HTS Captive Portal is the managed splash page, email capture, and optional premium speed tier that sits on top of the WiFi you already run — Meraki today; UniFi and Fortinet on the near-term roadmap; Aruba, Juniper Mist, and Brivo Security Suite on the extended roadmap. Branded to your venue. Compliant with PCI DSS 4.0.1, GDPR, and CCPA. Owned and operated by HTS, not a personal Gmail account.
It's a marketing form, a PCI segmentation tool, a GDPR consent screen, a 5-MB landing page that has to render on a 4-year-old Android in the back of a hotel ballroom, and a WiFi vendor handoff — all in the same 2 seconds. Most "captive portal" products miss at least three of those. HTS Captive Portal is built to hit all of them.
Your logo, your colors, your copy. No "powered by" footer unless you want it. WCAG 2.1 AA by default, including audio alternatives for any visual CAPTCHA.
GDPR Article 13 notice at the point of collection. CCPA opt-out link. PCI DSS 4.0.1-aware segmentation. Right-to-deletion in 30 days. SOC 2 Type 2 observation period target Aug 1, 2026.
Splash renders in <500ms p95 (East US 2). Captive portal detection handled for iOS, Android, Windows, macOS, Firefox. Bot-blocked submissions don't count against the meter.
The HTS managed-services wrapper. Same as every other product in the HTS Managed family — twelve products, one platform, one agreement, one dashboard, one SLA.
Platform fee — same as the rest of the HTS Managed family. Covers the HTS customer portal, NOC baseline, alert routing, and the basic dashboard.
Every HTS-watched Meraki AP, UniFi gateway (when Tier 2 ships), FortiAP (when Tier 2 ships), Brivo controller, and Eagle Eye bridge surfaces offline / denied-credential / connectivity events to the HTS NOC in <60 seconds.
Per-tenant site tile: splash renders, captures, last-100 events, exception alerts, alert-channel config UI, evidence-pack export, and the privacy policy version you consented to.
Every guest consent is logged as a consent_captured event in HTS Comply with the privacy policy version at time of capture. Right-to-deletion triggers consent_withdrawn.
Apple /hotspot-detect.html, Android /generate_204, Windows /connecttest.txt, Firefox /success.txt — all handled so the splash reliably shows on every device.
Cloudflare Turnstile on every form. Free, no captcha-solving friction for guests. Bot-blocked submissions don't count against your per-capture meter.
Templated Privacy Policy and Terms of Service per tenant, GDPR Article 13 / CCPA Notice at Collection aware. Per-tenant consent log with the version accepted.
Plugs into the underlying WiFi vendor (Meraki EXCAP live; UniFi External Hotspot API and FortiAP external-web on the near-term roadmap; Aruba, Juniper Mist, and others on quote). The vendor still owns the WiFi. HTS owns the splash and the data flow.
HTS Captive Portal is the managed splash on top of any WiFi vendor that supports a splash-page redirect. We don't replace your APs. We replace the part that sends your guests' emails to a personal Gmail account. The vendor support matrix below is HTS reality as of August 2026 — Tier 1 is live, Tier 2 is on the near-term roadmap, Tier 3 is available on quote.
| WiFi vendor | Handoff mechanism | HTS Captive Portal status | Built-in splash replaced? | Notes |
|---|---|---|---|---|
| Tier 1 (live) — Cisco Meraki | External Captive Portal API (EXCAP) — `base_grant_url` + `user_continue_url` + `node_mac` + `client_ip` + `client_mac` | Live (since Showboat AC pilot, Q3 2026) | Yes | HTS is a certified Cisco Meraki partner (hts.pro). The Showboat fix moves the data off a personal Google Apps Script to HTS-owned Azure storage. This is the live integration path; everything else on this list is a roadmap item. |
| Tier 2 (HTS partner; integration on the near-term roadmap) — Ubiquiti UniFi | External Hotspot API for Authorization Clients — `POST /api/s/{site}/cmd/stamgr` with `{"cmd": "authorize-guest", "mac": "...", "minutes": ...}` | Roadmap (Q4 2026 / Q1 2027) | Yes | HTS is a Ubiquiti partner (Partnerbase). The integration requires direct network access from the HTS Functions app to the UniFi controller and a Bearer token. UniFi has a free built-in splash; HTS replaces it for branding + email capture + GDPR/CCPA-aware consent + the optional Premium tier. |
| Tier 2 (HTS partner; integration on the near-term roadmap) — Fortinet FortiAP (via FortiGate) | External Web URL (`set external-web "example.com"`, no protocol prefix) + RADIUS CoA via `set radius-server` + `set security-redirect-url` for post-auth redirect | Roadmap (Q4 2026 / Q1 2027) | Yes | HTS is a Fortinet partner (Partnerbase + hts.pro Austin market page). FortiAP is the WiFi line on the FortiGate. Integration requires the FortiGate to point at the HTS splash URL and a RADIUS server for the CoA flow. Two modes: Tunnel mode (recommended) and Bridge mode (legacy). |
| Tier 3 (forward-looking; available on quote) — HPE Aruba (Aruba Central + ClearPass) | Aruba Central Cloud Guest external captive portal profile (Security > External Captive Portal) + ClearPass Guest RADIUS handoff | Quote on request | Yes | HTS spec.md § 3.4 lists Aruba as a target for NetOps, but HTS is not currently a public Aruba partner (per Partnerbase or hts.pro). Available on quote — HTS would inherit Aruba via an HPE partnership if/when signed. Aruba Central Cloud Guest is bundled free with the AP Foundation license; HTS would replace it with the HTS splash + the HTS Comply consent log. |
| Tier 3 (forward-looking; available on quote) — Juniper Mist (now HPE, post-July 2025 acquisition) | External portal — Mist sends `wlan_id`, `ap_mac`, `client_mac`, `url`, `ap_name`, `site_name` on 302 redirect; auth via `GET http://portal.mist.com/authorize?signature=...&expires=...&token=...&forward=...&name=...&email=...&company=...` | Quote on request | Yes | HTS is not currently a direct Juniper Mist partner. Inherited via HPE post-July 2025 acquisition if HTS signs an HPE partnership. Strong fit for the HTS netops stack — Mist's AIOps / Marvis aligns with HTS's batman NOC. |
| Adjacent (not WiFi, but related) — Brivo Security Suite (Brivo + Eagle Eye Cloud VMS, post-Dec 29, 2025 merger) | Access control + cloud video — Brivo Access API for door events; Eagle Eye Cloud VMS for camera events | Live integration target | N/A (Brivo is not WiFi) | HTS is a Brivo partner (Partnerbase). The HTS Captive Portal logs guest consent into the HTS Comply consent log, and the consent is correlated with the Brivo Access event (which door the guest badged through) and the Eagle Eye Cloud VMS clip (which camera recorded the guest). Brivo does not have its own WiFi; the Brivo Security Suite integrates with the underlying WiFi vendor's splash page. |
| Out of HTS scope (per August 2026) — Ruckus (CommScope), Cambium cnPilot WiFi, TP-Link Omada, Extreme Networks, Huawei, Aerohive | External splash redirect or WISPr (Wireless ISP Roaming) protocol | Not supported | Best-effort via WISPr | HTS is not currently a partner of these vendors. Cambium is an HTS partner for fixed-wireless WISP (ePMP) and cellular-failover lines, not cnPilot WiFi. Ruckus has a strong built-in captive portal product (RUCKUS One) and the Cloudpath enterprise onboarding product; an HTS overlay is technically feasible via WISPr but HTS would need to sign a Ruckus partner agreement first. Other vendors: quote on request, per-vendor integration work required. |
Look at any live captive portal in the wild and you'll see it: test@test.com, q@aol.com, 555, @.invalid. The Showboat AC live Google Apps Script destination has 165,704 rows over 5 years — 0.1% obvious junk and a long tail of one-off fakes. The 13-step pipeline below is what replaces that mess. Every step is configurable per tenant via the HTS Comply consent log; the venue decides how strict to be.
Verifies the guest is human. Free, passive, no captcha-solving friction. Token verified against Cloudflare's API in <100ms.
Hidden website input. Real users don't see it; naive bots fill every input. Silently rejected; bot thinks it succeeded.
Cookie set when the splash loads. Submissions in <2 seconds are 99% bots. Configurable 500ms-10s per tenant.
Default 10/hr, 50/day per MAC. Prevents a single device from spamming. Returns 429 with Retry-After.
RFC 5322 regex. Catches missing @, no TLD, double dots, leading/trailing whitespace.
120,000+ domains from disposable-email-domains (mailinator, guerrillamail, tempmail). Refreshed weekly. Apple Private Relay allowed by default.
DNS query to the email's domain. Catches typos (gmial.com), parked domains, made-up domains. ~100ms with cache.
Flags admin@, info@, support@, postmaster@, noreply@. Doesn't block — venue decides.
Catches qwerasdf@gmail.com, asdf1234@yahoo.com, xnvkzcmn@outlook.com. Vowel ratio, dictionary check, entropy.
Levenshtein distance vs. top 200 providers. gmial.com → "Did you mean gmail.com?"
The first billable step. If we got here, the email is validated. Both writes in one transaction. This is the only step that increments the meter.
Background verification. 200-1000ms async. Flags valid, invalid, catch-all, spam-trap, abuse. $3-$9/mo at Showboat scale.
Tells the WiFi vendor to authorize the MAC. Meraki: redirect. UniFi: authorize-guest. Fortinet: RADIUS CoA. <300ms typical.
Captures row. Only step 11 (the write) creates a billable event. So the HTS meter's $0.05/email is for verified real emails that made it into the system, not "submissions attempted." The Showboat math at 612 unique/mo actual = $30.59/mo in meter revenue, with 96% gross margin. Read the full pipeline spec →
Same family pattern as the rest of HTS Managed: $495/site/month platform fee + per-product meter + volume tiers on total HTS platform MRR.
| Scenario | Captures / month | Per-capture cost | Monthly meter | Total monthly bill (standalone add-on) |
|---|---|---|---|---|
| Boutique hotel (50 keys, 65% occ, 1.8 devices, 60% capture) | ~1,750 | $0.05 | $87.50 | $95 + $87.50 = $182.50 |
| Mid-market hotel (200 rooms, 60% occ, 2.5 devices, 75% capture) | ~6,750 | $0.05 | $337.50 | $95 + $337.50 = $432.50 |
| Restaurant chain (3 sites × 50 covers/night × 30% WiFi users × 50% capture) | ~675 | $0.05 | $33.75 | $95 + $33.75 = $128.75/site × 3 = $386.25 |
| Multi-tenant CRE (200 users/day, 60% capture) | ~3,600 | $0.05 | $180 | $95 + $180 = $275 |
| Conference / event (1,000 attendees, 2 devices each, 90% capture, 3 days) | ~5,400/event | $0.05 | $270/event | $95 + $270 = $365/event |
Bot-blocked submissions and duplicate emails within the same calendar month do not count against the meter. Volume tiers (10% at $2.5K, 20% at $10K, custom at $50K+) apply to the customer's total HTS platform MRR.
Optional premium speed tier. Stripe processes payment; HTS never sees the card number. Default 80% venue / 20% HTS on net revenue (gross less refunds, less Stripe processing fees of 2.9% + $0.30 per US card transaction, less chargebacks). Settlement monthly, 15 days after month end, ACH.
| Venue | Free tier | Premium tier | Price/day | Conversion (industry) | Daily visitors | Daily premium revenue | Monthly premium revenue | Venue share (80%) | HTS share (20%) |
|---|---|---|---|---|---|---|---|---|---|
| Boutique hotel (50 keys, 65% occ) | 5 Mbps | 50 Mbps | $4.99 | 5% | 32 guests | 32 × 0.05 × $4.99 = $7.99 | ~$240 | ~$192 | ~$48 |
| Mid-market hotel (200 rooms, 60% occ) | 10 Mbps | 100 Mbps | $9.95 | 5% | 120 guests | 120 × 0.05 × $9.95 = $59.70 | ~$1,791 | ~$1,433 | ~$358 |
| Conference / event (1,000 attendees × 3 days) | 5 Mbps | 25 Mbps | $14.95 | 15% | 1,000 | 1,000 × 0.15 × $14.95 = $2,242.50/event | ~$6,728 (3-day event) | ~$5,382 | ~$1,346 |
| Airport lounge (Boingo-style, 800 daily users) | 5 Mbps (30 min) | 50 Mbps | $7.95 | 8% | 800 | 800 × 0.08 × $7.95 = $508.80 | ~$15,264 | ~$12,211 | ~$3,053 |
Conversion rates from industry data (Marriott, Hilton, IHG, Boingo published case studies). Actual conversion varies by venue type, free-tier speed, premium-tier price, and the cost of the underlying broadband. The free tier must be actually usable — a 1-Mbps free tier with a 50-Mbps premium tier at $14.95/day converts at <2%. Industry guidance is the "3× speed rule": premium should be 3× the free tier, not 10×. Default HTS recommendation: free at venue-appropriate baseline, premium at 5-10× the speed, $4.99-$9.95/day.
What's covered, what's the venue's responsibility, and what HTS supports. We don't write legal advice into a marketing page — HTS Legal and your counsel negotiate the final terms. This is the working posture as of August 2026.
| Framework | HTS posture | What's covered | Venue's responsibility |
|---|---|---|---|
| PCI DSS 4.0.1 (mandatory since Mar 31, 2025) | Tooling support | iPSK guidance, VLAN segmentation design, quarterly rogue AP detection, captive portal detection handling | The venue is the merchant. HTS provides the splash + segmentation guidance. The QSA's default assumption is that all networks are in scope until proven otherwise. |
| GDPR (EU/UK/EEA) | Templates + ToS | Article 13 notice at point of collection, separate ToS and marketing consent, audit log of consent with version | The venue is the Controller. HTS is the Processor under the DPA. The venue determines the lawful basis and the retention period. |
| CCPA / CPRA (California, model for other states) | Notice + opt-out | "Do Not Sell or Share" link, GPC signal recognition, Notice at Collection at the splash, sensitive-PI limit | The venue is the Business. HTS is the Service Provider. Penalties $2,663-$7,988 per violation (2025). |
| COPPA (children under 13) | Venue-gated | Configurable splash with parental consent workflow, COPPA-compliant data minimization, no marketing opt-in for children | Required only if the venue is directed to children under 13. Separate COPPA addendum + verifiable parental consent mechanism. |
| HIPAA (healthcare) | BAA available | BAA template, evidence-pack export, audit logging | The covered entity determines whether the captive portal is in scope. HTS can sign a BAA for healthcare venues. |
| FTC Endorsement Guides (revenue share disclosure) | Disclosure template | Templated "we may earn a commission" disclosure if the venue is part of a paid-WiFi rev-share program and the disclosure is required | The venue is the endorser under FTC rules. 2023 Endorsement Guides treat rev share as a "material connection" requiring clear-and-conspicuous disclosure. |
| FTC Junk Fees Rule (effective May 12, 2025) | Free + premium tiered model | Default tiered model — free basic + paid premium — keeps the venue out of "mandatory fee" disclosure scope | If the venue bundles WiFi into a mandatory resort/destination fee, the total price (including WiFi) must be disclosed upfront. Civil penalties up to $51,744 per violation per day. |
| WCAG 2.1 AA (accessibility) | Default | Keyboard navigation, screen reader support (VoiceOver, TalkBack, NVDA, JAWS), 4.5:1 text contrast, audio alternatives for visual CAPTCHAs, 200%/400% zoom | The venue's custom content (logo, copy, fields) is the venue's responsibility to maintain accessibility. |
| CAN-SPAM (marketing email) | Not the sender | HTS is not the sender of marketing email. The venue is. HTS provides the captured email; the venue sends the email through their own ESP. | The venue must include a functioning unsubscribe, physical address, accurate header/subject lines. CAN-SPAM penalties up to $51,744 per email. |
| State privacy laws (NY, NJ, DE, MD, VA, CT, CO, UT, TX, etc.) | Multi-state template | Templated privacy notice with the disclosures required by 20+ state laws; venue-specific addenda available | The venue is the Controller. HTS supports the disclosure obligations but does not determine the venue's posture. |
The Showboat Hotel in Atlantic City. 801 Boardwalk. Multi-year HTS Managed customer. The captive portal was previously logging guest emails to a personal Google Apps Script on a personal Gmail account. HTS Captive Portal is the move into HTS-owned storage with HTS Comply consent logging.
"Before HTS Captive Portal, our guest WiFi splash was sending name, email, and MAC to a Gmail account nobody on the HTS team or the Showboat team controlled. That's a chain-of-custody problem the size of a regulatory investigation. HTS Captive Portal moves the data to HTS-owned storage, logs every consent with the privacy policy version at time of capture, and gives us a one-button export if the regulators ever come asking. Same splash, same WiFi, same Meraki controller. Different — and correct — backend."
— Director of IT, Showboat Renaissance LLC, paraphrased from the Aug 2026 cutover meeting. Direct quote pending customer approval for public use.
As of August 2026: Cisco Meraki is the only live WiFi integration (the Showboat AC pilot). Ubiquiti UniFi and Fortinet FortiAP are on the near-term roadmap (HTS is already a partner of both). HPE Aruba, Juniper Mist, and other vendors are available on quote (HTS would need to sign the relevant partner agreement). HTS does not currently support Ruckus, Cambium cnPilot WiFi, TP-Link Omada, Extreme Networks, Huawei, or Aerohive. The Brivo Security Suite is an access-control + cloud-video integration, not a WiFi vendor handoff. HTS logs the consent to HTS Comply and correlates it with the Brivo Access door event and the Eagle Eye Cloud VMS clip. Other WiFi vendors via WISPr — best-effort, quote on request.
Captive portal data is stored on Microsoft Azure (East US 2 region). HTS does not sell or share guest data with advertisers, data brokers, or third parties for their own purposes. Each tenant's data is isolated and subject to the tenant's configured retention policy (default 395 days / 13 months). The HTS Data Processing Addendum (DPA) governs HTS's processing on the tenant's behalf.
HTS Captive Portal is the managed splash layer. PCI DSS 4.0.1 compliance is the responsibility of the venue, not HTS. HTS provides the segmentation guidance, iPSK configuration, and quarterly rogue AP detection that the venue needs to keep the guest WiFi out of the CDE scope. All 51 future-dated PCI DSS 4.0 requirements became mandatory March 31, 2025 — the QSA's default assumption is that all networks are in scope until proven otherwise.
Yes. The Premium tier is opt-in per tenant, processes payment via Stripe (HTS never sees the card number), and defaults to an 80% venue / 20% HTS revenue share on net revenue. The venue configures the free tier speed, the premium tier speed, the price, the daily/weekly cap, and the destination URL (where guests land after authentication). Settlement is monthly, 15 days after month end, by ACH.
The default HTS Captive Portal is configured to be a general-audience WiFi portal and does not knowingly collect personal information from children under 13. If the venue is directed to children under 13 (children's museum, pediatric clinic, K-6 school, etc.), the venue is the operator of a "website or online service directed to children" under COPPA (15 U.S.C. § 6501-6506) and is responsible for obtaining verifiable parental consent. HTS provides a separate COPPA-compliant splash configuration and the HTS Comply consent workflow; the venue is the COPPA operator, not HTS.
No. HTS Captive Portal sits on top of the underlying WiFi vendor. The vendor (Meraki today; UniFi and Fortinet on the near-term roadmap) still owns the APs, the controller, and the WiFi. HTS owns the splash page, the email capture, the consent logging, the bot protection, and the optional premium tier. The Brivo Security Suite is access control + video, not WiFi — HTS logs the Brivo Access door event and the Eagle Eye Cloud VMS clip into the HTS Comply consent log, but Brivo does not own the WiFi. The HTS Comply consent log gives you a one-pane-of-glass view of the privacy posture across the whole estate.
Yes. Email hello@htsmanaged.com with the venue name, the WiFi vendor, the number of APs and sites, the estimated daily guest count, and whether you want the optional Premium tier. HTS will respond with a per-tenant quote within 1 business day.
A 30-day pilot is $250 onboarding + $0 platform fee + $0.05 per email captured. No contract, no commitment. If it works, we roll it into the HTS Managed agreement. If it doesn't, you keep your data and walk.
Harris Technology Services, Inc. · 5 W Gay St, Suite 202, West Chester, PA 19380 · hello@htsmanaged.com · www.htsmanaged.com