Rulecanopy
Review firewall rules offline by age, hit evidence, breadth, owner, expiry, change intent, and rollback readiness.
Focused field tools
Review first-match, last-match, implicit, and platform-specific evaluation behavior.
Narrow source, destination, direction, zone, protocol, and service.
Resolve nested groups and stale aliases before approving intent.
Use representative hit and flow evidence without treating silence as proof.
Require accountable recertification and expiry for temporary access.
Find rules that can never match or are subsumed by broader rules.
Rulecanopy reviews recorded rules and evidence; it does not connect to, configure, or prove behavior on any firewall. Confirm evaluation order, zones, objects, NAT, routes, identity policy, platform defaults, live traffic, and change control in the authoritative system.