§ ruledoc.io
Firewall compliance engine

Three thousand rules. Ninety seconds. One verdict.

Drop a firewall config. ruledoc reads every rule, scores the risk, and typesets the findings against NIS2, PCI DSS, ISO 27001 and CIS. No agent. No console access. Just the file. And its secrets never leave your browser.

no card·watermarked sample·delete your config any time

01 The backlog

Nobody reads firewall configs. Auditors bill by the day for trying.

A production firewall carries years of history. Migration leftovers, vendor access that never got removed, an any-any rule someone added during an outage at 3 am. It all stays open until somebody reads the file.

Manual review takes days and goes stale the week after. Compliance deadlines do not wait: NIS2 is law, PCI DSS v4 is in force, and your next customer security questionnaire is already in the inbox.

ruledoc reads the whole file, every time. Every rule, every interface, every crypto setting. Typeset into findings your auditor, your CISO and your board can act on.

0rules in one real config
0seconds to a verdict
0frameworks per run
02 The engine

Four passes. Zero access to your network.

P—1

Upload

Drag in the raw config file. Eleven vendor formats auto-detected. Secrets and password hashes are stripped in your browser, before the file ever uploads.

P—2

Parse

Every rule, object, interface and crypto setting is normalized into one universal model. Vendor quirks end here.

P—3

Analyze

Hundreds of controls run against the model: exposure, dead rules, weak crypto, management hygiene, segmentation.

P—4

Typeset

A risk score, severity-ranked findings and framework mappings. Browser, PDF and JSON. Ready for the audit binder.

Zero-knowledge upload

Your secrets never leave your machine.

A firewall config is the most sensitive file your network holds, so ruledoc never sees your secrets. PSKs, passwords, private keys and SNMP communities are stripped in your browser, before the file uploads, and replaced with placeholders on your own device.

Do not take our word for it. Open your browser's network tab and watch the upload: it carries only placeholders. The code is readable and makes no other outbound call.

no signup needed·runs 100% in your browser·10 vendor formats

on your device
Before — stays with you
set psksecret 7hV$2k9mQpX1 set admin password S3cr3t!Adm1n <SSHHostKey Key="-----BEGIN RSA…">
After — this is what uploads
set psksecret __STRIPPED_PSK__ set admin password __STRIPPED_PASSWORD__ <SSHHostKey Key="__STRIPPED_SSH_HOST_KEY__">
✓ 3 secrets stripped in your browser
03 The report

Findings your auditor can quote verbatim.

fw-helsinki-edge.conf fortigate · nis2 · 3,795 rules · 2026-06-09 14:02
0risk / 100
0 critical 0 warning 0 info
critical
Any-to-any accept rule reachable from WAN

Policy 412 permits all sources to all destinations on all services. Effectively no firewall.

NIS2 Art.21 · PCI 1.2.1
critical
Telnet management enabled on outside interface

Cleartext administration exposed on port9. Credentials readable in transit.

ISO A.8.20 · CIS 4.6
warning
1,204 rules with zero hits in 365 days

A third of the rulebase is dead weight. Every unused rule is unreviewed attack surface.

NIS2 Art.21 · CIS 4.1
info
IPsec proposals use modern suites only

No legacy DES/3DES/MD5 found in phase 1 or phase 2. Keep it that way.

PCI 4.2.1
full report: 28 pages · pdf + json · remediation snippets included Run yours
04 The frameworks

six report types per config · every finding mapped to the clause your auditor will ask about

05 The fleet

If it filters packets, we read it.

FortiGate
FortiOS 5.x – 7.x
Palo Alto
PAN-OS + Panorama
Cisco ASA
incl. transparent mode
Juniper SRX
set + hierarchical
Check Point
policy + objects
Sophos
SFOS
WatchGuard
Firebox
Clavister
cOS Core
pfSense
config.xml
Untangle
NG Firewall
Sangfor
NGAF
Yours next?
new vendors ~1 week
06 The bill

Priced like a tool, not a procurement project.

Free Sample
€0no card required
try.before.you.buy
  • 1 report per email per month
  • All six frameworks visible
  • Browser view, watermarked
  • No PDF or JSON export
Start free
Single Reportmost picked
€49one-off, no subscription
pay.once.done
  • 1 config, all six frameworks
  • Full PDF, unwatermarked
  • JSON export for your GRC tool
  • Refundable until generated
Buy a report
Pro
€99/ month
cancel.anytime
  • 15 reports per month
  • Scheduled re-runs of saved configs
  • 1-year history · priority queue
  • 30-day money-back guarantee
Start Pro

Read your firewall.

The first report is free, watermarked, and takes about ninety seconds. If it does not tell you something you did not know, you have lost two minutes.

Run a free report

no card·no agent·configs encrypted at rest, deletable any time