliance together in one place.
The COD combines its own solutions with integrations. Capabilities such as NAC, backup, OTP, GRC, or virtual switch management are delivered as standalone, vendor-independent solutions. Existing third-party systems — such as directory services, monitoring, your CMDB/asset management, Baramundi, or firewalls — remain in place and are connected. You keep the mechanisms you know and gain central transparency and automation.
All modules are active by default and already installed out of the box — the only exception is our optional VAS module (Vulnerability Assessment).
We include the following as standalone, vendor-independent solutions: Network Access Control (NAC), backup/disaster recovery, OTP authentication, GRC (including NIS2 support), hypervisor management (for virtual switches), as well as network documentation and visualization (L2/L3 topology) including firewall and report management.
Through integrations, we also connect existing third-party systems: directory services, monitoring, your CMDB/asset management, and Baramundi.
The COD is delivered as containers and can run on-premises or in your own environment (including Docker and Kubernetes/Helm). Your data therefore stays within your infrastructure.
Because the COD runs in your own environment, your data stays under your control. Access is governed by roles and is logged. Data is held in dedicated databases, and site-specific data is stored separately per tenant/site.
Through role-based access control (RBAC). Permissions are assigned in fine-grained detail per module, role, and site. For sign-in, existing directory services can be connected via LDAP/Active Directory, and local accounts are supported as well.
Yes. The COD is multi-tenant and multi-site capable. Data and permissions are separated per site, and users can switch between the sites they are authorized for.
The GRC module digitizes the risk matrix, asset-based risk management, and policy and threat catalogs. Combined with the central asset and dependency context, the COD supports the evidence and documentation obligations under NIS2.
The COD is multi-vendor capable. In network management, it supports Cisco, HPE, Allied Telesis, Ruijie, and MikroTik, among others. Firewalls can be managed via OPNsense, pfSense, and AIMdefense. For NAC, PacketFence can be connected as an alternative. In addition, we connect directory services (LDAP/Active Directory), monitoring, your CMDB/asset management, and Baramundi. The goal is to operate with your existing, heterogeneous infrastructure.
Security is built in from the ground up: role-based access, optional two-factor authentication (OTP), encrypted storage of sensitive data, and end-to-end audit logs. Tenants are already separated at the database level. On-premises operation keeps data and access within your environment.
All modules are included in the base price — there is no separate licensing for individual modules. Only our VAS module (Vulnerability Assessment) is optional and comes at an additional cost. For a custom quote, contact us at info@extoco.de or +49 (861) 88 00 32 00.
Feature Overview
It covers the core features currently shipping, condensed module by module into one description per feature. We continuously maintain the complete, technically detailed picture — just ask about a specific project.
COD is modular: you license the modules you need. Which features belong to which module is shown above in the respective group, and the terms are listed on the Pricing page.
Yes. COD runs in your environment, and you retain full data sovereignty — a good fit for KRITIS and NIS2 requirements.
Integrations
No. COD talks to your existing systems through Connect integrations and consolidates their data instead of replacing them.
Through the REST-based bConnect interface: communication via JSON, secured over HTTPS with authentication and SSL. Inventory data is imported automatically and synchronized into your CMDB.
codPass can be run standalone today. Native integration into COD is in preparation. Browser plugins are not part of the product.
NIS2 & Compliance
COD delivers the technical building blocks that NIS2 requires — asset transparency, asset-based risk management, and gapless auditability. The specific legal assessment of your obligations remains with you or your legal counsel. COD is not a substitute for legal advice.
No. COD can run fully on-premises and is KRITIS-ready. Compliance data resides in a dedicated PostgreSQL database under your full control.
The GRC module works on the same assets that COD-Network detects and maintains automatically. Your risk assessment refers to the actual asset including its live status — not to an outdated list.
Pricing
These are non-binding list-price guide values (net, EUR/month unless stated otherwise). Your final price depends on the number of seats, hosting model, asset size, and service level — we will prepare a custom quote for you.
Entry starts at a minimum of 2 seats at €47.50 each plus a tenant fee starting at €8 (self-hosted). VAS and service packages are added as needed.
Yes — with a 36-month contract term, seats come with a 10% term discount. For very large environments (from 25,000 assets), we calculate individually.
Live Demo
If you like, yes. We demonstrate COD hands-on using scenarios from your environment — or with a prepared sample environment, whichever works best for you.
Yes. The live demo is free and without any obligation — no sales pressure.
Any that interest you: from Network & Assets to NAC, firewall & VPN, GRC, and monitoring, all the way to vulnerability management and backup. You set the focus.
Network & Access
Monitoring
That depends on the check interval, which you configure per tenant via a cron job. This lets you set the check frequency to suit each customer and site.
No. Per-firewall throttling prevents repeated alerts about the same issue, and you schedule planned maintenance centrally in the calendar, so monitoring does not trigger without reason.
Monitoring is built directly into COD as a module and uses the same data as your network inventory. Existing systems such as Zabbix can be connected through Connect integrations.
Network Access Control (NAC)
- Type: COD-native, vendor-independent NAC solution based on RADIUS
- Authentication: 802.1X (EAP with certificates), MAC authentication
- Access control: dynamic VLAN assignment (Tunnel-Private-Group-Id, Cisco-AVPair, Egress-VLANID), client groups with priorities, quarantine VLAN
- PKI: integrated certificate management for 802.1X (CA/leaf certificates, CRL, PKCS#12 export)
- Windows CA: alternatively, connect existing Windows CA environments in read-only mode (reads out existing certificates)
- NAS management: switches/access points with shared secret
- Logging: authentication and accounting logs (success/failure, sessions), connection statistics
- Import: CSV bulk import (MACs, VLANs, groups) with validation and conflict detection
- Device discovery: ping/monitoring polling and RADIUS events
- Alternatively connectable: PacketFence
A COD-native, vendor-independent solution for Network Access Control based on RADIUS. It controls and logs network access centrally in the COD.
Usually not. COD-NAC is multi-vendor capable and works with existing 802.1X- or MAC-capable infrastructure.
802.1X (EAP, with certificates) as well as MAC authentication.
Dynamically via RADIUS attributes. Client groups with priorities let you bundle rules, and non-compliant devices can be placed in a quarantine VLAN.
Yes. The CSV bulk import handles MAC addresses, VLAN assignments, and groups, including validation and conflict detection.
From the integrated PKI: creation of CA and leaf certificates, CRL management, and PKCS#12 export for distribution to clients.
Yes. As an alternative to the integrated PKI, an existing Windows CA environment can be connected. COD reads out the existing certificates in read-only mode and manages them centrally.
Yes. PacketFence can be connected as an alternative, and existing policies are preserved.
Through authentication and accounting logs (real time and history) as well as per-client connection statistics.
Captive Portal
No. Thanks to role-based delegation, reception or non-technical staff can handle guest management themselves, without admin rights and without an IT ticket.
It is automatically disabled and removed. Forgotten legacy accounts and permanently valid passwords are a thing of the past.
They are generated server-side according to current standards, with WPA2/3 and complexity requirements, optionally as one-time passwords. No one copies a password off a whiteboard anymore.
TACACS+ (Device Administration)
- Type: TACACS+ AAA server for administering network devices (authentication + authorization)
- Protocol: TACACS+ (port 49), RFC 8907; for switches, routers, firewalls, access servers
- Authorization: PERMIT/DENY rules, pattern-based command authorization, privilege levels 1–15
- RBAC: roles link user group ↔ device group ↔ authorization rule (different permissions per device)
- Crypto: Argon2id (passwords), AES-256-GCM (sensitive fields)
- Management: REST API, separate from the server daemon
- Operation: PostgreSQL, Python
Any TACACS+ client per RFC 8907 — such as switches, routers, and firewalls. The solution is not vendor-specific.
Yes. Through roles (user group × device group × rule), permissions can be assigned granularly per device group.
Yes. Command authorization works on a pattern basis.
As an Argon2id hash — not reversible.
For managing users, clients, groups, and rules — separate from the actual server daemon.
Levels 1 to 15, configurable per user.
Via an enabled flag. Disabled entries are skipped during evaluation.
Switch Automation
- Type: Automated switch configuration via Ansible
- Vendors: Allied Telesis (AWPlus), Cisco IOS, Ruijie (CLI fallback) — extensible
- Profiles: PORT (interface), AUTH (802.1X/AAA), VLAN (create/delete), PORT_ACTION (cable test, port restart)
- Security: credentials encrypted in the vault; automatic config backup before every change, selective restore
- Transport: SSH (libssh/paramiko), legacy algorithms for older devices
- Execution: asynchronous with task/result logging, tied into the COD audit
Allied Telesis, Cisco IOS, and Ruijie (via CLI fallback). Additional vendors can be added.
No. After the initial rollout, credentials are stored encrypted in the vault and reused.
A backup of the current configuration is created automatically. A restore to an earlier state is possible.
Yes, via profiles (PORT, AUTH, VLAN) directly from the COD.
Yes. Legacy algorithms (host key, key exchange, cipher) are supported, and paramiko is used when needed.
No. Only the individual interface is reset (shutdown/no shutdown), and the device stays in operation.
There is no lock. Requests are processed sequentially, and parallel manual CLI changes should be avoided in the meantime.
Security & Identity
Vulnerabilities (VAS)
VAS brings scans, severity distribution, remediation status, and trends into a shared, multi-tenant context on COD's live asset base — so findings become prioritized and trackable instead of just appearing as a list.
Findings are broken down by severity and presented so you immediately see where urgent action is needed — you work on the risk, not on the length of the list.
Yes. The vulnerability module is part of the modular COD platform, multi-tenant capable and fully operable on-premises — KRITIS-ready, with full data control.
OTP Authentication
- Type: COD-native, central OTP management
- Standard: TOTP (RFC 6238), SHA-1/256/512, 6–8 digits, 30-second interval
- Provisioning: QR code or manual entry; compatible with common authenticator apps (Google, Microsoft, Authy)
- Sharing: private (user-bound) or public tokens; group delegation for teams
- Recovery: six one-time backup codes per user
- Isolation: site-specific (separated per tenant)
- Integration: multi-factor sign-in and password reset in the COD
It manages time-based one-time passwords (TOTP) centrally — for multi-factor authentication, without credentials having to be shared among users.
Yes. It generates standard otpauth:// codes and works with any RFC 6238-compatible app.
Yes. Tokens can be shared across a team via groups, while private tokens remain bound to individual users.
Six one-time backup codes per user are available for sign-in.
Private tokens only the respective owner. Public or group tokens are visible to the members of the group as well as administrators.
Yes. All tokens and groups are isolated per site.
Through the COD's role-based access control and site isolation. Storage is in the secured database.
For multi-factor sign-in and securing the password reset.
codPass
Yes. codPass can be run standalone and operates fully independently as a dedicated password and secrets manager. Native COD integration is in preparation.
No. codPass currently does not offer browser plugins. Managing passwords, secrets, and OTP happens directly in the application.
Because openness builds trust: the source code and the security mechanisms are transparent and verifiable. For a secrets manager, that is a security and quality feature, not an afterthought.
Stronghold – Password Vault (coming soon)
Coming soon. Stronghold is in final development.
- Type: Zero-knowledge vault for passwords and secrets (end-to-end encrypted)
- Principle: The server stores only ciphertext. Plaintext, the master password, and private keys never reside on the server.
- Vaults: one personal vault per user, plus shared team vaults (roles: OWNER/MEMBER)
- Sharing: individual entries across users, with READ/WRITE permission and expiration date
- Recovery: one-time recovery code at setup
- Crypto: Argon2id (key derivation), X25519 sealed box (key wrapping), AES-GCM (entries), HKDF
- Sign-in: JWT (ES384) via the COD login, verified through JWKS
- Operation: PostgreSQL; reachable only through the COD proxy; rate limiting; tamper-proof audit log (HMAC chain)
No. The server holds only encrypted data. Without your master password — which exists only on the client side — that data is worthless even in a full database dump.
At setup you receive a one-time recovery code. It lets you restore access to your key and set a new master password.
Yes — either through a shared vault or by sharing individual entries (with permission and expiration date). Both are public-key encrypted.
The vault key is reissued for the remaining members, and the removed member loses access to future content.
No. The vault name is encrypted, and only the icon is stored in plaintext.
The recovery code restores access to your key (e.g., after a forgotten master password). The COD's regular backup protects against server-side data loss.
Through the COD login (JWT, ES384; verified via JWKS). The vault is reachable exclusively through the COD proxy.
Operations & Resilience
Backup & Disaster Recovery
- Type: COD-native, vendor-independent backup solution
- Target systems: all devices reachable via SSH (switches, firewalls, servers) as well as MariaDB/MySQL databases
- Methods: SSH command, SFTP file/folder, MariaDB dump
- Scheduling: cron per host or template
- Encryption: optional AES-256-CBC per host/template
- Retention: by count or age (days), automatic cleanup
- Comparison: diff view of two backup states
- Storage: local, optional mirroring to an SCP server
- More: jump host/bastion, pre-backup scripts, email alerts, disk-space monitoring, serial number check
Configurations of all devices reachable via SSH as well as MariaDB/MySQL databases. The solution is vendor-independent and extensible via OS templates.
Freely configurable via cron — per host or per template, e.g., hourly, daily, or weekly.
Optionally. AES-256-CBC can be enabled per host or template.
Configurable by count or age in days. Once the limit is reached, the oldest states are deleted automatically.
Yes. A diff view shows the changes between two versions line by line.
You receive an email alert with error details, and the host is flagged with ERROR status.
Yes. Optionally, backups are mirrored to an SCP server, including retention rules.
Yes, through a jump-host tunnel.
Backups can be downloaded through the interface. Restoring to the device is done manually with the usual tools.
Hypervisor Management (virtual switches)
- Type: Management of virtual switches (no VM or host management)
- Platform: VMware vCenter / ESXi
- Objects: vSwitches, port groups, VLAN IDs (0–4094), NIC teaming, security policies
- Functions: read inventory (datacenter → cluster → host → vSwitch → port group), create vSwitch, create/modify/delete port group
- Dry run: test changes in advance without risk
- Multi-host: operations across multiple hosts, result per host
- Interface: REST API, sign-in via vCenter account
Virtual switches and port groups on VMware. It deliberately does not control the lifecycle of VMs or hosts.
VMware vCenter and ESXi (via the VMware API pyVmomi). Other platforms such as Hyper-V or KVM are not supported.
Yes. Each port group is assigned a VLAN ID (0–4094).
Yes. All modifying calls support a dry-run mode that simulates changes without making them.
Yes. Active/standby/unused NICs as well as load balancing can be read and configured.
With vCenter credentials (host, user, password) in each call.
Yes. Operations accept a host list, and the result reports success or failure per host.
It provides the complete vCenter object tree as read access — for example, for dashboard views or documentation.