One key back.
Configuration backup, verified restore and examiner-ready evidence for a bank’s firewall estate. It lives inside the bank, is silent to the internet, refuses to store a capture it cannot prove complete, and restores only with a person in command.
Four things, and it refuses rather than guesses at each
Captures, or refuses
A capture that cannot prove it is complete does not enter the vault. The end-marker check and the size guard both have to pass, and a failure stores nothing at all.
Redacts at every boundary
A secret becomes a stable keyed fingerprint before it leaves the vault — in terminal output, diffs, packs and alerts alike. An unchanged secret makes no diff noise; a rotated one shows as a change without the value appearing.
Proves the record
Every version is encrypted, deduplicated and hash-chained. The evidence pack is signed, and a recipient verifies it with no vault, no configuration and no passphrase — one edited number and it fails.
Restores with a person in command
Device-changing steps exist only inside an approved change session, and every approval is signed by an authenticated identity. There is no unattended push, and no configuration key that would enable one.
Where BackZone sits, and why
Two axes, because the obvious ones do not separate anything. Almost every product here is on-premise — SolarWinds NCM has no SaaS at all, ManageEngine is fully on-premise, Oxidized installs on your own box — so “cloud versus on-premise” sorts nobody.
What does separate them for a bank is whether the product needs anything outside the bank to work, and whether what it produces can be handed to an examiner.
- How to read it
- Both axes are ordinal, not measured. Every position below carries the reason it sits where it does, drawn from each vendor’s own published material — a quadrant you cannot argue with is not analysis.
- BackZone
- No update channel, no licence server, no telemetry, no call-home; vendored offline build. Hash-chained versions, Ed25519-signed packs that verify with no vault, secrets redacted at every boundary.
- BackBox
- On-premise ISO and genuinely well supported, but updates come from updates.backbox.com, the vulnerability module needs live NVD/CISA feeds, the Cisco check calls Cisco's own web service, the MLSA reserves remote access and the licence is bound to the server IP. Session recording, RBAC and approval workflows are documented; a tamper-evident chained log is not.
- SolarWinds NCM
- Self-hosted only, no SaaS SKU — but the main server is Windows-only and it is licensed and sized as part of a platform. No tamper-evident chain described in public material.
- ManageEngine NCM
- Fully on-premise and agentless, with a bundled database; licensing is per-device and gated behind a quote. Roughly 80 vendors and 280 device templates published.
- Unimus
- Self-hosted commercial, no SaaS, and the only vendor here that publishes its prices. A JVM application; backup and change tracking rather than evidence.
- Oxidized · RANCID
- No licence server, no phone-home, no SaaS — as independent as it gets. But configurations land in git in plaintext with secrets included, there is no RBAC, no signed artefact and no chain a regulator would accept.
- Vendor-native managers
- FortiManager, Panorama, SmartCenter, FMC, Catalyst Center. Deep and correct for one vendor and already paid for — but single-vendor by construction, and the manager sits inside the same blast radius as the estate it protects.
The reporting portal, on a worked estate
A generated, self-contained page: eleven views, most of them available as a table, a treemap or a reachability map. It loads nothing from anywhere and prints to A4.
Open the demonstration Access code required · synthetic estate, no real bank