Assurance read-only on the estate you run today
Know what your network is actually doing.
Then keep knowing.
A fixed-scope, read-only audit that builds your network truth — what you declared, what your kit enforces, what actually flows — and measures the gap. Then the same engine keeps running, so the evidence exists before anyone asks for it.
69%
of firewall rules are unused FireMon Insights 2.0 · 9.2m policy checksacross hybrid networks · Jun 2026
45%
have no owner or documentation Same dataset · 17% redundant or shadowed outright58%
of firewalls fail a high-severity compliance check Same dataset · 48% fail at critical severityWhat we move: those three stop being estimates. Measured on your estate, in the first read-only pass — no change window, no risk committee. Industry baselines shown, not our results.
core · no SRv6 required no agents · no probes · no device logins
0100 the first two weeks
The clock starts at the first byte. Not at the signature.
Everything starts on day zero, because nothing forces a sequence: the engine scores at ingest. A one-page readiness checklist before the clock starts — which exports exist, which exporters can point at a listener — is the whole of the preparation.
- Day 0 Engine container deployed in your tenant. Firewall policy and config archives pushed to its own ingest URL; flow exporters pointed at its listener; manager pulls where you run one. About thirty minutes of your effort.
- Day 5–7 The deterministic readout: declared against configured is complete. Reachability computed, every rule classified — shadowed, redundant, disabled, overly broad, unused, unknown — with the conservative retirement list.
- Day 14 The full readout with whatever observed coverage accumulated, as a generated evidence pack. Late exporters trail as an addendum; the audit bills on declared against configured alone, so observation enriches it and never delays it.
- Continuously The window never closes. The same engine keeps the network truth aligned with your intent; stopping it becomes a decision rather than a default.
Two weeks is the standard tier, on one named domain. Multi-domain or multi-region estates run four to six — or, better, as several scopes in parallel. What fits a scope is below.
0200 what comes back
Every relationship in one of six states — with the reason.
Three truths give six states, not two. The important ones are the pairs that look fine from any one source alone: a path the configuration permits that no intent covers is an exposure whether or not a flow has been seen on it yet.
| Intent | Configured | Observed | State |
|---|---|---|---|
| allowed | reachable | seen | Verified & observed |
| allowed | reachable | — | Verified reachability, not observed |
| allowed | blocked | — | Broken intent |
| denied | reachable | — | Exposure |
| denied | reachable | seen | Active violation |
| denied | blocked | — | Correctly isolated |
“—” means not observed in the available telemetry. It never means no traffic exists.
The network truth
Topology, address spaces, zones and the reachability graph — computed from the configuration actually in force, not from a diagram. Roles resolved from what the estate already declares, with the source of every resolution recorded; an address nothing covers stays an address, never a guess.
Every rule, classified
Shadowed, redundant, disabled, overly broad, unused per its own hit counters, or unknown — then keep, retire-candidate, or investigate. Retirement is proposed only for rules whose counters are present and whose removal the reachability model shows to be safe. A named approver decides; the engine proposes.
The evidence pack
Generated, not written: the ledger, the classification, the coverage and the limits — sampling rate per stream, every construct the parsers could not read, every device without counters — with a hash on every input and a replay command. What a third party does with it →
If no declared intent exists yet, the audit derives a proposed baseline from what is configured and observed — a deliverable, not a prerequisite. Bring the inventory you have, in whatever state it is in; nothing here requires it to be right.
0300 continuous
Assurance that never claims to see every flow.
Routers sample. A one-in-a-thousand exporter will never show you a rare flow, and a product that promises “we verify every flow” on sampled telemetry is promising something it cannot measure. So the promise is a different one.
Continuously prove that configured reachability remains aligned with declared intent — using network state, observed traffic, and the evidence each can honestly carry.
Declared against configured — deterministic
Given the configuration in force, can A reach B? That question is answered from the configuration itself, without a single observed packet, and re-answered on every change: a config export lands, the model recomputes, the diff becomes a verdict. Drift — declared, undeclared, enforcement — surfaces here, and it is where the promise is kept.
Observed traffic — evidence, never authority
The flow streams from the audit keep running. Every record carries the sampling rate it arrived under, or the word unknown. What is seen confirms what the configuration permits and catches what it should not; what is not seen proves nothing, and the ledger says so. Seen-but-undeclared escalates to a named human; it never widens anything.
Intent coverage
The share of your declared relationships under continuous verification against the configuration. The number that should read one hundred.
Traffic evidence coverage
The share of relationships the available telemetry actually supports with observed flows — honest about sampling, by construction.
Freshness
Per source, when it last spoke. A continuous promise with a stale source is not continuous, so the service level is a gate with an alarm, not a dashboard tile.
The queue
What is waiting for a person, and for how long. Sensitive calls are never auto-allowed and never silently dropped; they wait, and the wait is visible.
Intent starts as network intent — this address space may reach that one, on this service — and that level is always sufficient. Where you have the data, it binds progressively to applications, owners and criticality; where you do not, nothing is blocked on a CMDB that was never going to be perfect.
0400 what never happens
The engine listens. The estate sends.
Runs in your tenant
One container, wherever you want it. Your management-plane integration is your choice; we have no access to any of it.
CPU only, no GPU
The verdict path is deterministic and contains no model. An optional assist container drafts groupings a person accepts or rejects — proposals, never verdicts.
Reproducible
A closed window replays byte-identically from its own artifacts. Evidence that cannot be reproduced is not evidence.
Read-only, by construction
Not a setting. There is no code path that writes to the network, and that is something your security team can check by reading it.
0500 what fits a scope
One named domain. Above these, we split rather than stretch.
The two-week promise holds inside a bounded scope, and the bounds are published so you can tell in week zero rather than week three. An estate larger than this is not a bad fit — it is several scopes, each verified in parallel. These are starting bounds, calibrated with the first estates.
The decode ceiling is a measured number — lab, one core: 672k records/s for v5, 230k for v9, 218k for IPFIX — and the sustained figure keeps two-times headroom for scoring. Every parser ships a coverage report; a construct it could not read is a listed finding, never a silent gap. The test configurations are standards-shaped, and the first real export from your vendor will enumerate what they missed. That is what the readiness checklist is for.
e000 End.DT6 deliver
See it against your own kit.
30–60 minutes, read-only. We look at which exports exist, agree the scope, and the clock starts at the first byte.
Savings are computed from your own estate in the first two read-only weeks — never from our slides.