Being built · looking for the first providers

You already collect every client's firmware version. Nothing tells you which ones are vulnerable.

Your network monitoring records the firmware version of every firewall, switch and router you look after. It does not check those versions against published vulnerabilities. Firmwatch reads the versions you already collect and gives you one list, across all of your clients, of the devices that have a problem worth acting on this week.

Get early access

$39 a month for your whole fleet. Every client, every device, one price. The only published price we can find for this job is $249 a month, inside a plan you cannot buy with a card.

What you do about firmware vulnerabilities today

There are three real answers, and two of them are free. We think it is worth saying which is which before you give us your email address.

Nothing

The firmware versions sit in the monitoring tool, correct and up to date, and nobody compares them against anything. You hear about a bad one when a vendor email happens to catch your eye.

A script you wrote

Cisco and Fortinet both publish a vulnerability feed for free, and the public vulnerability record is free as well. Some providers wire these together themselves. It works, and it is free.

The enterprise plan

At least one large monitoring platform does this job properly. It sits in a plan at $249 a month whose button asks you to request a price quote, four times the price of the plan below it.

If you already run a script that you trust, keep it

That is a real answer and we are not going to pretend otherwise. Here is the part that makes it harder than it sounds, so you can judge for yourself whether it is worth $39.

A plain version lookup returns noise

We asked the public vulnerability record about one FortiOS version and got 116 records back. One Cisco IOS version returned 92, and the oldest of those was published in the year 2000.

The work is deciding what matters

Removing what is already fixed, what does not apply to how the device is configured, and what is too old to act on is the job. The matching part is the easy tenth of it.

And then it has to keep running

A script written once is a script that breaks quietly when a feed changes. This is a thing you want to still be true in eighteen months, across every client you have signed since.

How it works

1

Connect the tool you already run

You paste a read-only key from your network monitoring. Firmwatch reads the device inventory it has already collected. Nothing new is installed at a client site.

2

We match and then filter

Each firmware version is checked against the vendors' own advisories and the public vulnerability record. What is fixed, withdrawn or not applicable is taken out.

3

One list, and a message when it changes

You get one screen ranked across every client, and an email only when something new appears that touches a device you really run.

The price, in full

$39 a month, whole fleet
  • Every client and every device is included. We do not charge per device.
  • Unlimited users on your team — technicians do not cost extra.
  • No minimum, no contract, and no call with a salesperson.
  • Cancel yourself, in the console, without emailing anyone.

The price is on this page because you are pricing a client contract and you need the number now, not after a meeting.

What this is not

  • It is not a scanner. It never touches your clients' devices. It reads the inventory that your own monitoring tool has already collected.
  • It is not a patching tool. It tells you what is wrong and you decide what to do about it.
  • It is not a full vulnerability management platform, and it is not trying to become one.
  • It is not built yet. This page is how the first providers are being found.

Get early access

Leave your email and three answers. You will hear directly from the person building it, and telling us it is wrong for you is a useful answer.

Questions

Can I buy it today?

No, not yet. It is being built, and this page is how the first providers are being found. If you sign up you will hear from the person building it before it opens.

Cisco and Fortinet publish free vulnerability feeds. Why pay anything?

If you have already wired those feeds to your device inventory and you trust the result, keep it. It is free and it is a good answer, and this product does not try to beat a script that already works.

What we sell is the part after the match. A version lookup on its own gives you everything ever recorded against that version, including records more than twenty years old, on every device, every day. Turning that into a short list you act on is the work, and keeping it correct as feeds and clients change is the part that does not stay done.

Which monitoring tools can you read from?

We are starting with the ones that expose the firmware version of a device through a read-only interface. If yours is not covered, say which one it is on the form and it goes to the front of the list.

Does it need access to my clients' networks?

No. It reads your monitoring tool, which has already collected the inventory. There is nothing to install at a client site and no credentials for client devices.

Why is the price published when the bigger platforms do not publish theirs?

Because the plan that does this elsewhere costs $249 a month and asks you to request a quote. A provider who wants to buy a tool with a card at a price he can read is the customer this is built for.