Firewall audit software for MSPs & MSSPs

Turn firewall reviews into
a recurring managed service.

Scan every client's FortiGate, Palo Alto, Sophos, Check Point, or Cisco ASA config and deliver posture scores, attack-path findings, compliance evidence, and ready-to-paste remediation — in minutes, without agents, API access, or storing a single raw config.

Bulk-import a whole client estate. Per-tenant isolation. White-label reports.

A new recurring line item

Add a quarterly Firewall Exposure Review to every managed-security contract. Repeatable, billable revenue from configs you already hold — not another tool sitting unused.

Nothing to deploy

No agent, no API keys, no firewall credentials. Export the config the client already has, drop it in. The raw config is parsed in memory and never written to disk or database.

Client- and auditor-ready

Posture score, prioritized findings, attack paths, and vendor-specific CLI fixes — packaged as an evidence export a client executive or auditor can actually read.

Built for managing a fleet, not one box

Fleet dashboard — every client firewall in one view, with a composite risk score, firmware alerts, and configuration drift across the whole managed estate
Scheduled rescans — monthly or quarterly automated re-audits that catch drift before it becomes a compliance gap or a breach path
Per-client posture scoring — each tenant gets its own score, severity breakdown, and trend, so you can demonstrate measurable improvement over time
Audit evidence packages — export a client's full scan history, findings, and remediation status as a structured package, ready for compliance reviews
Team access with RBAC — owner / admin / analyst / read-only roles, with each client's data siloed by tenant
Bulk import — upload a ZIP of multiple client configs in one pass; all parsed in memory simultaneously, no config ever reaches another tenant
Five platforms, vendor-specific fixes — FortiGate, Palo Alto, Sophos, Check Point, and Cisco ASA, each finding shipping paste-ready CLI remediation for that platform
Firmware CVE matching — versions cross-referenced against CISA KEV, NVD, and vendor advisories, filtered to features actually enabled in the config

A quarterly review, without the quarterly scramble

Manual firewall reviewCRWLR
Time per firewallHours of line-by-line rule readingA scan in about a minute
ConsistencyVaries with whoever runs itThe same engine, every client, every time
CoverageWhatever the reviewer remembers to check175 checks across policy, zones, profiles, VPN, firmware
Drift between reviewsInvisible until the next manual passScheduled rescans flag drift automatically
EvidenceA hand-written document to assembleStructured evidence package, exported
Scaling to a fleetLinear effort per clientBulk import + one fleet dashboard

Founding MSP Partner pilot — limited

Run five client firewall reviews on us.

We're onboarding a small group of founding MSP partners. You get a 60-day pilot to put CRWLR in front of real clients and see what converts — with direct founder support the whole way.

Five client firewall audits, free
60-day pilot, white-label reports
Direct founder support
Discounted first-year fleet pricing

In return, we ask for your honest feedback and — only if you get real value — permission to publish an anonymized or named case study.

Apply for the pilot →

Fleet-based pricing

Priced around your estate, not per seat — per-tenant pricing with white-label options. Tell us your fleet size and we'll put together a fixed price.

MSP questions

How is CRWLR priced for MSPs?

Fleet-based, not per seat. We offer per-tenant pricing and white-label report options sized to your estate. Tell us how many client firewalls you manage at contact@crwlr.io and we will put together a fixed fleet price — no tiers to squeeze into.

Can I white-label the reports for my clients?

Yes. Per-tenant pricing includes white-label report options, so the posture report, evidence package, and remediation guidance go to your client as your deliverable.

How many client firewalls can I manage?

There is no per-device or per-seat cap — firewalls per tenant are unlimited. Bulk import lets you drop a ZIP of multiple client configs in a single pass; each is parsed in memory simultaneously and no config ever reaches another tenant.

Is each client’s data isolated?

Yes. Every client lives in its own tenant with row-level isolation, and team access is governed by role-based access control (owner / admin / analyst / read-only) so engineers see only the clients they should.

Do I need firewall access, an agent, or API keys?

None of those. You export the configuration the client already has (or that you hold) and upload it. There is no agent to deploy, no API access to broker, and no firewall credentials to manage. The raw config is parsed in memory and discarded at the end of the scan.

Which platforms are supported?

FortiGate (FortiOS), Palo Alto (PAN-OS), Sophos (SFOS XML and PostgreSQL dump), Check Point (R80+ mgmt_cli and Gaia clish), and Cisco ASA. Every finding ships with vendor-specific, paste-ready CLI remediation for that platform.

Can I show the output to a client or an auditor?

Yes — that is the point. Each scan produces a posture score, prioritized findings with severity, attack paths, and an exportable evidence package designed to be read by a client executive or an auditor, not just an engineer. 175 checks map to CIS, PCI DSS, and NIST references.

Add a Firewall Exposure Review to every contract.

No agent, no API access, raw configs never stored. Start free, or apply for the founding-MSP pilot.

Apply for the pilot →
Firewall Audit Software for MSPs — Recurring Managed Service | CRWLR