Built Windows collector

Know every firewall has a recent, protected backup

ConfigVault runs locally, backs up Palo Alto Networks firewall configurations on a schedule, signs and encrypts each backup, and keeps restore control in the customer's hands.

Local consoleEncrypted .cvb backupsRecovery-key restoreCertificate pinning
ConfigVault overview showing healthy backups, the next scheduled run and five protected firewalls
OverviewSee backup health, the next run and where backups go at a glance.
PAN-OS backupScheduled configuration backup through a Windows collector.
Encrypted and signedBackups are sealed before they leave the collector.
Customer-held keyThe collector cannot open its own backups without the recovery key.
Review before commitRestores are staged only. Nothing is loaded or committed automatically.

Verified backups

Signed backups with firewall details visible before restore

ConfigVault verifies backup integrity and shows model, serial and version context before any restore action is prepared.

A verified ConfigVault backup showing firewall details and the option to stage it on a firewall
Verified backupEvery backup is signed and checked before it can be restored.

Controlled restore

Stage the configuration, then review and commit on the firewall

ConfigVault uploads a verified configuration as a named snapshot. The firewall administrator still reviews, loads and commits through the normal device workflow.

Restore staged on a firewall with web interface and CLI steps to load, review and commit
Restore stagingConfigVault stages the configuration. You review and commit on the firewall.

Recovery key boundary

The collector cannot read sealed backups by itself

Backups are encrypted and signed by the collector. Opening one requires the customer-held recovery key, whether through the console or offline restore tools.

ConfigVault backup encryption settings showing the recovery key ID
Encryption settingsSigned, encrypted and only readable with the recovery key.

Trust changes

Backups pause if the firewall certificate changes

Certificate pinning helps make unexpected management-plane changes visible. A firewall resumes backup only after the new certificate is reviewed and trusted.

ConfigVault alerting that a firewall management certificate has changed and pausing its backups
Certificate reviewIf a firewall certificate changes unexpectedly, ConfigVault stops and asks.

Operating model

Built for controlled MSP backup routines

ConfigVault keeps management local, makes backup state easy to scan and gives support teams diagnostics without collecting customer configurations through the public website.

Destinations

Local folder, file share or Amazon S3

Choose a storage target that fits the customer environment, with per-firewall retention for folder and share destinations.

Diagnostics

Plain-English health checks

Diagnostics explain collector state and support export handover without exposing passwords, recovery keys or configuration content.

Compliance evidence

Backup evidence broken out by standard

ConfigVault does not prove compliance on its own. It creates repeatable backup, restore and change-control evidence that can support wider assurance work.

PCI DSS v4.0

Firewall control and segmentation evidence

For cardholder-data environments, ConfigVault can help evidence firewall backup discipline, retained configuration snapshots and controlled restore handling alongside PCI DSS segmentation and change reviews.

Cyber Essentials

Secure configuration support

Recent configuration backups give MSPs a cleaner operating baseline when reviewing secure configuration, internet-edge exposure and remediation rollback planning.

ConfigVault diagnostics with plain-English health checks
DiagnosticsPlain-English diagnostics, with a sanitised export for support.

Preview boundary

Public website boundary stays strict

  • Palo Alto Networks PAN-OS backup workflow only.
  • No firewall uploads, credentials, recovery keys or backup files are collected by this website.
  • Restore staging never loads or commits automatically.
  • Deployment, support and licensing details are agreed per environment.