Read-only access model
The platform is designed for analysis and reporting, not for pushing production changes.
Security and Trust
FortiGate configurations are sensitive. This page explains the read-only model, handling approach, and trust details that matter during evaluation.
At a glance
The platform is designed for analysis and reporting, not for pushing production changes.
Raw configuration data is used for the audit workflow rather than positioned as a generic document store.
If an audit waits for worker capacity, the queued payload may be stored temporarily in encrypted form until processing starts or the queued item expires.
Findings, scores, report metadata, and audit history can remain until deleted.
Multi-factor authentication helps protect access to audit history and findings.
Collector-based collections can be configured so appliance credentials remain on the collector host rather than being stored in the website.
Export protection applies to downloaded reports and should be considered separately from platform-side controls.
Handling flow
Manual upload or least-privilege collector retrieval.
Raw configs are used to build the audit view for that run, and queued payloads may be stored temporarily in encrypted form until processing begins.
Findings, scores, and history may remain until deleted.
Engineer, executive, and download-oriented outputs.
Direct answers
Data handling matrix
Collector security
Use the lowest practical privilege that still allows full configuration retrieval.
Collector-side credentials stay a customer host concern, not a website-managed secret store.
Website communication is designed around outbound HTTPS from the collector host.
Host placement, network policy, and read-only access still need normal internal approval.
Account access roles
Full account administration, including configuration of collection workflows, credential handling, audits, users, and account-level settings.
Operational access for running audits, reviewing findings, and working with report output without full account-administration scope.
Read-focused access for viewing findings and reports without broader configuration or account-management permissions.
Buyer review notes
Raw configurations are processed for the audit workflow, and queued submissions may be stored temporarily in encrypted form until processing begins or the queued item expires.
Storage expectations differ by workflow: hosted retrieval may involve website-managed appliance credentials, while collector-based retrieval can keep those credentials only on the collector host.
Contact secdit if your review needs current hosting region, jurisdiction, or implementation details for encryption in transit and at rest.
Support access, backup/log retention, queue expiry handling, and customer-controlled deletion should be reviewed against your internal handling requirements.
ConfigSentry is not presented here as independently certified. The controls described support customer review.
Next step
If the trust model fits your needs, the next step is usually to run a real FortiGate audit and review the output.