ConfigSentry FAQ

Questions people ask before they start

A practical guide to how ConfigSentry works, what it audits, and how teams normally use it.

What this page covers

The main questions, grouped properly

Product fit

What ConfigSentry is, which FortiGate environments it supports, and who it is designed for.

How audits work

How configurations are reviewed, whether direct access is needed, and what continuous monitoring adds.

Security and outcomes

How findings are presented, what compliance support looks like, and how quickly you can begin.

In practice

Most teams start simple and go deeper only when they need to

The normal path is straightforward: create an account, use the always-included sign-up credits, and evaluate the product using a real FortiGate configuration.

If the workflow fits, you can continue with more credits for occasional review or move into licensing for continuous monitoring.

Trial and pricing

Questions about the free trial

Is there a free trial?

Yes. Every new user always receives 2 free audit credits on sign up. Separately, the current free trial period also makes additional trial items available until the trial end date.

Do free trial credits expire?

The always-included sign-up credits are separate from the free trial offer. The free trial offer ends on 30 September 2026.

Do I need a long-term commitment to try it?

No. You can start with the current trial offer, run real audits, and only move to paid credits or licensing if the workflow fits your environment.

How do I decide between credits and a license?

Use audit credits for occasional one-off reviews. Use an annual license when you want scheduled reviews, collector-based retrieval, or continuous monitoring for a firewall or cluster.

Product fit

What the product is for

What is ConfigSentry?

ConfigSentry is a Fortinet FortiGate-specific firewall auditing platform. It analyses FortiGate firewall configurations to identify security risks, misconfigurations, and compliance gaps.

Which firewalls are supported?

Only Fortinet FortiGate firewalls are supported right now, across physical, virtual, and cloud deployments, as long as a valid FortiOS configuration is available for review.

Does this only audit firewall policies?

No. It audits the wider FortiGate firewall configuration, including administrative access, VPNs, interfaces, objects, logging, and broader security posture settings.

Is this an official Fortinet product?

No. ConfigSentry is an independent auditing solution developed by secdit. It is designed to complement Fortinet products, not replace them.

Who is ConfigSentry designed for?

It is designed for network engineers, security teams, consultants, and organisations responsible for securing FortiGate environments.

How audits work

How review and monitoring actually work

How does the audit work?

The platform analyses a FortiGate configuration, either uploaded manually or retrieved through a collector workflow, and evaluates it against defined checks that consider both specific settings and wider configuration context.

Do you make changes to my FortiGate firewall?

No. ConfigSentry is read-only. It does not push configuration changes and it does not execute commands that modify the FortiGate firewall.

Is direct FortiGate firewall access required?

No. You can start with uploaded configuration files. If you want recurring retrieval or continuous monitoring, you can use a read-only collector-based workflow instead of relying on manual exports.

What are the benefits of continuous monitoring?

Continuous monitoring helps detect configuration changes, security drift, and newly introduced risk over time instead of relying on occasional manual review.

How often are audits performed in continuous mode?

Audit frequency is configurable. Teams typically choose an interval that gives quick visibility into change without creating unnecessary operational noise.

How quickly can we get value from the platform?

Most teams can begin with a manual upload in minutes. Collector-based monitoring takes longer because it requires collector setup, appropriate read-only access, and internal approval where needed.

Do manual uploads require network changes?

No. Manual upload uses a FortiGate configuration export you already have, so it does not require network changes or live read-only access to begin.

Security and reporting

What you get back from the platform

What compliance standards does it check against?

Audits reference recognised security guidance such as Fortinet best practices, CIS FortiGate Benchmarks where applicable, and broader security hygiene checks. These mappings support alignment and review discussions, but they do not by themselves guarantee compliance.

How are risks presented?

Findings are categorised by severity and include context, impact, and remediation guidance so teams can prioritise what needs attention first.

Can this help with external audits?

Yes. Audit outputs can help demonstrate security posture, internal control quality, and alignment with recognised best practice during internal or third-party review.

Does ConfigSentry replace manual firewall reviews?

It significantly reduces manual effort, but it works best alongside experienced security and network professionals who still make the final judgement calls.

How are firewall configurations reviewed and handled?

Raw firewall configurations are processed in memory for the audit run and removed from memory after processing. The platform can still retain config-derived findings, scores, report metadata, and audit history records until you delete them or remove them through account cleanup, so review the Security and Data Handling page for the workflow-specific model.

Practical use

Operational questions

Does it support multi-firewall environments?

Yes. ConfigSentry can audit multiple FortiGate firewalls or clusters so organisations can keep a consistent review standard across environments.

Can I customise audit checks?

Yes. You can clone existing rules and modify them to suit your requirements, or create entirely new custom rules from scratch.

Can I control which checks are included in an audit?

Yes. You can create and manage audit rule templates, allowing you to choose exactly which checks are performed during each audit.

Does this work for cloud-hosted FortiGates?

Yes. Cloud-hosted FortiGate instances can be audited in the same way as on-premises FortiGate firewalls, provided configuration access is available.

How quickly can I run my first audit?

Usually within minutes of signing up. New users can create an account, use their included sign-up credits, and run a real audit straight away.

Commercial and support

Questions buyers often ask before purchase

What support is available after purchase?

Support is available through the support portal and contact channel. For onboarding, product, or commercial questions, contact secdit so the right follow-up path can be arranged.

Can we get help during rollout?

Yes. If you need help planning evaluation, collector setup, or the right usage model for your environment, contact secdit through the normal contact path.

Can we pay by invoice or purchase order?

If you need invoice or purchase-order handling, contact secdit to confirm the current commercial options for your region and buying process.

How do renewals or cancellations work?

For the current renewal or cancellation process for paid licenses, contact secdit. The exact commercial handling can depend on how the purchase is arranged.

What if we only need occasional audits?

That is what audit credits are for. You can stay with one-off reviews and buy credits only when you need another audit, without moving to a recurring license.

Trust and procurement

Questions that matter during customer review

Does account MFA matter here?

Yes. Multi-factor authentication helps protect access to audit results and config-derived findings, especially where account history is shared across a team.

What should we know about retention or deletion?

Workflow-specific handling differs. Raw firewall configurations are processed in memory and removed after processing, while audit history and account-linked data can remain available until deleted or removed through account cleanup. Deleting data normally removes it from the main platform workflow, while some operational logs or backups may remain temporarily as part of normal resilience processes.

Where is the service hosted?

For current hosting location or jurisdiction details relevant to your review, contact secdit directly so the latest information can be confirmed during evaluation.

How should we think about encryption controls?

Public website access and collector upload or download endpoints are provided over HTTPS. Exported report encryption or password protection, where offered, applies to the downloaded report package and should not be read as a statement about every platform-side storage control. Contact secdit if you need current deployment or storage-architecture details for review.

Is the platform presented as independently certified?

ConfigSentry is not currently presented here as independently certified. The security controls and data-handling model described on the site are intended to support customer review.

Next step

Ready to try it with a real configuration?

Every new user account includes 2 free audit credits on sign up so you can run an initial FortiGate firewall audit straight away. During the current free trial period, additional zero-cost trial credits and trial licenses are also available. Decide later whether you want extra credits or a license for continuous monitoring.