Security / Analysis / Governance

Insights

Turning configurations into evidence.

Firewall policy analysis and tracking, connecting technical context to security decisions.

Original brand · conceptual composition
Context
Developed at Gantech
Authorship and contribution
Individual conception and execution
Current stage
Validated in development and a lab

01 / Insights

The starting point

A firewall configuration contains extensive information, but does not by itself provide a clear security posture assessment. Policies, devices, firmware, changes and evidence need to be connected.

Insights was created to organize that analysis over time, preserving what was observed and the context behind each result.

02 / What I built

Turning configurations into evidence.

I developed a portal that collects configurations in read-only mode, normalizes data and runs analyses against snapshots. Results remain linked to evidence, supporting the tracking of conditions and changes.

The architecture keeps security decisions with a person. The system organizes evidence and recommendations without directly changing firewall configurations.

03 / Capabilities and deliverables

Capabilities and deliverables

01

Collection and snapshots

Read-only PAN-OS and Panorama sources, normalization and preserved observations with identity and history.

02

Versioned analyses

Policy and posture checks linked to the snapshot and engine version that produced each result.

03

Firmware and advisories

Observed versions related to official security information, with context to support evaluation and remediation.

04

Evolution and differences

Condition tracking and comparisons between observations, preserving changes and previous evidence.

05

Observation schedules

Daily or weekly schedules, execution history and retry recovery for collection and analysis.

06

Governance and access

Authentication, MFA, roles and traceability, alongside backup artifact capture and retrieval.

04 / Decisions that shaped it

Decisions that shaped it

01

Analyze without changing the environment

Collection is read-only. Observation and interpretation remain separate from decisions to change infrastructure.

02

Preserve the basis of each conclusion

Snapshots and analytical versions identify which data and rules supported a result, even after the environment changes.

03

Distinguish capture from recovery

Possessing a backup artifact does not demonstrate restoration on a device. This distinction defines what the product can claim about its evidence.

05 / My contribution

Individual conception and execution

Identity applied to the project

Design is part of what I build.

My work on this project also included interface design, information organization and the application of Gantech's visual identity.

  • Security analysis conception and modeling
  • Collection, normalization, snapshots and analysis engine
  • Portal, evidence presentation and history
  • Interface design and visual identity applied to Insights
  • Application security, infrastructure and validation

Technologies and concepts

  • Next.js
  • Python
  • FastAPI
  • PostgreSQL
  • PAN-OS
  • Panorama
  • Railway

06 / Current stage

What the work made possible

An implemented portal validated in development and a lab, covering collection, analysis and tracking over time. The case does not imply customer or production deployment.

Access and availability

Private corporate project. No public demo or real device data on this site.

Discuss this work