{"product_id":"router-no-wifi","title":"Router (no WiFi)","description":"\u003ch1\u003eAbout\u003c\/h1\u003e\n\u003cp\u003eThe RISC-V Router by Start9 makes advanced networking and network security accessible to everyone. Built on a RISC-V processor with an open-source boot stack and operating system, it is the most open router on the market, built specifically to accommodate the demands of self-hosting.\u003c\/p\u003e\n\u003cp\u003eContributions fund development of the router and the software. Units are expected to ship in September 2026.\u003c\/p\u003e\n\u003ch2\u003eKey Points\u003cbr\u003e\n\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eMaximally Open Source\u003c\/strong\u003e: The Start9 router is built on RISC-V — an open instruction set architecture — with a fully open-source boot stack (OpenSBI, U-Boot), open-source Linux kernel, and published board schematics.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eUser-friendly\u003c\/b\u003e: Unlike other routers, especially routers with advanced functionality, the Start9 router is accessible to non-technical users. Our modern GUI is easy to use and provides sane defaults for users who just want a plug-and-play experience.\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eStartOS-friendly\u003c\/b\u003e: StartOS users will be able to link their server to automate port forwarding for streamlined clearnet experience.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eHardware Specs\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cb\u003eProcessor\u003c\/b\u003e: \u003ca href=\"https:\/\/docs.banana-pi.org\/en\/BPI-F3\/SpacemiT_K1\" target=\"_blank\"\u003eSpacemiT K1 8-core RISC-V chip\u003c\/a\u003e\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eMemory\u003c\/b\u003e: 4GB LPDDR4 RAM\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eStorage\u003c\/b\u003e: 16GB eMMC\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eEthernet\u003c\/b\u003e: 1 WAN Gb, 1 LAN Gb\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eSoftware Stack\u003cbr\u003e\n\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan style=\"color: rgb(0, 0, 0);\"\u003e\u003cb\u003e\u003cspan style=\"font-family: Inter, Twemoji, 'Apple Color Emoji', 'Segoe UI Emoji', Arial, Helvetica, sans-serif, 'Noto Color Emoji'; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: -0.132px; text-align: start; text-indent: 0px; text-transform: none; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; display: inline !important; float: none;\"\u003eOpenSBI\u003c\/span\u003e\u003c\/b\u003e\u003c\/span\u003e: a firmware layer in the boot process, providing runtime services from the machine mode (M-mode) to the supervisor mode (S-mode) kernel, abstracting platform-specific hardware details and making operating systems more portable across different RISC-V systems. \u003ca href=\"https:\/\/github.com\/riscv-software-src\/opensbi\" target=\"_blank\"\u003eLearn more\u003c\/a\u003e.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eStartWRT\u003c\/b\u003e: Start9's fork of \u003ca href=\"https:\/\/openwrt.org\/about\" target=\"_blank\"\u003eOpenWrt\u003c\/a\u003e, including a modern GUI, that reimagines the router experience from first principles.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"\u003eOpen Source: What Is and Isn't\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cb\u003eWhat is open\u003c\/b\u003e: The RISC-V instruction set, board schematics, boot stack (OpenSBI + U-Boot), Linux kernel, and the OS.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWhat's closed:\u003c\/strong\u003e the WiFi radio firmware — true of \u003cem\u003eevery\u003c\/em\u003e WiFi 5\/6 card; there is no open-firmware option for modern WiFi from \u003cem\u003eany\u003c\/em\u003e manufacturer. There are two early boot binaries (DRAM initialization and the first-stage bootloader) that execute once at startup and are closed; open-source replacements are in progress.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003ch1\u003eFeatures of StartWRT\u003c\/h1\u003e\n\u003ch2\u003eSecurity Profiles\u003c\/h2\u003e\n\u003cp\u003eEvery device on the network receives a Security Profile, which determines its permissions on the network, including:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eWhich other devices on the network it can see\u003c\/li\u003e\n\u003cli\u003eWhat DNS servers it uses\u003c\/li\u003e\n\u003cli\u003eWhat access it has to the Internet: all, none, IP whitelist, IP blacklist\u003c\/li\u003e\n\u003cli\u003eHow it accesses the Internet: direct, or using a VPN (or VPN chain)\u003c\/li\u003e\n\u003cli\u003eWhen WiFi is available\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003ePoints of Entry\u003c\/span\u003e\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003e\u003c\/span\u003e\u003c\/span\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eHow a device joins the network determines the Security Profile it receives. There are three ways a device can gain access to a network:\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eEthernet: \u003c\/span\u003e\u003c\/span\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eeach port maps to a different Security Profile. Note that this device has 1 built-in LAN port but comes with a 4-port switch that will inherit its Security Profile for connected devices.\u003c\/span\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eWiFi: each password maps to a different Security Profile.\u003c\/span\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eVPN: each server maps to a different Security Profile. See \"Inbound VPNs\" below.\u003c\/span\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eWiFi (Identity PSK)\u003c\/h2\u003e\n\u003cp\u003eIf you choose to add a WiFi module to your router...\u003c\/p\u003e\n\u003cp\u003eInstead of a \"primary\" network and a \"guest\" network, StartWRT uses Identity PSK to provide a single network with multiple passwords, each leading to a different Security Profile. For example, when a guest comes to visit, they connect using the \"guest\" password, which leads to the \"guest\" Security Profile, restricting what they can see on the network and forcing their Internet traffic out through a specific VPN.\u003c\/p\u003e\n\u003ch2\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eInbound VPNs\u003c\/span\u003e\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003eCreate as many Inbound VPN Servers as you need for personal or shared remote access to the home network. Like Ethernet ports and WiFi passwords, each VPN server leads to a different Security Profile.\u003c\/p\u003e\n\u003ch2\u003eOutbound VPNs\u003c\/h2\u003e\n\u003cp\u003eConnect as many, network-wide outbound VPN clients as you need for Internet privacy. Optionally chain VPN clients together to avoid consolidating activity with a single provider and achieve multi-jurisdictional resilience.\u003c\/p\u003e\n\u003cdiv style=\"text-align: left;\"\u003e\u003cimg src=\"https:\/\/cdn.shopify.com\/s\/files\/1\/0256\/9551\/8786\/files\/proxies_240x240.jpg?v=1788489458\" alt=\"\" style=\"float: none;\"\u003e\u003c\/div\u003e\n\u003cp\u003e\u003cb\u003eExample\u003c\/b\u003e. Mark has accounts with Mullvad VPN and Proton VPN. Whenever he makes a request to the Internet, it goes through Mullvad VPN, then through Proton VPN, then to the final destination. This ensures neither Mullvad nor Proton knows his Internet activity unless they collaborate with each other.\u003c\/p\u003e\n\u003ch2\u003e\n\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eWiFi Blackout Schedules\u003c\/span\u003e\u003c\/span\u003e\u003cbr\u003e\u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003e\u003c\/span\u003e\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp\u003eIf you choose to add a WiFi module to your router...\u003c\/p\u003e\n\u003cp\u003eOptionally power down the WiFi radio on a schedule. e.g. disable WiFi from 10pm-7am in order to prevent WiFi usage or to limit \u003cspan class=\"ILfuVd\" lang=\"en\"\u003e\u003cspan class=\"hgKElc\"\u003eradiofrequency EMF exposure.\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003eHelp Mode\u003c\/h2\u003e\n\u003cp\u003eToggle \"Help Mode\" to get a detailed explanation of everything in the current view, including links to external resources. Toggle again to make it disappear.\u003c\/p\u003e","brand":"Start9 Labs","offers":[{"title":"Default Title","offer_id":45152309149762,"sku":"router-single-wired","price":270.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0256\/9551\/8786\/files\/router-2.png?v=1788489661","url":"https:\/\/store.start9.com\/products\/router-no-wifi","provider":"Start9 Labs","version":"1.0","type":"link"}