Built for the networks that cannot take risks.
SegAudit makes traffic-backed IT/OT segmentation audits for Palo Alto, Fortinet, Cisco and Check Point firewalls. It runs offline on a jump host, reads a firewall config and the sessions the firewall logged, and writes the change window that closes the paths into the plant.
Why it exists
SegAudit exists because the tools that grade firewall rulebases cannot run where OT security matters most, and the tools that watch OT traffic do not write the firewall change. Plant teams and the consultants who audit them were left to join the two by hand, in spreadsheets, once a year.
Rulebase graders
Network security policy management platforms grade a rulebase. They cannot say which allows still carry traffic, and they are not built to run on an isolated jump host inside a plant.
OT traffic monitors
Tools that watch OT traffic show what is talking to what. They do not write the ordered firewall change, with rollback and safety checks, that closes the path.
What SegAudit adds
It reads policy and the sessions the firewall logged together, maps zones onto the Purdue model, and writes the change window that closes the gaps without cutting a live path.
Who it is for
Principles
These are design rules, not settings. They hold in every edition, free or paid.
- Runs air-gappedOne signed container on a jump host. It makes no network requests of its own: fonts and assets are bundled, and there is no update check.
- No telemetryNo analytics, crash reporting or usage data sent. The app counts seats and active days on your machine; we see those counts only if you upload them at renewal, after reading them.
- No uploadConfigs, traffic logs and engagement files are read in the browser and held in memory. The container has no database and never receives them.
- Evidence never leaves the jump hostReports, change packages and saved engagements are files you choose to save. They leave only if you send them.
- Files in, plans outNo collectors, no agents, no span port and no firewall credentials. The tool never connects to Panorama, FortiAnalyzer or a firewall.
- Evidence over opinionEvery finding points to the sessions and rules behind it, and every report lists what the evidence cannot see.
- Refuse to pretendIf a change would cut production, the tool says so and blocks the change window until it is safe.
- Your outputs are yoursPaid licenses are signed files checked offline. There is no kill switch, and saved engagements can always be opened and exported.
What the company holds
Because the product never sends your data to us, the company's own footprint is small. Here is what that means in practice.
What the company never holds
Firewall configurations, traffic logs and engagement files. None of them ever leave your workstation.
What the company does hold
Source code, the signing pipeline, and customer account and billing records, plus messages you send to sales and support.
How releases are signed
Release images are signed in CI with Sigstore keyless signing. There is no long-lived private key.
Where the detail is
The company security page lists each policy and its status, and the subprocessors page lists the vendors that touch account data.
How to reach us
| For | What it covers | Where to write |
|---|---|---|
| Sales and quotes | Prices, plans, trials, purchase orders and invoices. Trials and Plant edition quotes are self-serve. | sales@segaudit.com |
| Press | Logos, colors, product screenshots and boilerplate, free to download from the press kit. | sales@segaudit.com |
| Partners and firewall vendors | Consulting firms and firewall vendors. Ask to join the vendor waitlist if you want support for a platform other than Palo Alto, Fortinet, Cisco ASA and FTD, or Check Point. | sales@segaudit.com |
| Security | Vulnerability reports and the security pack for procurement reviews, shared under NDA. | security@segaudit.com |
| Privacy | Requests for a copy, correction or deletion of the personal data the company holds. | privacy@segaudit.com |
| Support | Help for customers, with response times by plan. | support@segaudit.com |
Please never send firewall configs, traffic logs or saved engagements to any of these addresses. For a security issue, follow the vulnerability disclosure policy rather than the contact form.