The configuration vault — backup, compliance & vulnerability
Keep is the vault for your security and network device configs: agentless, vendor-native backups across 50+ vendors, tested and integrity-verified so a restore actually works. It remediates vulnerabilities and pushes firmware upgrades centrally, audits configs against ISO 27001, BDDK and PCI DSS, and surfaces the CVEs on every device.
Backup you can actually restore — and act on
Keep vaults each config the vendor's way, proves it's intact, and turns it into compliance and remediation.
- 1
Vault
Speak each platform's own backup path — agentless, vendor-native across 50+ vendors — and store every config encrypted.
- 2
Verify
Backup-test, integrity-check and size-verify every artifact, so a silent or truncated backup never passes as good.
- 3
Assure
Audit configs against ISO 27001, BDDK and PCI DSS, surface each device's CVEs, and remediate or roll back in minutes.
Every backup, proven — not just green.
The fleet view shows each device's vendor, last backup, and status; open a run to watch the connect → capture → verify pipeline clear all five integrity checks before you ever trust a restore.
What it does
Agentless, vendor-native vault
Speaks each platform's own backup path — firewalls, routers, switches, SIEM/SOAR, load balancers, 50+ vendors — and vaults every config encrypted, with no fragile scraping.
Tested & verified backups
Every artifact is backup-tested, integrity-checked and size-verified, so a silent or truncated backup never passes as good — a restore you've actually proven.
Automated remediation
Remediate vulnerabilities and push version and firmware upgrades from one place — central automation across the fleet, not device-by-device console work.
Compliance reporting
Audit backed-up configs against ISO 27001, BDDK, PCI DSS and other local and foreign frameworks, and hand auditors a ready-made report.
Vulnerability intelligence
Surface the known CVEs on every backed-up and integrated device, so a missing patch or end-of-life box never hides in the fleet.
Why teams run Keep
- ✓ Sleep on a restore you've actually tested — not a backup job that only looked green.
- ✓ Remediate vulnerabilities and push firmware upgrades centrally, instead of one console at a time.
- ✓ Hand auditors ISO 27001, BDDK and PCI DSS reports straight from your real device configs.
- ✓ See the known CVEs on every device, and catch unauthorized config change against a signed baseline.
- ✓ One vault across firewalls, routers, switches, SIEM/SOAR and load balancers — 50+ vendors, agentless.
Fleet posture
last 24hPart of the Seraxi platform
See Seraxi on your environment.
Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.