FirewallIQ Secure validates firewall configurations, exposes hidden gaps, and produces evidence auditors actually accept — without exploiting, evading, or touching a single byte on your systems.
| Host | Port | Observation |
|---|---|---|
| 10.20.0.14 | 443/tcp | TLS 1.3 · valid cert |
| 10.20.0.14 | 3389/tcp | RDP — exposed externally |
| 10.20.0.7 | 161/udp | SNMPv2c · default community |
| 10.20.0.7 | 22/tcp | SSH 8.9 · auth disabled probe |
| 10.20.0.21 | 23/tcp | Telnet — insecure protocol |
| 10.20.0.21 | 8443/tcp | Admin panel · TLS 1.0 |
The problem
Perimeter security degrades silently. Every change adds entropy. Every audit cycle exposes the same gaps — discovered too late.
One emergency any-any rule lives forever. Shadow rules accumulate. Nobody reviews 8,000 lines of config every quarter.
An admin panel briefly opened for a vendor never closed. Telnet on a forgotten device. SNMP with public community on a printer VLAN.
The diagram says PCI is isolated. The reality is one misconfigured NAT and a forgotten east-west allow rule.
PCI Q4. ISO recertification next month. You need evidence, not opinions — and you need it now.
The approach
FirewallIQ Secure is built for the team that has to prove the perimeter works — not the team trying to break it. Three principles are wired into the platform, not bolted on as policy.
Authorized
Every scan is bound to a signed scope. No scope, no scan. No exceptions.
Non-destructive
Reachability and configuration only. We never exploit, brute-force, or modify your systems.
Auditable
Findings carry hash-chained evidence. Reports are signed. Audit log is append-only and exportable.
From scan request → audit-ready finding
Scope is signed by your security lead
An Ed25519-signed document defines what IPs and domains are in-bounds. Scope is the contract.
Scan is approved and rate-limited
Production scope requires dual approval and step-up MFA. Rate is capped per the safety profile.
Workers run with safety compiled-in
Each worker refuses jobs that don't match its signed safety profile. Offensive primitives aren't in the binary.
Evidence is hashed and chained
Every banner, screenshot, and probe is written to a WORM evidence vault with a tamper-evident hash chain.
Findings map to your frameworks
PCI 1.2.1, ISO A.8.20, NIST PR.AC-05, CIS 4.4 — auto-mapped, with the rationale auditors expect.
The platform
Each module is purpose-built and rate-limited. Together they answer the one question that matters: is the perimeter actually doing what we said it does?
Nmap, naabu, and custom safe probes map open ports, services, banners, and protocols across your authorized scope.
Parsers for Palo Alto, FortiGate, Cisco ASA, Check Point, pfSense, Juniper, SonicWall, Sophos. Detects any-any, shadow rules, missing egress.
Verifies which services are externally reachable. Flags exposed RDP, SMB, SNMP, Telnet, weak TLS, expired or default certificates.
Multi-vantage TCP handshake probes prove which zones can — and can't — talk. Violations against your declared policy are surfaced immediately.
Object-locked storage with a tamper-evident hash chain. Every finding is replayable for audit, with full chain-of-custody.
CVSS base score × business context. Mapped to MITRE ATT&CK, CIS Controls, PCI-DSS, ISO 27001, NIST CSF, GDPR, and DPDPA.
Executive, technical, and compliance reports in PDF, DOCX, JSON, CSV, or HTML — all cryptographically signed and verifiable.
Claude-powered explanations, natural-language queries over findings, and remediation guidance grounded in vendor docs and CIS benchmarks.
How it works
Your security lead authors a scope — CIDRs, domains, exclusions, validity window — and signs it with Ed25519. No scope, no scan.
Engineers create a scan request bound to the scope. Production-touching scans require dual approval and step-up MFA.
Workers run with a signed, compiled-in safety profile. Discovery, exposure, segmentation, and rule analysis — all non-destructive.
Findings are scored, mapped, and persisted with hash-chained evidence. Export signed reports — PDF, DOCX, JSON, or HTML.
The safety promise
Offensive primitives aren't in our worker binaries. The safety profile is compiled-in, signed, and verified at startup — there is no runtime flag to flip.
Compliance
Every finding category is mapped — by us, reviewed annually — to the controls in every framework you care about. CI gates ensure no category ships without a complete mapping.
Requirements 1, 2, 10, 11
Annex A — A.8, A.12, A.13
PR.AC, PR.PT, DE.CM
AC, SC, SI families
Controls 4, 12, 13
Article 32 — security of processing
Section 8(5) — safeguards
SOC 2 mapping
Coming in v2
Built for the team
Defensible perimeter posture you can take to the board. A risk heatmap that doesn't need translation.
The platform you wished your scripts could grow into. Approved, repeatable, evidence-producing.
Findings already mapped to your framework, with hash-chained evidence and signed reports.
Multi-tenant, white-labelable, audit-grade. Deliver perimeter assessments at portfolio scale.
Why FirewallIQ Secure
We're the audit-grade, defense-only middle ground — repeatable, authorized, and built to produce the evidence your auditor actually wants.
| Capability | FirewallIQ Secure | Traditional pentest | DIY scripts | Generic scanner |
|---|---|---|---|---|
| Authorized, scope-bound by design | ||||
| Non-destructive — no exploitation, ever | ||||
| Immutable, hash-chained audit log | ||||
| Findings auto-mapped to PCI / ISO / NIST / CIS | ||||
| Vendor-neutral firewall rule analysis | ||||
| Segmentation validation across vantages | ||||
| Multi-tenant with 8-layer isolation | ||||
| AI explanations & natural-language query | ||||
| Continuous monitoring (scheduled, diffed) | ||||
| Repeatable evidence in days, not weeks |
covered · partial · not covered
Architecture
Stateless workers. Signed artifacts. Append-only audit. Tenant isolation in eight layers. Deployable as SaaS, dedicated, or on-prem (including air-gapped).
Edge
WAF · CDN · mTLS
API gateway
OIDC · RBAC · audit
Orchestrator
FSM · scope check
Workers
Go · safety-pinned
Data plane
Postgres · RLS · Redis
Evidence vault
WORM · hash chain
Tenant isolation
Token → app context → Postgres RLS → storage prefix → network policy.
Supply chain
Cosign-signed images. Admission verifies provenance. SLSA L3 target.
Observability
OpenTelemetry → Tempo. Loki for logs. Audit log → Kafka → WORM.
Frequently asked
A 30-minute demo on real findings. We'll walk through scope signing, a live scan, and a signed compliance report — all on a customer-style sandbox.
No credit card. No agent install. Authorized-only by design.