Omuuz

ConfigVault

Back up network configurations. Audit what actually changed.

ConfigVault backs up network-device configurations and turns each snapshot into an evidence-linked change record. Support is verified for a specific vendor, network OS, model, firmware, role, management plane, and configuration scope—not inferred from a logo.

Deterministic semantic diffObject-level changes with source lines and explicit opaque coverage
Evidence-based supportClaims are scoped to model, firmware, role, transport, and config scope

Available to purchase for $9.99 USD

An editorial ConfigVault illustration connecting a secure vault to routers, switches, and wireless infrastructure.

ConfigVault Product tour

Real English-interface screenshots from the current product repository, shown with privacy-safe sample data.

ConfigVault showing a semantic audit with a high-risk ACL change
ConfigVault overview — ConfigVault is a native macOS network-device configuration backup and semantic change audit app for routers, switches, wireless controllers, and managed AP environments. Its protected local engine encrypts configurations and metadata, preserves unknown syntax explicitly, and verifies support against the exact device and collection scope instead of making broad vendor claims. (Sample data)
ConfigVault offering configuration import or read-only live device connection
ConfigVault evidence view — ConfigVault is a native macOS network-device configuration backup and semantic change audit app for routers, switches, wireless controllers, and managed AP environments. Its protected local engine encrypts configurations and metadata, preserves unknown syntax explicitly, and verifies support against the exact device and collection scope instead of making broad vendor claims. (Sample data)
ConfigVault overview with encrypted backup and audit scope explanations
Understand the audit scope — The native overview explains what ConfigVault audits, where data comes from, and how to start the first comparison. (Sample data)

Product facts

  • Deployment — Native SwiftUI macOS app with a protected local audit engine; optional self-hosted web UI and API for advanced deployments
  • Collection — Fixed read-only SSH CLI and NETCONF plans with pinned SSH host keys
  • Protection — AES-256-GCM envelopes for credentials, configurations, and protected metadata
  • Diff — Deterministic object changes for SSH CLI; conservative opaque XML structure changes for NETCONF
  • Support — Runtime evidence scoped to device fingerprint, role, management plane, transport, and configuration scope
  • License — Internet is required to activate. A Secure Enclave device key and signed offline receipt then allow normal use without a connection; launch and network recovery refresh when available
  • Compatibility — macOS 13 or later on Apple silicon, or an Intel Mac whose Secure Enclave is available
  • Commercial — $9.99 USD one-time license for up to three compatible Macs, with signed private download

How it works

  1. Add a device — Select an exact profile and configuration authority, then provide protected credentials and verified host identity.
  2. Run collection — Execute only the adapter's fixed read-only fact and configuration steps.
  3. Verify support — Record the actual model, firmware, role, transport, scope completeness, parser coverage, and limitations.
  4. Review change — Compare encrypted snapshots as deterministic semantic objects, with unknown content kept visible.

What it does—and does not do

Not server backup
Linux server files, databases, and operating-system backup are outside the product
No broad vendor promise
Every support claim is narrower than a vendor logo and must carry evidence
No configuration push
Collection, diff, verification, and notification are read-only
NETCONF is conservative
Typed semantic coverage is zero until a device-specific YANG interpretation is verified
REST is not built in
The library runner exists, but no built-in profile exposes a REST collection plan
License required
The workspace is locked before activation. Activation requires internet; afterward a device-bound signed receipt allows normal use without a connection
Mac compatibility
Activation requires Secure Enclave: use Apple silicon or a compatible Intel Mac with Secure Enclave available
Availability
$9.99 USD one-time license for up to three compatible Macs; version 0.1.6 is signed, notarized, and privately delivered

ConfigVault Product guides

How to back up router and switch configurations safelyHow to audit network configuration changes with semantic diffRunning configuration vs startup configuration: what should you back up?How to verify whether a network device is really supportedHow ConfigVault encrypts network configuration backups

Questions answered from the product specification

What does ConfigVault back up?

It backs up supported configuration scopes from routers, switches, wireless controllers, and managed AP environments. It is not a Linux server backup product.

Which vendors are included?

The current registry includes Cisco IOS/IOS XE, Juniper Junos, Arista EOS, Aruba AOS-CX, Fortinet FortiOS, and MikroTik RouterOS profiles. Each remains subject to the exact model, firmware, role, transport, scope, and evidence recorded by Device Support Check.

How is a device marked supported?

A support claim records vendor, network OS, model, firmware or build, role, deployment mode, management plane, collection method, logical scope, completeness, parser coverage, evidence level, and known limits.

Is the stored configuration encrypted?

Yes. Credentials, collector-normalized configuration bodies, device metadata, snapshot metadata, and verification reports use AES-256-GCM envelope encryption with separated purposes.

What makes the diff semantic?

Supported SSH CLI syntax is normalized into stable objects, so ConfigVault reports added, removed, modified, and reordered objects with source-line evidence instead of relying only on line positions.

What happens to syntax ConfigVault does not understand?

It is retained as an opaque object, included in accounting and change detection, and redacted in public diff values. High-risk unknown syntax lowers confidence and can block a clean semantic conclusion.

Where does the configuration data come from?

ConfigVault collects live device facts and named configuration scopes through fixed read-only SSH CLI or NETCONF plans. A manual import can also be analyzed, but it is labeled separately because it cannot prove endpoint identity, transport, freshness, or collection completeness. No built-in profile currently exposes REST collection.

What exactly does ConfigVault audit?

It compares network configuration state: supported objects such as interfaces, VLANs, access lists, routing, and services when the selected parser recognizes them, plus explicitly retained opaque changes. It does not audit traffic, Linux server files, application logs, or operator intent.

Should I back up running or startup configuration?

Back up every authority required by your policy. When a platform separates active running state from boot-time startup state, collect both and review their drift. NETCONF startup and candidate datastores exist only when the device advertises the matching capabilities.

Does scanning an SSH host key prove the device is trusted?

No. The scanned fingerprint must be compared through a separate trusted channel before it is pinned. Pinning then detects an unexpected key change; it does not establish the identity of a key that was never verified.

Does ConfigVault push configuration changes?

No. The current scope is read-only collection, encrypted backup, verification, diff, audit, and notification.

Does ConfigVault require an internet connection after activation?

No. Activation requires internet, but normal use can continue fully offline on that Mac. ConfigVault stores a device token and signed offline receipt in owner-only Application Support files, verifies the receipt with an embedded public key, and binds it to a non-exportable Secure Enclave private key. It still refreshes when launched or when the network returns so revocation and device status can be learned.

Can I buy ConfigVault now?

Yes. ConfigVault is a one-time $9.99 USD license for up to three compatible Macs. Sign in to Omuuz to download the signed and notarized installer and complete checkout.

Fact-check note

Audited against the signed and Apple-notarized ConfigVault 0.1.6 (build 11): native SwiftUI app, protected local Go audit engine, mandatory activation gate, Secure Enclave device binding, owner-only Application Support license files, signed permanent offline receipt verification, launch and network-recovery refresh, guided configuration import and automatic comparison, recovery export, built-in adapter registry, SSH CLI and NETCONF collectors, encrypted filesystem store, deterministic parser and diff tests, Device Support Check model, scheduler, optional web UI and API, signed update verification, production License fulfillment, and private installer delivery. Device support claims remain evidence-scoped; no broad vendor certification or configuration-push capability is claimed.

First-party technical sources