Book a briefing

The archive a bank can put in front of an examiner

What it is

Capture · refuse · keep · prove · restore

BackZone captures the configuration of firewalls and network devices, refuses to store a capture it cannot prove is complete, and keeps every version encrypted, deduplicated and hash-chained on hardware you own.

It reports what changed since last night, evaluates 16 baseline rules against the latest capture, and produces a dated, signed evidence pack on the incident, quarterly and annual reporting rhythms. When a change goes wrong, it takes the estate one key back: a verified restore, executed inside your approval workflow.

EncryptedDeduplicatedHash-chained Signed packsVerified restoreNo unattended push

A capture that cannot prove completeness does not enter the vault

Capture → end-marker check → size guard ≥ 0.5× → vault. A capture that fails either guard is refused with BZ-E0407 and nothing is stored.

Device coverage

Every driver verified on hardware

19Drivers compiled in
19Lab-verified
19Restore proven
4Native-export

Every driver has been run against real hardware or a vendor VM image; the session transcript for each is a fixture in the repository, and a build test fails if any driver’s claimed status exceeds its evidence. Platforms that cannot prove completeness over SSH are captured through their own authoritative exports, ingested and manifest-verified.

Drivers are plain TOML: copy one, edit it, point driver_path at your copy — the supported workflow for estate-specific hardware, with the same verification harness available to your team.

The nineteen, as the driver files declare them
DriverPlatformVerificationCompleteness
fortiosFortiGate (FortiOS 6.x / 7.x)Lab-verifiedProvable
fortimanagerFortiManager 7.xLab-verifiedProvable
panosPAN-OS (PA-, VM-series)Lab-verifiedProvable
panoramaPanorama (M-series, virtual)Lab-verifiedProvable
cisco_iosIOS / IOS-XELab-verifiedProvable
cisco_asaASA (5500-X, ASAv)Lab-verifiedProvable
cisco_ftdSecure Firewall Threat DefenseLab-verifiedProvable
cisco_nxosNX-OS (Nexus 3000–9000)Lab-verifiedProvable
juniper_junosJunos (SRX, EX, MX)Lab-verifiedProvable
checkpoint_gaiaGaia OS (gateway, management)Lab-verifiedProvable
huawei_vrpVRP (S-series, AR, USG)Lab-verifiedProvable
mikrotik_routerosRouterOS (CCR, RB, CHR)Lab-verifiedProvable
f5_bigipBIG-IP (LTM, APM, ASM)Lab-verifiedProvable
aruba_aoscxAruba CX (AOS-CX 10.x)Lab-verifiedNative export
hpe_procurveProVision (2530–5400)Lab-verifiedNative export
sophos_sfosSophos Firewall / SFOSLab-verifiedNative export
symantec_proxysgProxySG / ASG (SGOS 6 / 7)Lab-verifiedNative export
tufin_securetrackSecureTrack / TOS AuroraLab-verifiedProvable
generic_sshAny SSH device, POSIX shellLab-verifiedProvable
Languages

Five interfaces, native-reviewed

Each catalogue is signed off by a named native reviewer recorded in the file
CodeLanguageReview status
enEnglishSource
haHausaNative-reviewed
yoYorùbáNative-reviewed
igIgboNative-reviewed
pcmNaijá (Nigerian Pidgin)Native-reviewed

A test blocks any catalogue from claiming native-reviewed without a named reviewer. Technical identifiers are never translated — device names, driver ids, CLI verbs and error codes stay ASCII, because a translated error code is unsearchable in a ticket.

Security

One AEAD · one KDF · one hash

A secret becomes a stable keyed fingerprint: HMAC-SHA256 under a vault subkey, truncated to four bytes. An unchanged secret makes no diff noise; a rotated one shows as a change without the value appearing.

set vpn ipsec psk S3cr3t!Br@nch-9   # on the wire
set vpn ipsec psk <redacted:psk:9f2c41ab>  # everywhere else

27 generic patterns plus per-driver patterns; a pattern without a (?P<secret>…) group, or with an invalid regex, is refused at compile time. 170 realistic secret-bearing lines across all 19 drivers run as a release gate that fails on a leak, a mask on the wrong token, or a clean line altered.

Redaction applies at every boundary that leaves the vault — show, diff, packs, alerts, any remote model call. Revealing a secret needs --with-secrets and BACKZONE_WITH_SECRETS=yes, and is audited.

SHA-256 content addresszstd -9AES-256-GCM Argon2idNo algorithm agilityNo key escrow

Evidence and reporting

A page your auditor can photocopy

backzone portal writes one self-contained HTML file: status, coverage, changes, compliance findings, gaps, device health, the automation log and the audit trail. No CDN, no font, no image, no src=, no analytics — it loads nothing from anywhere, reads the same air-gapped as connected, and cannot report that your auditor opened it.

Read-only by construction: each section names the command that performs the action. Every status is a word before it is a colour, because the page gets printed to A4 for the board pack and photocopied. A fresh estate renders an empty page, not a green tile.

IncidentQuarterlyAnnual MD / JSON / PDFEd25519-signedVerifies with no vault

A pack over an empty scope is refused rather than asserting full coverage of nothing; a device with no backup blocks the pack unless --include-gaps is passed, and the gaps are then named before the summary. The audit-chain head is embedded as an anchor and the verification instructions travel inside the signed bytes: a recipient checks the signature with no vault, no configuration and no passphrase — one edited number fails with BZ-E0904.

What the pack will not say

It states on its face that it is not a compliance opinion, and no rule cites a Nigerian clause number — enforced by a test proven capable of failing. BackZone reports technical control state; whether a control fact satisfies the CBN framework, the NDPA or PCI DSS is your compliance function’s judgement.

Design boundaries

What BackZone will not do — on purpose

A tool for a bank’s most sensitive network layer earns trust by having edges. Four territories, mapped so your architecture review can rely on them.

No unattended push — ever

Device-changing steps exist only inside an approved change session. restore.autonomous is not a configuration key.

Read-only by default

Day to day it captures, diffs and evidences. The write path can be disabled entirely by policy and the archive loses nothing.

Single node, replica DR

Recovery is a person with a runbook. No cluster on the evidence path.

No key escrow

The vault key never travels with the replica. Lose the passphrase and the data is gone — BZ-E0202 says so.

No cloud dependency

No update channel, no licence server, no telemetry, no call-home. It is whole in a segregated zone.

The archive and evidence layer

No OS or firmware patching, no rule-risk scoring, no alert workflow. Precise events out; your NOC owns the process.

Inference optional, offline

The summariser is deterministic and never states what it did not read; the model runtime ships disabled and loads only local weights.

Search is exact

Literal patterns and near-duplicates over stored configurations — every result traceable to a line.

Provenance on every artefact

Native-export platforms carry that origin for the life of the archive; the pack says how each byte was obtained.

The edge is the feature — a tool that cannot act alone cannot break a firewall at 02:00.

Get the paper

The product brief

Where BackZone sits against BackBox, SolarWinds NCM, ManageEngine, Oxidized/RANCID, Unimus and the vendor-native managers, and what a bank gets from choosing it.

Sent by email rather than published, because we would rather know who is reading it.

One address, stored to decide who to follow up with. Not sold, not shared, no tracking pixel, no newsletter.