Three thousand rules. Ninety seconds. One verdict.
Drop a firewall config. ruledoc reads every rule, scores the risk, and typesets the findings against NIS2, PCI DSS, ISO 27001 and CIS. No agent. No console access. Just the file. And its secrets never leave your browser.
no card·watermarked sample·delete your config any time
Nobody reads firewall configs. Auditors bill by the day for trying.
A production firewall carries years of history. Migration leftovers, vendor access that never got removed, an any-any rule someone added during an outage at 3 am. It all stays open until somebody reads the file.
Manual review takes days and goes stale the week after. Compliance deadlines do not wait: NIS2 is law, PCI DSS v4 is in force, and your next customer security questionnaire is already in the inbox.
ruledoc reads the whole file, every time. Every rule, every interface, every crypto setting. Typeset into findings your auditor, your CISO and your board can act on.
Four passes. Zero access to your network.
Upload
Drag in the raw config file. Eleven vendor formats auto-detected. Secrets and password hashes are stripped in your browser, before the file ever uploads.
Parse
Every rule, object, interface and crypto setting is normalized into one universal model. Vendor quirks end here.
Analyze
Hundreds of controls run against the model: exposure, dead rules, weak crypto, management hygiene, segmentation.
Typeset
A risk score, severity-ranked findings and framework mappings. Browser, PDF and JSON. Ready for the audit binder.
Your secrets never leave your machine.
A firewall config is the most sensitive file your network holds, so ruledoc never sees your secrets. PSKs, passwords, private keys and SNMP communities are stripped in your browser, before the file uploads, and replaced with placeholders on your own device.
Do not take our word for it. Open your browser's network tab and watch the upload: it carries only placeholders. The code is readable and makes no other outbound call.
no signup needed·runs 100% in your browser·10 vendor formats
Findings your auditor can quote verbatim.
Policy 412 permits all sources to all destinations on all services. Effectively no firewall.
Cleartext administration exposed on port9. Credentials readable in transit.
A third of the rulebase is dead weight. Every unused rule is unreviewed attack surface.
No legacy DES/3DES/MD5 found in phase 1 or phase 2. Keep it that way.
six report types per config · every finding mapped to the clause your auditor will ask about
If it filters packets, we read it.
FortiOS 5.x – 7.x
PAN-OS + Panorama
incl. transparent mode
set + hierarchical
policy + objects
SFOS
Firebox
cOS Core
config.xml
NG Firewall
NGAF
new vendors ~1 week
Priced like a tool, not a procurement project.
- 1 report per email per month
- All six frameworks visible
- Browser view, watermarked
- No PDF or JSON export
- 1 config, all six frameworks
- Full PDF, unwatermarked
- JSON export for your GRC tool
- Refundable until generated
- 15 reports per month
- Scheduled re-runs of saved configs
- 1-year history · priority queue
- 30-day money-back guarantee
Read your firewall.
The first report is free, watermarked, and takes about ninety seconds. If it does not tell you something you did not know, you have lost two minutes.
no card·no agent·configs encrypted at rest, deletable any time