Questions people ask before they start

Use this page for objections, edge cases, and buying questions after you already understand the product, workflow, and sample output.

Questions people ask before they start

Product scope

What the platform is for

What is ConfigSentry?

ConfigSentry is a FortiGate-focused audit and reporting platform for reviewing firewall configuration risk, posture, and control gaps. It is designed to turn a FortiGate configuration into structured findings, remediation context, and report output for technical and governance audiences.

Which firewalls are supported?

ConfigSentry currently supports Fortinet FortiGate firewalls. The current support baseline documented in the product terms is FortiOS 6.4.5 and later, and the exact supported models and FortiOS versions are published on the Supported Platforms page in the knowledge base.

Does it support HA clusters?

Yes. The product and pricing are positioned per FortiGate firewall or cluster, so an HA pair or cluster is treated as one licensed review target rather than separate appliances for each member.

Does it support VDOMs?

Yes. VDOM-aware FortiGate configurations are supported in the audit workflow, and the runtime metadata used by the audit engine includes selected or detected VDOM scope for the run.

Does it support cloud-hosted FortiGates?

Yes, provided the FortiGate is otherwise supported and you can supply a valid configuration through manual upload, direct SSH retrieval, or an approved collector-based workflow.

Does it only review firewall rules?

No. Firewall policy is a major part of the review, but the platform also looks at management exposure, logging posture, segmentation-impacting access, objects, services, interfaces, and wider configuration signals that affect operational risk.

Who is it designed for?

It is designed for network engineers, firewall engineers, security engineers, consultants, and organisations that need clearer FortiGate review output, repeatable evidence, and less manual cross-checking before audit or remediation work.

Audits and reports

How review output works

Do I need to give ConfigSentry live firewall access?

No. You can start with a manual FortiGate configuration upload and run an on-demand audit without giving the platform live retrieval access first.

Can I use manual upload before deploying a collector?

Yes. Manual upload is the normal starting point for one-off audits and first evaluations because it lets you test the output against a real FortiGate configuration without deploying a collector first.

Does ConfigSentry support direct SSH retrieval as well as collectors?

Yes. The documented product workflows include manual upload, automated collection through an on-premise collector, and direct SSH auditing for supported appliances. That means a collector is useful for recurring review, but it is not the only way to retrieve a configuration.

Does ConfigSentry make changes to my FortiGate?

No. The platform is designed for read-only review and reporting. It analyses configurations and produces findings and reports, but remediation and production change remain under your own change-control process.

How does an audit start?

An audit can start from a manual upload, from direct SSH retrieval against a supported appliance, or from a collector-based workflow when you want scheduled or lower-touch recurring review.

What output do I get from one audit?

One audit produces prioritised findings plus both the engineer report and the executive report from the same audit run. The engineer view is intended for technical follow-up, while the executive view is intended for posture, priority, and governance conversations.

What happens if an audit fails or the configuration cannot be parsed?

The audit does not complete successfully. Depending on the failure reason, you may need to upload the configuration again, let the collector recollect it, or correct the input before retrying. If a queued audit cannot start because its temporary decrypt key is unavailable, the status may show retry required.

Does a failed audit consume a credit?

No. Failed audits do not consume a credit.

Can I export reports for audit evidence?

Yes. Engineer and executive outputs can be exported and used for review and evidence support, but they remain advisory outputs rather than a compliance certificate.

Can this replace engineer judgement?

No. Findings and reports are advisory outputs only. A qualified engineer still needs to validate findings and make remediation decisions.

What should I review next after this page?

Use the How It Works and Sample Reports pages for the workflow and output detail.

Security and data handling

Questions about trust and handling

Is the platform read-only?

Yes. The platform is designed for retrieval, analysis, and reporting, not for pushing configuration changes back to the firewall. That applies whether the audit starts from manual upload, direct SSH retrieval, or a collector workflow.

Is a Data Processing Agreement available?

A self-service Data Processing Agreement is not currently available during the early free trial. If your organisation requires a DPA or supplier security review before uploading production firewall configurations, please contact Secdit first.

Can I upload production firewall configurations during the trial?

Only if you are authorised to do so and your organisation is comfortable with the current trial terms. For early testing, we recommend using a lab, test, sample, or sanitised configuration where possible.

Can firewall configurations contain personal data?

They can, depending on how the firewall is configured. Configuration files may include usernames, email addresses, VPN identities, hostnames, IP addresses, comments, or other environment-specific information. Treat them as sensitive.

Do you store raw FortiGate configuration files?

For the normal hosted audit path, secret material such as passwords, private certificates, and keys is stripped before queueing. If a manual audit is run with "Do not save results on website" selected, the configuration is processed in memory only. See the Security and Data Handling page for the fuller handling path.

How long are raw configurations retained?

For the normal hosted path, the stripped configuration is generally processed within a few minutes and then removed from the queue database. The Security and Data Handling page covers the fuller retention context.

Can I delete audit data and reports?

Yes. Deleting audits, reports, or related account data removes them from the live database immediately. Periodic database backups may still retain deleted data for up to 30 days as part of normal resilience and recovery processes.

What data is retained after an audit?

Audit results, findings, reports, audit history, and related account metadata may remain as part of the service until deleted. Those outputs can still contain sensitive security information about the reviewed environment.

Do audits always start immediately?

Not always. Manual uploads, direct SSH retrieval, scheduled direct SSH runs, and collector-triggered audits can be queued when workers are busy or health limits delay processing. In that case the audit is accepted first and starts automatically when capacity is available.

What does retry required mean?

Retry required means the queued audit could not start because its temporary decrypt key was unavailable before processing began. In that situation you may need to upload the configuration again or let the collector or retrieval workflow collect it again.

Does account MFA matter?

Yes. MFA helps protect access to audit history and config-derived findings, especially in shared accounts. The current sign-up flow enables email-based MFA by default, and the application also supports TOTP as a backup MFA method.

Can collector secrets stay local?

Yes. The collector documentation states that where a setting is marked Enter Locally, the secret is intended to remain on the collector host instead of being stored as a website-managed secret value.

Where is ConfigSentry hosted?

ConfigSentry is hosted with Hetzner in Nuremberg, Germany.

Can I customise audit checks or templates?

Yes. Audit templates help control which checks run for a given review, so teams can manage the rule set used for a particular audit workflow.

Where should I look for detail?

Use the Security and Data Handling page for the trust model and handling summary, and the collector knowledge-base pages if your review needs host, network, or local-secret detail.

Pricing and trial

Questions about getting started commercially

Is there a free trial?

ConfigSentry is currently being offered as an early free trial. Every new account receives 2 included audit credits on sign up. Additional evaluation credits and licenses may be available during onboarding. The intended evaluation path is to run a FortiGate audit first rather than relying on brochure-only product claims.

What does one audit credit include?

One audit credit covers one full audit and produces both the engineer report and the executive report from that same audit run.

How do I choose between credits and a license?

Use audit credits for one-off review, spot checks, or pre-audit validation. Use licenses when you want recurring scheduled audits, collector-based retrieval, or faster ongoing monitoring in environments where configuration drift matters.

Is support included?

Yes. A support portal is available to help with product issues. There is no published SLA, but issues are worked on as soon as possible.

Do I need to commit before I test it?

No. The normal path is to create an account, run a real audit with included credits, review the findings and reports, and only then decide whether you need more credits or a recurring license.

Collector and compliance

Questions about recurring review

What is the benefit of the collector workflow?

It reduces reliance on manual exports and supports lower-touch recurring audit workflows. The collector documentation also supports scheduled collection and syslog-triggered collection when you want configuration-change events to trigger a targeted run.

Which collector platforms are supported?

The collector knowledge base currently documents supported collector workflows for Windows, Linux, and FreeBSD. Those guides cover host requirements, installation, local settings, service behaviour, and update workflows.

Do I still need a collector if I only want one audit?

Usually no. For a one-off review, manual upload or direct SSH auditing is the lighter starting point. A collector becomes more useful when you want scheduled retrieval, recurring review, or syslog-triggered collection inside your environment.

Is ConfigSentry a compliance certification tool?

No. Findings and reports can support control review and evidence gathering, but they do not by themselves certify compliance or act as a certification or assessor substitute.

Where should I look next?

Use Audit Models for operating fit, Security and Data Handling for trust detail, and Compliance Alignment if you want the governance-oriented view of how findings support control conversations.

Next step

If the main questions are answered, try it yourself

Start free when you are ready, or check pricing one more time before you decide.