See, standardise and secure every firewall you run.

ThisFirewall is two products in one platform. Fleet & Config gives you instant visibility of every firewall - configuration, licensing, standards and performance - with no log forwarding. Switch on Threat & SIEM to unlock threat hunting, UEBA and egress intelligence over your logs. Any firewall. Read-only. Your data stays yours.

Live in an afternoon Read-only toward your firewalls Bring your own AI key Your data stays yours
FortiGate 6501F photo by Premeditated, Wikimedia Commons, CC BY-SA 4.0
app.thisfirewall.com / overview LIVE17 firewalls
Global activity & threats12 active
13:02:41CRITc2_beaconing 172.20.14.7 → 203.0.113.200 / 120s
13:02:18HIGHioc_match 198.51.100.0/24 → SSL-VPN :10443
13:01:55OTmodbus PLC-3 → HMI-1 · OT→OT · normal
13:01:30INFOnew_geo_login user j.diaz · VPN · NL
Fleet posture14/17 healthy
12
Open threats
58
Seg. score
L1
OT maturity
Outbound to known-malicious IP
RBM-EDGE-FW01 · allowed · St Kitts AS · needs block + EDR
Throughput · 24h
Reads the firewalls you already run · multi-vendor by design
FortiGate live Palo Alto roadmap Cisco ASA / FTD roadmap Sophos roadmap Check Point roadmap pfSense / OPNsense roadmap
What you can stand behind
Every firewall
Multi-vendor by design - reads the telemetry you already collect
21+ hunts
Behavioural detections - scored, deduplicated and FP-tuned
Read-only
Never touches your firewall - telemetry in, nothing pushed back
Audit-ready
Maturity scorecard & compliance evidence from real data
Two systems, one platform

Two systems. One platform. Two steps.

Begin with Step 1 - fleet visibility on the day you connect. Switch on Step 2 - the SIEM - whenever you are ready. Same login, same data, nothing to re-learn.

01 Step 1 · Start hereFleet & Config

See and standardise every firewall

Point us at your firewalls and, within an afternoon, see every device you manage - no log forwarding, no agents, read-only.

No log forwarding required
  • Configuration posture, hygiene & drift
  • Licensing & FortiGuard expiry across the fleet
  • Standards alignment & policy analysis
  • Performance, upgrade & migration planning
  • Fleet health monitoring - auto root-cause & ticketing
  • Config AI: misconfiguration, optimisation & "why is this slow?" diagnostics
Live in an afternoon · read-only API access
02 Step 2 · ActivateThreat & SIEM

Switch on the SIEM

Forward your firewall logs to unlock full threat detection and investigation - built on the telemetry your firewalls already produce.

The activation - add log forwarding
  • Threat hunting, live alerts & incidents
  • UEBA - user & entity behaviour analytics
  • Egress & exfiltration intelligence
  • Shadow IT & shadow-AI usage, per user and client
  • Identity risk (M365) & compromised-host verdicts
  • Attack stories & MITRE ATT&CK coverage
  • AI threat-hunting copilot over your logs
Built on the logs your firewalls already send
One platform · one login · one bill - start with Step 1, switch on Step 2 anytime.
How it works

From raw firewall logs to evidence, in five stages.

Firewall logs are millions of lines no human can read. ThisFirewall processes every flow through a fixed, auditable pipeline - until what remains is a clear, named, actionable record.

01

Ingest

Syslog from every firewall, any vendor, into one platform. No agents.

02

Enrich

Every IP, ASN, application, country and identity resolved - locally, in real time.

03

Hunt

21+ behavioural hunts turn noise into named threats - scored, deduplicated, tuned.

04

Illuminate

OT traffic, the IT/OT boundary and dwell time - made visible from the same stream.

05

Prove

A maturity scorecard and compliance evidence your board and auditor will read.

A worked example

What an actionable record looks like.

A real-shape incident, anonymised. Six raw signals correlated into one narrative and one decision.

Attack story · auto-assembled

A quiet workstation was beaconing to St Kitts every two minutes.

A host behind RBM-EDGE-FW01 made a near-perfect 120-second outbound connection to a freshly-allocated Caribbean IP - the heartbeat signature of command-and-control. The firewall allowed it. ThisFirewall resolved the destination's owner, correlated four separate signals into one timeline, and surfaced it as a single critical record instead of four orphan alerts.

Verdict: real C2-shape beacon, allowed by policy. Recommended action: block the /21 outbound and deploy EDR on the host. One click to a ticket.
07:32ioc_match - outbound destination on a threat feed (GreenSnow)
07:32c2_beaconing - 120s ± 5s interval, 99% regularity
07:33enrich - destination owner = newly-allocated St Kitts ASN
07:34correlate - 4 signals → 1 record, scored 95
07:34propose - block 203.0.113.0/24 + EDR on host
One platform

Everything your firewalls know, on one pane.

ThisFirewall is a full security-analytics platform, not a point tool. Each capability reads the same enriched stream, so a threat, a flow and a device are always one click apart.

Log Search & Sessions

Every firewall log, searchable in seconds - sessions, flows and identities across the whole fleet.

Threat Hunting

21+ behavioural hunts (beaconing, brute-force, exfil, recon) with scoring, dedup and FP-tuning built in - plus proactive alerts on detection-coverage gaps and rule regressions.

Attack Stories

Scattered alerts auto-correlated into one timeline with a verdict and a recommended action.

Egress & Exfil Intel

Learns each application's normal destinations and flags the drift - data leaving where it never has before.

NEW

Shadow IT & Shadow-AI

Every unsanctioned app - GenAI, P2P, proxies, consumer storage - surfaced per user, host and client. The AI tools your staff actually use, with the data they upload.

NEW

Signal, not noise

Known-benign patterns auto-suppress on evidence - a staff member pasting context into a generative-AI assistant is filed as shadow-AI, not a critical "exfiltration" alert. Your queue stays the threats that matter.

OT / Industrial Visibility

Modbus, DNP3, S7, OPC-UA and peers classified as first-class - the OT traffic you couldn't see.

Segmentation Analyzer

The IT↔OT zone matrix, a boundary score, and review-only policy to close the gaps.

Dwell-time KPI

How long threats ran before detection - the metric your board now asks for, from your own data.

Maturity Scorecard

Scored against the industry L0-L4 ladder from observed evidence, not a self-assessment.

Fleet & Compliance

Firmware/KEV exposure, config posture, versioned config backups, and audit-ready evidence - delivered live or as a scheduled report your board can read.

NEW

"Why is this slow?"

A user reports slow or broken browsing. ThisFirewall's AI reads that one device's actual configuration and diagnoses the cause directly - no packet capture, no agent, no guesswork.

NEW

Fleet Health & Auto-Ticketing

When a firewall goes quiet, ThisFirewall tells you whether it's the device or the pipeline, raises the flag, and opens the ticket - then closes it itself the moment the device recovers.

NEW

Identity & User Risk

Microsoft 365 sign-in risk, MFA and conditional-access signals correlated against firewall and VPN activity, per user - plus a live inventory of every personal device that's joined your network.

Scorecards & Verdicts

Every signal touching a host rolls up into one Clean/Suspicious/Compromised verdict; every device rolls up into a graded A-F security rating and live ISO 27001 control alignment.

See every flow

Know what's actually talking on your network

ThisFirewall classifies every flow your firewall sees - work, OT, remote-access, shadow-AI, risky - and maps the devices behind them. The traffic you've been paying to log finally tells you something.

  • Industrial protocols pulled out of "Other" and named
  • Shadow-AI and shadow-IT surfaced per user and host
  • Per-site, per-client and per-device breakdowns
Traffic by category · 24hlive
Cloud / CDN · 31%
Work · 23%
OT / Industrial · 16%
Remote access · 12%
Shadow AI · 10%
Risky · 8%
Close the boundary

See - and propose - the IT/OT boundary

Tag your interfaces and ThisFirewall builds the zone-to-zone matrix from real traffic, flags every IT↔OT crossing and Internet→OT path, scores the boundary, and drafts review-only firewall policy to close it. Read-only, always.

  • Worst crossings first, scored by exploitability
  • A 0-100 boundary score your auditor understands
  • Review-only CLI - ThisFirewall never touches your firewall
Zone matrix · sessions58 / 100 · C
IT
OT
DMZ
WAN
IT
-
HIGH
·
ok
OT
HIGH
-
·
EGR
WAN
vip
CRIT
·
-
1 critical · 2 high crossings · proposal ready
Measure what matters

The dwell-time number, and the climb to the next level

ThisFirewall measures how long activity ran before you caught it - in the same bands the industry survey uses - and scores your OT maturity against the L0-L4 ladder from what it observes. Evidence, not a questionnaire.

  • Median dwell, longest dwell, weeks/months danger zone
  • A maturity level you've genuinely earned
  • The exact next rung, with the gaps to close
Dwell-time · 90dmedian 6m
Minutes62%
Hours24%
Days9%
Weeks4%
Months1%
L1Visibility & segmentationyou are here
L2Access & profilingnext →
Read the config, not the packets

"Why is this slow?" - answered from the firewall alone

A user reports slow or broken browsing - a site that won't load, a login that hangs - while the same laptop is fine on 5G. ThisFirewall's AI reads that device's actual configuration (SSL inspection, MSS/MTU, DNS path, WAN health) and diagnoses the cause directly, instead of a forum thread and a guess.

  • No packet capture, and nothing installed on the endpoint
  • Findings are grounded in the real config - the AI never invents one
  • Propose-only: you apply the fix in your own change window
Diagnosis · device config2 findings
TCP MSS not clamped on the internet-egress policy
Large TLS handshakes (SSO, M365 sign-in) can silently drop over the tunnel - fast on 5G, slow here.
DHCP is handing out the firewall as DNS
Adds a resolution hop most users never notice - until it's the difference.
Inside the product

The actual screens, not mockups.

Every view below is the real ThisFirewall console, shown on a read-only demo of a fictional fleet. This is what your team works in.

ThisFirewall Threat Hunt console showing the library of behavioural hunts, each mapped to MITRE ATT&CK
Threat Hunting21+ behavioural hunts (beaconing, brute-force, exfil, recon, shadow IT), each mapped to MITRE ATT&CK, run on demand or on schedule.
OT Security Maturity scorecard showing the L0 to L4 ladder scored from observed evidence
OT MaturityYour OT security scored against the L0-L4 ladder from what ThisFirewall actually observes, never a questionnaire. The exact next rung, with the gaps to close.
Dwell-time dashboard showing detection latency bucketed into the industry report bands
Dwell TimeHow long activity ran before you caught it, in the industry report's own bands. Median dwell and time-to-resolve, computed from your own detections.
Upgrade Advisor showing pending firmware cross-referenced against known-issue reports and Fortinet recommendations
Upgrade AdvisorEach device's pending firmware cross-referenced against curated known-issue reports and the Fortinet-recommended release, so a regression never ships by accident.
Who it's for

Built for the teams who run real things.

Whether you're a SecOps lead, a plant engineer, an MSP, or the person who has to answer the auditor - ThisFirewall meets you where you are.

SecOps & SOC

One pane across every firewall. Threat records instead of alert floods, with dwell-time you can report.

Plant & OT teams

See the OT traffic and the IT/OT boundary - without a sensor on the line or a touch to the firewall.

MSPs

Multi-client, multi-firewall, one console. Sell OT visibility and posture as a managed service.

Risk & compliance

Maturity and dwell-time evidence mapped to the standards procurement and regulators ask for.

Works with what you run

No rip-and-replace. Point your firewalls at us.

ThisFirewall reads firewall telemetry and enriches it locally. Send syslog, add a read-only API user, and you're live - no new hardware on the network.

FortiGatelive
Syslog / CEFstandard
CISA KEVfeed
Threat feedsbuilt-in

On the roadmap? Click any vendor above to join its waitlist and we'll email you the moment support ships.

23%
of operators see only about half their OT network
rise in weeks/months attacker dwell time, year on year
89%
expect new OT regulation within five years
#1
control operators name: segmentation - still unbuilt
Source: Fortinet, 2026 State of Operational Technology and Cybersecurity Report (700+ OT leaders). ThisFirewall closes these gaps from the firewalls you already run.
Why ThisFirewall

The platform approach, not another point tool.

Read-only, propose-only

ThisFirewall never writes to your firewalls. Policy suggestions are review-only - you stay in control, always.

No new sensors or agents

It reads the telemetry you already collect. Nothing to deploy on the plant floor, nothing to maintain.

Vendor-neutral by design

Built to read any firewall's logs. Consolidate onto one pane instead of a tool per vendor.

Your data stays yours

Single-tenant deployment available. We don't pool your logs or sell your data - ever.

Where the line is

ThisFirewall reads from the firewall, so it sees the cross-zone traffic that segmentation actually governs - not the intra-VLAN PLC chatter or ICS function-code internals that need a passive in-plant sensor. We tell you that up front. For most operators, serious security analytics from the infrastructure you already own is the right first move - and the one the industry data says is missing.

Deployment & hosting

Run it where you need it to run.

Self-host it, or let us run it for you - in the region and jurisdiction you choose. Single-tenant either way; your data is never pooled.

Self-hosted

In your own datacentre or cloud. ThisFirewall ships as Docker on Ubuntu - you hold the box, the data and the keys. We provide the images, a deployment runbook and support.

We host it for you

A fully managed, single-tenant instance in our datacentre, in the region you choose. We run the ops, updates, monitoring and backups - you just use the console.

Your region, your sovereignty

Choose the jurisdiction - New Zealand, Australia, the EU, or your own. Single-tenant, database-per-tenant isolation; your data stays in-region and is never moved cross-border without your say.

Whichever model you pick, the guarantees are the same: read-only toward your firewalls, your raw logs never leave your instance, and nothing is sent to a third party beyond the dependency register we disclose up front. Moving between self-hosted and managed later is supported - it is the same platform.

Commercial · Introductory pricing

Priced for the firewalls you run, not per seat.

Introductory rates for the customers who come on board first. One simple price per firewall, per month - it gets cheaper as your fleet grows. Built for MSPs, internal IT teams and SOCs. Hosting is separate, so you choose where it runs.

Small

1-5 firewalls
$55per firewall / month
Introductory rate

A single site or a handful of branches.

Most popular

Growth

5-25 firewalls
$42per firewall / month
Introductory rate

A growing MSP book or a multi-site business.

Scale

25-100 firewalls
$30per firewall / month
Introductory rate

An established MSP or SOC fleet.

Fleet

100+ firewalls
$20per firewall / month
Introductory rate

A large MSP, enterprise or national SOC.

Every plan is the full platform: threat detection and hunting, egress and shadow-AI, identity risk, fleet health monitoring, OT visibility, config posture, dwell-time and compliance evidence. No feature gates by fleet size. Introductory pricing for our first customers - around 25% off again when you pay annually. Hosting (self-hosted, fully managed, or a dedicated instance in your region) is quoted separately.

FAQ

The questions operators ask first.

Does ThisFirewall touch or change my firewall?

No. It's read-only toward your firewalls. Policy proposals are review-only CLI you apply yourself, in your own change window.

Do I need new hardware or agents?

No sensors, no agents, no span ports. ThisFirewall ingests the syslog you already send and reads via a read-only API user.

Which firewalls do you support?

FortiGate today, with Palo Alto, Cisco, Sophos, Check Point and pfSense on the roadmap. Standard syslog/CEF works broadly - tell us what you run.

Where does my data live?

On infrastructure we agree with you - including a dedicated, single-tenant instance in your region. Your data stays yours; we don't pool it.

How fast can we be live?

An afternoon for the first firewall: point syslog at ThisFirewall, add a read-only API user, and the dashboards populate from day one.

Can it see inside my ICS protocols?

It sees cross-zone OT traffic at the firewall - what segmentation governs. Deep function-code inspection needs an in-plant sensor; we're honest about that line.

Is this introductory pricing permanent?

These are introductory rates for the customers who join us first, while we're still onboarding early deployments. Ask your contact for the specifics before you commit to a term.

Technical FAQ

For your security and infrastructure team.

The detail a security review asks for. For the full picture, read the Technical & Security Overview.

What OS and infrastructure does it run on?

Ubuntu 24.04 LTS (kernel 6.8) under Docker. A single instance runs comfortably on ~4 vCPU and 16 GB RAM, plus block storage sized to your log volume and retention. Deploy on Hetzner, your own cloud, or on-prem.

What is the data architecture?

A SQLite control/application database plus a ClickHouse columnar store for firewall logs. Tenants are isolated as one database per tenant. Backups are on-host, encrypted, and restore-tested.

What leaves my network, and what is sent to third parties?

Your raw logs never leave your instance. Outbound calls are limited and disclosed: Microsoft Entra ID for SSO (no passwords are stored), optional AI on your own key with sanitised, tenant-scoped prompts, and threat-intel feeds that receive only public IPs and indicators. Full dependency register on request.

How is data secured, at rest and in transit?

TLS 1.2/1.3 in transit, including syslog over TLS (6514). Credentials and API keys are encrypted at rest with AES-256-GCM. The log store is bound to loopback, and the host firewall exposes only SSH (IP-locked) and 443.

How is multi-tenant isolation enforced?

Database-per-tenant, with tenant-scoped access enforced on every read and write. For single-customer isolation, a dedicated single-tenant instance is available.

Is it genuinely read-only toward my firewalls?

Yes. Ingest is syslog plus a read-only API user. The only policy output is review-only CLI we generate for you to apply in your own change window. ThisFirewall never pushes configuration.

How do authentication, access control and audit work?

Microsoft Entra ID SSO, role-based access scoped per client and per site, and a tamper-evident (SHA-256 hash-chained) audit trail recording who saw what, from where.

Is AI required, and where does it run?

Optional. Bring your own OpenAI or Anthropic key, or run a local LLM. Prompts are sanitised, tenant-scoped and token-minimised, no model is trained on your data, and the platform is fully usable with AI off.

Where is my data hosted, and can it stay in-region?

Hosting and region are agreed with you and configurable per deployment, including AU/NZ for data-sovereignty requirements. Your data is never pooled with other customers.

What compliance frameworks does it align to?

Engineered to ISO 27001 and SOC 2 principles, GDPR Article 32 security-of-processing, and the NZ Privacy Act 2020 (IPP5 and IPP12), with live control-evidence views in the product.

Complimentary · no commitment

Get a free Firewall Exposure Check.

Point one firewall at ThisFirewall for 24 hours - or send us a config export - and we'll return a report: your OT footprint, your IT↔OT segmentation boundary, your dwell-time baseline, and the exposures worth fixing first. Read-only. Yours to keep.

1 Connect one firewall (or upload a config) 2 We analyse 24h of telemetry, read-only 3 You receive a report and a 30-minute walkthrough
Your report includes
  • OT / industrial traffic, classified
  • IT↔OT boundary score and risky crossings
  • Dwell-time baseline versus the industry
  • Top exposures, prioritised to fix
Request the check
Security & trust

Built to be trusted with your security data.

You're handing a platform your firewall telemetry. Here is exactly how we treat it - architecture first, promises second.

Read-only by design

ThisFirewall never changes your firewalls. It ingests the syslog you already send and reads via a read-only API user. Every policy suggestion is review-only CLI you apply yourself.

Your data stays yours

Single-tenant deployment option, hosted in your region. Encrypted in transit (TLS 1.2/1.3), with credentials and API keys encrypted at rest. We never pool your data with other customers and never train models on it.

Compliance-aligned

Engineered to the controls enterprise procurement expects - ISO 27001 and SOC 2 principles, the NZ Privacy Act 2020, and GDPR-ready data handling - so security reviews go smoothly.

Access you control

SSO and role-based access, scoped per client and per site. An immutable audit trail records who saw what, from where - your evidence, on demand.

Bring your own AI key · BYOK

The AI runs on your key - not ours.

Connect your own OpenAI or Anthropic account, or point ThisFirewall at a fully local, self-hosted model. Your key, your model, your spend - we never mark up AI tokens and never route your telemetry through our AI accounts. Run a local LLM and your data never leaves your environment at all. And because it's your spend, ThisFirewall is token-minimised by default - response caching, prompt trimming and per-tenant budgets keep usage as low as possible. AI is opt-in, per-feature, and entirely under your control.

OpenAI Anthropic Local / self-hosted LLM No token markup Token-minimised · cache + budgets Opt-in & per-feature
Bring your own AI key ISO 27001-aligned SOC 2-aligned NZ Privacy Act 2020 GDPR-ready Read-only Encrypted at rest & in transit Single-tenant option Full audit trail
Request a demo

See your own network in a 30-minute demo.

Tell us about your environment and we'll show you your OT footprint, segmentation boundary and dwell-time numbers - from a firewall you already run.

  • No new sensors, agents or hardware
  • Read-only and propose-only toward your firewalls
  • A walkthrough with an engineer, not a sales script
  • A clear per-firewall quote and a pilot you can scope
Prefer email? [email protected] · A Belton IT Nexus product.
We use your details only to respond to this request. No spam, no list-selling.