Security, trust and data handling for ConfigSentry

A practical first-pass overview for customers, security consultants, and procurement teams: how ConfigSentry works, how sensitive data is handled, and where to ask for deeper evidence.

The short version

The main points most teams want first

  • ConfigSentry reviews FortiGate configuration data; it does not push firewall changes.
  • You can start with manual upload before using a collector.
  • Collector credentials can stay on your own collector host.
  • Account access is authenticated, supports MFA, and is scoped to the authorised account and role.
  • Audit retention is selectable (30, 90, 180, 365 days, or indefinite); the default is 365 days.
  • If your organisation needs a DPA, subprocessor detail, or a security/procurement review, contact Secdit before uploading production configs.

Configuration security

How your firewall configuration is protected

See how configuration data moves from your environment through secure transfer and analysis, and how temporary processing, retention and deletion are handled.

Click the diagram to view it at full size.

At a glance

A clearer first pass before the deeper review

Configuration charm representing processed audit data.

What ConfigSentry reviews

ConfigSentry performs a read-only review of FortiGate configuration data and produces reports and findings from that review. Configuration files can contain sensitive operational information and may contain personal data depending on how an environment is configured.

Shield charm representing raw configuration handling.

How hosted review works

For the normal hosted path, secret material such as passwords, private certificates, and keys is removed or minimised before temporary protected processing. That processing data is normally removed within a few minutes.

Shield charm representing temporary configuration handling.

Manual upload or no-save option

You can start with manual upload before using a collector. With "Do not save results on website" selected, the relevant configuration is processed without persistent hosted configuration storage.

Risk finding charm representing retained audit outputs.

Retention and deletion

Saved audits use a selectable 30, 90, 180 or 365-day retention period (365 days by default), or indefinite retention. Deletion removes live records; protected backups may retain deleted data for up to 30 days.

Collector charm representing local credential handling.

Collector credentials

Collector-based collections can be configured so appliance credentials remain on the customer collector host rather than being stored in the website.

Report output charm representing review-only reporting.

What ConfigSentry does not do

ConfigSentry is for audit, reporting, and review. It does not push changes to firewalls, does not perform automatic remediation, and leaves remediation under the customer’s own change control.

Handling flow

A practical view of what happens to a config

01

Configuration submitted or collected

A FortiGate configuration is provided either by upload or by an approved collection workflow.

02

Sensitive material is minimised

For the normal hosted audit path, passwords, private certificates, keys, and similar secret material are removed or minimised before temporary protected processing.

03

Processed quickly or without persistent storage

Temporary hosted processing data is generally removed within a few minutes. Manual audits using "Do not save results on website" process the relevant configuration without persistent hosted configuration storage.

04

Results follow your retention setting

Saved audits and reports are retained until the selected retention period expires or they are manually deleted. Available settings are 30, 90, 180 or 365 days (365 by default), with indefinite retention where selected. Protected backups may retain deleted data for up to 30 days.

Retention and deletion

Data lifecycle and deletion

See how temporary configuration processing, saved-audit retention, manual deletion and backup ageing fit together.

Click the diagram to view it at full size.

Direct answers

Direct answers to the handling questions buyers usually ask first

What should evaluators know before uploading?
ConfigSentry is currently being offered as an early free trial. A self-service Data Processing Agreement is not currently available. Firewall configuration files can contain sensitive operational information and may contain personal data depending on how an environment is configured. Please only upload configuration files that you are authorised to submit. If your organisation requires a Data Processing Agreement, supplier security review, subprocessor details, or specific data-handling terms before uploading production firewall configurations, contact Secdit before using the service.

Is ConfigSentry read-only?
Yes. It is designed for review, not change deployment.

Does it push changes to FortiGate?
No. Remediation remains under customer change control.

What data does it process?
Raw FortiGate configuration data for audit, plus the resulting findings, scores, reports, and related service metadata.

How are hosted audits handled?
For the normal hosted path, secret material is removed or minimised before temporary protected processing. Temporary processing data is generally removed within a few minutes.

What happens with the no-save manual option?
If a manual audit is run with "Do not save results on website" selected, the relevant configuration is processed without persistent hosted configuration storage.

What may be retained?
Saved audits use a selectable 30, 90, 180 or 365-day retention period (365 days by default), or indefinite retention. Deleting records removes the live data; protected backups may retain deleted data for up to 30 days.

Where is the service hosted?
Hosted with Hetzner in Nuremberg, Germany.

How are collector credentials handled?
Collector-based collections can be configured so appliance credentials remain local to the customer collector host.

How is access to the service protected?
Authenticated account access is required and MFA is supported. Resources are logically isolated by customer account, with role and account checks used to scope access to audits and reports. Public web traffic uses HTTPS/TLS, account passwords are stored as hashes, and stored appliance credentials are encrypted.

What staff access is stated publicly?
Support staff have minimal account access. They can see general account information, user email, account members and roles, submitted support messages, and account-related error logs. They cannot see audit report contents.

How can deeper review be discussed?
Contact Secdit at support@secdit.com or via the contact page for a legitimate security or procurement review. Additional architecture and control evidence can be discussed without making private operational material public.

Hosting and access context

What this page does and does not say about infrastructure and access

Shield charm representing hosting-provider information.

Hosted with Hetzner in Nuremberg, Germany

ConfigSentry data is hosted with Hetzner in Nuremberg, Germany. Hetzner publishes information about its ISO 27001:2022 certified ISMS and the data-centre scope it says is covered. That is hosting-provider information, not a claim that Secdit or ConfigSentry is ISO 27001 certified.

MFA charm representing authenticated service access.

Access control and authentication

Sensitive audit output should be treated as security-relevant data. ConfigSentry requires authenticated access to the service, MFA-supported access helps protect audit history, findings, and reports, public web traffic uses HTTPS with TLS 1.2, internal database connections use TLS with certificate authentication, account passwords are stored as hashes, and stored appliance credentials are encrypted.

Risk finding charm representing limited support access.

Minimal support-staff visibility

Support staff can see general account information such as account name, ID, user email, account members and roles, submitted support messages, and account-related error logs. They cannot see audit report contents.

Report output charm representing customer change control.

Customer change control remains in place

ConfigSentry can surface findings and support remediation planning, but customer teams still decide what to change, when to change it, and how those changes are approved and implemented.

Operational assurance

How the service and Collector are operated

Shield charm representing protected backups.

Protected backups and resilience

Protected backups support service recovery. Backup access is restricted, backup retention is limited, and recovery procedures are documented and reviewed. Deleted live data can remain in protected backups for up to 30 days.

Collector charm representing local collection controls.

Collector runs in your environment

The Collector runs in the customer environment for controlled configuration collection. Credentials marked for local use can remain there. Versioned releases and update checks protect package and update integrity; the Collector is not an arbitrary remote-administration tool.

Configuration charm representing read-only appliance access.

Controlled appliance access

Direct SSH and Collector workflows retrieve configuration read-only. Customers control appliance credentials and should grant only the access required. Stored service-side appliance credentials are encrypted; key or certificate authentication can be used where supported.

Risk finding charm representing controlled change triggers.

Change-trigger safeguards

For change-triggered collection, the Collector validates events against the configured appliance source and only supported configuration-change events can request collection. Duplicate and burst protections reduce repeated attempts. Customers control network exposure to their Collector.

Customer-controlled collection

Collector security boundary

The Collector runs inside the customer environment, can keep appliance credentials local, and communicates with ConfigSentry over protected service connections.

Click the diagram to view it at full size.

Security operations

Secure development, monitoring and response

ConfigSentry uses documented secure-development and release practices, including controlled source changes, dependency/version control where applicable, security-sensitive coding guidance, focused regression checks, and versioned Collector releases with integrity verification. It does not claim a formal SDLC certification, SOC 2, ISO 27001 certification, independent source audit, or independent penetration-test programme.

Security and operational logging supports the detection and investigation of abnormal activity. Privileged and security-sensitive activity is restricted according to role and need, with appropriate controls and logging. Secdit maintains documented incident-response and vulnerability-handling processes to assess, contain, investigate, recover from, and review credible issues.

Reporting a suspected vulnerability: responsible reports are welcome through support@secdit.com or the contact page. Please include enough information to understand or reproduce the issue. Secdit investigates legitimate reports; do not send credentials, keys, or unnecessary customer data.

Read the Privacy Policy, Cookie Policy, and ConfigSentry Terms for privacy, cookie and service terms. Organisations needing a DPA or subprocessor review should contact Secdit; the current DPA remains a draft pending legal review.

Privacy and procurement

Quick answers for security reviewers

Shield charm representing privacy information.

Privacy and processors

Secdit is controller for service operations and may process customer-submitted configuration content on the customer's behalf. Hosting is in Germany with Hetzner; Stripe Checkout and Cloudflare Turnstile are used where applicable. See the Privacy and Cookie Policies; a DPA draft is available for legal review on request.

MFA charm representing account protection.

Authentication and tenancy

MFA is supported. Customer accounts are logically isolated, and audit/report access is scoped through authenticated account and role checks. Passwords are hashed; appliance credentials stored by the service are encrypted.

Risk finding charm representing assurance limits.

No certification overclaim

Secdit and ConfigSentry are not currently ISO 27001, SOC 2, PCI DSS, or GDPR certified, and no independent penetration test or source-code audit is claimed. Hetzner certification information relates to Hetzner, not ConfigSentry.

Report charm representing procurement review.

Security or procurement review?

Contact Secdit for a legitimate buyer, security-consultant, or procurement review. We can discuss relevant private evidence while keeping implementation and customer-sensitive details confidential.

Account protection

Tenant isolation, MFA & role-based access

Authenticated access, MFA, account roles and logical tenant isolation help restrict audit and report access to the correct customer account.

Click the diagram to view it at full size.

Important limits

What we do not claim

Shield charm representing scope limits.

No compliance certification claim

ConfigSentry does not certify compliance, and this page should not be read as a statement that a reviewed firewall is compliant with any standard.

Risk finding charm representing engineer review limits.

No replacement for engineer review

ConfigSentry helps structure technical review, but it does not replace engineer judgement, internal review procedures, or environment-specific validation.

Report output charm representing no automatic remediation.

No firewall change push

ConfigSentry does not push configuration changes to firewalls and should not be treated as an automatic remediation system.

MFA charm representing hosting-provider certification limits.

Hosting-provider certification is not product certification

Information published by Hetzner about its own ISMS or data-centre certification scope should not be treated as product certification for Secdit or ConfigSentry.

Security review questions

Questions a serious buyer may still want answered before onboarding

Configuration charm representing retention questions.

Retention and deletion details

This page states that live audit, report, and related account records are removed immediately when deleted, while periodic database backups may retain deleted data for up to 30 days. Ask Secdit directly if your review needs more backup-handling detail.

Shield charm representing encryption questions.

Encryption detail

This page states that public web traffic uses HTTPS/TLS, account passwords are stored as hashes, stored appliance credentials are encrypted, and temporary audit-processing data is protected and short-lived. Ask separately if your review needs deeper implementation detail.

MFA charm representing staff access questions.

Staff access controls

Publicly stated support access is limited to general account information, account members and roles, support messages, and account-related error logs. Audit report contents are not visible to support staff.

Report output charm representing contract and privacy questions.

Contract and privacy review

ConfigSentry is currently being offered as an early free trial. A self-service Data Processing Agreement is not currently available. Organisations that need a DPA, supplier security review, subprocessor detail, or specific data-handling terms before uploading production firewall configurations should contact Secdit before using the service.

Collector charm representing customer-side handling responsibilities.

Customer-side handling still matters

Downloaded reports, exported files, collector hosts, and any local copies of configurations remain part of the customer’s own security scope and should be handled under the customer’s normal controls.

Next step

If the handling model fits, try it with an authorised config

Run an audit when your review is comfortable with the handling approach, or check pricing if you still need commercial detail.