Seraxi
Seraxi Keep

The configuration vault — backup, compliance & vulnerability

Keep is the vault for your security and network device configs: agentless, vendor-native backups across 50+ vendors, tested and integrity-verified so a restore actually works. It remediates vulnerabilities and pushes firmware upgrades centrally, audits configs against ISO 27001, BDDK and PCI DSS, and surfaces the CVEs on every device.

Backup you can actually restore — and act on

Keep vaults each config the vendor's way, proves it's intact, and turns it into compliance and remediation.

  1. 1

    Vault

    Speak each platform's own backup path — agentless, vendor-native across 50+ vendors — and store every config encrypted.

  2. 2

    Verify

    Backup-test, integrity-check and size-verify every artifact, so a silent or truncated backup never passes as good.

  3. 3

    Assure

    Audit configs against ISO 27001, BDDK and PCI DSS, surface each device's CVEs, and remediate or roll back in minutes.

See it in action

Every backup, proven — not just green.

The fleet view shows each device's vendor, last backup, and status; open a run to watch the connect → capture → verify pipeline clear all five integrity checks before you ever trust a restore.

keep · backups Backup fleet 142 devices · all vendors · last sweep 2m ago Verified 128 Drifted 3 Running 11 DEVICE VENDOR / MODEL LAST BACKUP SIZE STATUS edge-fw-01 backup · cfg + system Palo Alto PA-5410 2m ago 4.8 MB Verified core-fw-02 backup · cfg + system Fortinet FortiGate 600F 11m ago 2.1 MB Verified dmz-fw-03 backup · cfg + system Check Point 16000 Quantum running Running wan-rtr-07 backup · cfg + system Cisco Catalyst 8500 1h ago 318 KB Drifted adc-lb-04 backup · cfg + system F5 BIG-IP i5800 1h ago 12.4 MB Verified 5-step verification connect capture size hash restore-test
Backup fleet — vendor rows, status chips, last-backup times
keep · backups / edge-fw-01 / run #4471 edge-fw-01 Palo Alto PA-5410 · scheduled backup · completed in 3.4s Verified backup Connect vendor-native Capture running-config Verify 5 checks passed INTEGRITY CHECKS Connector handshake vendor-native API · TLS 1.3 Artifact captured running-config + system state Size within baseline 4.82 MB · Δ +0.3% vs prior SHA-256 verified 9f3c…a71e · signed Restore dry-run parsed & schema-valid ARTIFACT Size 4.82 MB SHA-256 9f3c…a71e Signed by keep-vault Retention 90 days · immutable Restore this config
One run — 5-step verification, size, hash, and restore

What it does

01

Agentless, vendor-native vault

Speaks each platform's own backup path — firewalls, routers, switches, SIEM/SOAR, load balancers, 50+ vendors — and vaults every config encrypted, with no fragile scraping.

02

Tested & verified backups

Every artifact is backup-tested, integrity-checked and size-verified, so a silent or truncated backup never passes as good — a restore you've actually proven.

03

Automated remediation

Remediate vulnerabilities and push version and firmware upgrades from one place — central automation across the fleet, not device-by-device console work.

04

Compliance reporting

Audit backed-up configs against ISO 27001, BDDK, PCI DSS and other local and foreign frameworks, and hand auditors a ready-made report.

05

Vulnerability intelligence

Surface the known CVEs on every backed-up and integrated device, so a missing patch or end-of-life box never hides in the fleet.

Why teams run Keep

  • Sleep on a restore you've actually tested — not a backup job that only looked green.
  • Remediate vulnerabilities and push firmware upgrades centrally, instead of one console at a time.
  • Hand auditors ISO 27001, BDDK and PCI DSS reports straight from your real device configs.
  • See the known CVEs on every device, and catch unauthorized config change against a signed baseline.
  • One vault across firewalls, routers, switches, SIEM/SOAR and load balancers — 50+ vendors, agentless.
keep · 512 devices live

Fleet posture

last 24h
99.4 %
Backed up
512
Devices
3
Config drift
2 m
Last run
509 / 512 in policy
3 awaiting tonight's window · 0 failed

See Seraxi on your environment.

Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.

Book a demo