PolicyProbe

PolicyProbe is a web + lightweight desktop collector that continuously detects “policy drift” across firewalls, VPNs, and security groups (e.g., Palo Alto, Fortinet, Cisco ASA, AWS Security Groups, Azure NSGs). It pulls configs on a schedule, normalizes rules into a common model, and flags risky changes: overly broad CIDRs, new any/any rules, shadowed rules, expired temporary exceptions that never got removed, and rules that violate your own standards. It generates human-readable change reports and evidence bundles for audits (SOC 2/ISO 27001) without pretending to replace a full SIEM. This is not magic: integrations are the hard part, and you’ll start with 3–5 popular platforms. The value is fast visibility and accountability: who changed what, why it’s risky, and what to fix—before it becomes an incident or an audit finding.

← Back to idea list