SegAudit
Solutions

Who SegAudit is for.

SegAudit audits IT/OT segmentation on Palo Alto, Fortinet, Cisco and Check Point firewalls from a firewall config, with a traffic log adding proof of what is in use. Two kinds of team use it: consultants who assess other companies' plants, and firewall teams who audit their own.

Pick your starting point

The same engine either way

Consultants and plant teams load the same evidence and get the same analysis. What differs is who reads the result and how often the audit runs. Consulting deliverables, such as the proposal, readout slides and client pack, come with the consultant plans.

  • Traffic-backed findingsEvery finding is tied to the sessions the firewall logged and the rule that allowed them.
  • A change you can applyOrdered change windows with CLI, rollback and safety gates that protect production hosts.
  • Proof it workedThe next traffic log marks each plan Verified, Regressed, Not applied or No traffic.
  • Nothing leaves the workstationNo upload, no account, no telemetry, and no connection to the firewall.

Mapped to the frameworks you answer to

The compliance crosswalk marks controls in IEC 62443-3-3, NIST CSF 2.0, NIST SP 800-171 and CMMC Level 2, ISO/IEC 27001 and NIS2 as supported, partial or gap, from the same evidence, with NERC CIP, the TSA directives, the EPA water checklist, the US Coast Guard rule and UK NCSC CAF for clients in those sectors. It helps you assess segmentation controls; it does not certify compliance.

Start without a purchase

The Community edition is free: a full analysis of one plant, up to 2 firewalls. It opens on a three-plant sample, so you can see every step before exporting anything. Palo Alto Panorama, standalone PAN-OS firewalls, Fortinet FortiGate, Cisco ASA, Cisco FTD managed by FMC and Check Point are supported today; see firewall support.

Read next