Assurance read-only on the estate you run today

Know what your network is actually doing.
Then keep knowing.

A fixed-scope, read-only audit that builds your network truth — what you declared, what your kit enforces, what actually flows — and measures the gap. Then the same engine keeps running, so the evidence exists before anyone asks for it.

69%

of firewall rules are unused FireMon Insights 2.0 · 9.2m policy checks
across hybrid networks · Jun 2026

45%

have no owner or documentation Same dataset · 17% redundant or shadowed outright

58%

of firewalls fail a high-severity compliance check Same dataset · 48% fail at critical severity

What we move: those three stop being estimates. Measured on your estate, in the first read-only pass — no change window, no risk committee. Industry baselines shown, not our results.

core · no SRv6 required no agents · no probes · no device logins

0100 the first two weeks

The clock starts at the first byte. Not at the signature.

Everything starts on day zero, because nothing forces a sequence: the engine scores at ingest. A one-page readiness checklist before the clock starts — which exports exist, which exporters can point at a listener — is the whole of the preparation.

  1. Day 0 Engine container deployed in your tenant. Firewall policy and config archives pushed to its own ingest URL; flow exporters pointed at its listener; manager pulls where you run one. About thirty minutes of your effort.
  2. Day 5–7 The deterministic readout: declared against configured is complete. Reachability computed, every rule classified — shadowed, redundant, disabled, overly broad, unused, unknown — with the conservative retirement list.
  3. Day 14 The full readout with whatever observed coverage accumulated, as a generated evidence pack. Late exporters trail as an addendum; the audit bills on declared against configured alone, so observation enriches it and never delays it.
  4. Continuously The window never closes. The same engine keeps the network truth aligned with your intent; stopping it becomes a decision rather than a default.

Two weeks is the standard tier, on one named domain. Multi-domain or multi-region estates run four to six — or, better, as several scopes in parallel. What fits a scope is below.

0200 what comes back

Every relationship in one of six states — with the reason.

Three truths give six states, not two. The important ones are the pairs that look fine from any one source alone: a path the configuration permits that no intent covers is an exposure whether or not a flow has been seen on it yet.

The gap ledger. Intent is what you declared, configured is what the network permits, observed is what the telemetry saw.
IntentConfiguredObservedState
allowedreachableseenVerified & observed
allowedreachableVerified reachability, not observed
allowedblockedBroken intent
deniedreachableExposure
deniedreachableseenActive violation
deniedblockedCorrectly isolated

“—” means not observed in the available telemetry. It never means no traffic exists.

The network truth

Topology, address spaces, zones and the reachability graph — computed from the configuration actually in force, not from a diagram. Roles resolved from what the estate already declares, with the source of every resolution recorded; an address nothing covers stays an address, never a guess.

Every rule, classified

Shadowed, redundant, disabled, overly broad, unused per its own hit counters, or unknown — then keep, retire-candidate, or investigate. Retirement is proposed only for rules whose counters are present and whose removal the reachability model shows to be safe. A named approver decides; the engine proposes.

The evidence pack

Generated, not written: the ledger, the classification, the coverage and the limits — sampling rate per stream, every construct the parsers could not read, every device without counters — with a hash on every input and a replay command. What a third party does with it →

If no declared intent exists yet, the audit derives a proposed baseline from what is configured and observed — a deliverable, not a prerequisite. Bring the inventory you have, in whatever state it is in; nothing here requires it to be right.

0300 continuous

Assurance that never claims to see every flow.

Routers sample. A one-in-a-thousand exporter will never show you a rare flow, and a product that promises “we verify every flow” on sampled telemetry is promising something it cannot measure. So the promise is a different one.

Continuously prove that configured reachability remains aligned with declared intent — using network state, observed traffic, and the evidence each can honestly carry.

Declared against configured — deterministic

Given the configuration in force, can A reach B? That question is answered from the configuration itself, without a single observed packet, and re-answered on every change: a config export lands, the model recomputes, the diff becomes a verdict. Drift — declared, undeclared, enforcement — surfaces here, and it is where the promise is kept.

Observed traffic — evidence, never authority

The flow streams from the audit keep running. Every record carries the sampling rate it arrived under, or the word unknown. What is seen confirms what the configuration permits and catches what it should not; what is not seen proves nothing, and the ledger says so. Seen-but-undeclared escalates to a named human; it never widens anything.

Intent coverage

The share of your declared relationships under continuous verification against the configuration. The number that should read one hundred.

Traffic evidence coverage

The share of relationships the available telemetry actually supports with observed flows — honest about sampling, by construction.

Freshness

Per source, when it last spoke. A continuous promise with a stale source is not continuous, so the service level is a gate with an alarm, not a dashboard tile.

The queue

What is waiting for a person, and for how long. Sensitive calls are never auto-allowed and never silently dropped; they wait, and the wait is visible.

Intent starts as network intent — this address space may reach that one, on this service — and that level is always sufficient. Where you have the data, it binds progressively to applications, owners and criticality; where you do not, nothing is blocked on a CMDB that was never going to be perfect.

0400 what never happens

The engine listens. The estate sends.

Themis never logs into a device. — no SSH, no RESTCONF into boxes, no credential hand-over. Configuration arrives as exports you push, or as pulls from the managers you already run: Panorama, FortiManager, NetBox, Hubble. Telemetry arrives because your exporters point at a listener.
Nothing is installed on a workload. — no agents, no active probes, nothing written to the network. The audit is passive end to end; the only thing deployed is one container in your tenant.
No write credentials. Ever, on this product. — every finding is yours to act on through your own change process; the engine verifies that the change landed as intended. There is no mode in which it widens or tightens policy on its own.
Data never leaves your tenant. — raw flows are classified in flight and discarded; what persists is the verdict ledger and a hash commitment per window. The engine is dependency-free Python with no network egress except one documented route: the licence check, which carries the licence state and nothing else.

Runs in your tenant

One container, wherever you want it. Your management-plane integration is your choice; we have no access to any of it.

CPU only, no GPU

The verdict path is deterministic and contains no model. An optional assist container drafts groupings a person accepts or rejects — proposals, never verdicts.

Reproducible

A closed window replays byte-identically from its own artifacts. Evidence that cannot be reproduced is not evidence.

Read-only, by construction

Not a setting. There is no code path that writes to the network, and that is something your security team can check by reading it.

0500 what fits a scope

One named domain. Above these, we split rather than stretch.

The two-week promise holds inside a bounded scope, and the bounds are published so you can tell in week zero rather than week three. An estate larger than this is not a bad fit — it is several scopes, each verified in parallel. These are starting bounds, calibrated with the first estates.

One named domain — a data centre and its edges, an IT/OT boundary, one cloud environment. Multi-domain and multi-region are several scopes.
Up to about 50 enforcement points and 25,000 rules — firewalls and ACL-bearing devices across the scope. Firewalls: FortiGate, PAN-OS, Cisco ASA and FTD. Routers: IOS-XE, NX-OS, IOS-XR, Junos, SR-OS, Huawei VRP, Arista EOS. Plus Kubernetes policy and cloud security groups.
Up to about 100 exporters per stream, 10,000 observed relationships — NetFlow v5, v9 and IPFIX, sampled or not, with the rate stamped on every record. One engine container decodes on the order of a hundred thousand records a second sustained; beyond that, one container per stream.

The decode ceiling is a measured number — lab, one core: 672k records/s for v5, 230k for v9, 218k for IPFIX — and the sustained figure keeps two-times headroom for scoring. Every parser ships a coverage report; a construct it could not read is a listed finding, never a silent gap. The test configurations are standards-shaped, and the first real export from your vendor will enumerate what they missed. That is what the readiness checklist is for.

e000 End.DT6 deliver

See it against your own kit.

30–60 minutes, read-only. We look at which exports exist, agree the scope, and the clock starts at the first byte.

Savings are computed from your own estate in the first two read-only weeks — never from our slides.

See it on your estate — read-only