Verified backups
Signed backups with firewall details visible before restore
ConfigVault verifies backup integrity and shows model, serial and version context before any restore action is prepared.

Product profile
A built preview Windows collector for scheduled, encrypted Palo Alto Networks firewall configuration backup workflows designed around MSP operating routines.
Built Windows collector
ConfigVault runs locally, backs up Palo Alto Networks firewall configurations on a schedule, signs and encrypts each backup, and keeps restore control in the customer's hands.

Verified backups
ConfigVault verifies backup integrity and shows model, serial and version context before any restore action is prepared.

Controlled restore
ConfigVault uploads a verified configuration as a named snapshot. The firewall administrator still reviews, loads and commits through the normal device workflow.

Recovery key boundary
Backups are encrypted and signed by the collector. Opening one requires the customer-held recovery key, whether through the console or offline restore tools.

Trust changes
Certificate pinning helps make unexpected management-plane changes visible. A firewall resumes backup only after the new certificate is reviewed and trusted.

Operating model
ConfigVault keeps management local, makes backup state easy to scan and gives support teams diagnostics without collecting customer configurations through the public website.
Destinations
Choose a storage target that fits the customer environment, with per-firewall retention for folder and share destinations.
Local only
The console is designed for local administration. It is not a public portal and does not open an inbound management surface.
Diagnostics
Diagnostics explain collector state and support export handover without exposing passwords, recovery keys or configuration content.
Compliance evidence
ConfigVault does not prove compliance on its own. It creates repeatable backup, restore and change-control evidence that can support wider assurance work.
ISO/IEC 27001:2022
Scheduled protected backups, certificate review and staged restore records can support ISO 27001 conversations around operational control, configuration management and risk treatment.
PCI DSS v4.0
For cardholder-data environments, ConfigVault can help evidence firewall backup discipline, retained configuration snapshots and controlled restore handling alongside PCI DSS segmentation and change reviews.
Cyber Essentials
Recent configuration backups give MSPs a cleaner operating baseline when reviewing secure configuration, internet-edge exposure and remediation rollback planning.

Preview boundary