Who SegAudit is for.
SegAudit audits IT/OT segmentation on Palo Alto, Fortinet, Cisco and Check Point firewalls from a firewall config, with a traffic log adding proof of what is in use. Two kinds of team use it: consultants who assess other companies' plants, and firewall teams who audit their own.
Pick your starting point
OT security consultants
You assess a client's IT/OT segmentation and hand over the findings and the fix. Send the evidence request, load the client's files on your own workstation, and deliver the brief, report, change package, roadmap and follow-on proposal under your firm's letterhead.
Engagement $2,500 per engagement, or Professional $6,000 per named consultant per year.
For consultants →
Plant and corporate firewall teams
You run the firewalls between the office and the plants. Run the same audit every quarter on a jump host inside your network, change rules through your own CAB, and track maturity and open issues plant by plant.
Plant edition $2,000 per plant per year, minimum 2 plants.
For plant teams →
The same engine either way
Consultants and plant teams load the same evidence and get the same analysis. What differs is who reads the result and how often the audit runs. Consulting deliverables, such as the proposal, readout slides and client pack, come with the consultant plans.
- Traffic-backed findingsEvery finding is tied to the sessions the firewall logged and the rule that allowed them.
- A change you can applyOrdered change windows with CLI, rollback and safety gates that protect production hosts.
- Proof it workedThe next traffic log marks each plan Verified, Regressed, Not applied or No traffic.
- Nothing leaves the workstationNo upload, no account, no telemetry, and no connection to the firewall.
Mapped to the frameworks you answer to
The compliance crosswalk marks controls in IEC 62443-3-3, NIST CSF 2.0, NIST SP 800-171 and CMMC Level 2, ISO/IEC 27001 and NIS2 as supported, partial or gap, from the same evidence, with NERC CIP, the TSA directives, the EPA water checklist, the US Coast Guard rule and UK NCSC CAF for clients in those sectors. It helps you assess segmentation controls; it does not certify compliance.
Start without a purchase
The Community edition is free: a full analysis of one plant, up to 2 firewalls. It opens on a three-plant sample, so you can see every step before exporting anything. Palo Alto Panorama, standalone PAN-OS firewalls, Fortinet FortiGate, Cisco ASA, Cisco FTD managed by FMC and Check Point are supported today; see firewall support.
Read next
How it works
The steps from exported files to a verified change, and what the engine checks along the way.
Sample deliverable
The brief, report and maturity view built from the sample plant, before you install anything.
Features
Everything the tool does, from attack paths and remote access to the deliverables pack.
Trust center
Data flow, hardening and supply chain, for the security team that has to approve the tool.