Direct answers
Direct answers to the handling questions buyers usually ask first
What should evaluators know before uploading?
ConfigSentry is currently being offered as an early free trial. A self-service Data Processing Agreement is not currently available. Firewall configuration files can contain sensitive operational information and may contain personal data depending on how an environment is configured. Please only upload configuration files that you are authorised to submit. If your organisation requires a Data Processing Agreement, supplier security review, subprocessor details, or specific data-handling terms before uploading production firewall configurations, contact Secdit before using the service.
Is ConfigSentry read-only?
Yes. It is designed for review, not change deployment.
Does it push changes to FortiGate?
No. Remediation remains under customer change control.
What data does it process?
Raw FortiGate configuration data for audit, plus the resulting findings, scores, reports, and related service metadata.
How are hosted audits handled?
For the normal hosted path, secret material is removed or minimised before temporary protected processing. Temporary processing data is generally removed within a few minutes.
What happens with the no-save manual option?
If a manual audit is run with "Do not save results on website" selected, the relevant configuration is processed without persistent hosted configuration storage.
What may be retained?
Saved audits use a selectable 30, 90, 180 or 365-day retention period (365 days by default), or indefinite retention. Deleting records removes the live data; protected backups may retain deleted data for up to 30 days.
Where is the service hosted?
Hosted with Hetzner in Nuremberg, Germany.
How are collector credentials handled?
Collector-based collections can be configured so appliance credentials remain local to the customer collector host.
How is access to the service protected?
Authenticated account access is required and MFA is supported. Resources are logically isolated by customer account, with role and account checks used to scope access to audits and reports. Public web traffic uses HTTPS/TLS, account passwords are stored as hashes, and stored appliance credentials are encrypted.
What staff access is stated publicly?
Support staff have minimal account access. They can see general account information, user email, account members and roles, submitted support messages, and account-related error logs. They cannot see audit report contents.
How can deeper review be discussed?
Contact Secdit at support@secdit.com or via the contact page for a legitimate security or procurement review. Additional architecture and control evidence can be discussed without making private operational material public.