See every misconfigured router before your auditor does.
Analyze Cisco configs, watch your whole fleet's compliance score in one dashboard, get alerted the moment a device drifts, and gate every CI/CD pipeline on it — mapped to ISO 27001, NIST SP 800-53, and live CVE data the whole way through.
The dashboard, doing the actual work
Click through six real views from the app — this is exactly what you see after logging in, not a mockup of what we hope to build.
Compliance Report
| Severity | Finding | ISO 27001 | NIST 800-53 |
|---|---|---|---|
| CRITICAL | Telnet enabled on VTY lines | A.9.4.2 | AC-17, SC-8 |
| HIGH | SNMP default community string | A.9.4.1 | AC-3, SC-8 |
| HIGH | BGP neighbor missing MD5 auth | A.13.1.1 | IA-3, SC-8 |
| PASS | OSPF area 0 authentication enabled | A.13.1.1 | IA-3, SC-8 |
Devices
Average Score
Fleet Critical/High
Grade Spread
Findings Affecting the Most Devices
| Severity | Finding | Devices Affected |
|---|---|---|
| CRITICAL | Telnet enabled on VTY lines | 7 / 12 |
| HIGH | SNMP default community string | 5 / 12 |
| MEDIUM | No NTP server configured | 4 / 12 |
Devices, Worst Score First
| Hostname | Score | Critical | High |
|---|---|---|---|
| edge-fw-03 | 28% (F) | 4 | 3 |
| access-sw07 | 41% (D) | 2 | 3 |
| core-rtr02 | 88% (A) | 0 | 0 |
Discovered Devices
| Host | Platform | |
|---|---|---|
| core-rtr01 | Cisco IOS-XE | seed |
| access-sw02 | Cisco IOS | 1 hop |
| access-sw03 | Cisco IOS | 2 hops |
| core-rtr02 | Cisco IOS-XE | 1 hop |
| firewall-01 | Cisco ASA | 1 hop |
| Name | Host | Interval | Status | Score |
|---|---|---|---|---|
| Core Router Nightly | 10.0.0.1:22 | 1440m | drift | 58% |
| Edge Firewall Check | 10.0.0.5:22 | 60m | ok | 91% |
| Access Layer Sweep | 10.0.1.12:22 | 720m | baseline set | 76% |
| DMZ Router | 10.0.2.1:22 | 360m | off | — |
| Policy | Rule | Severity | Status |
|---|---|---|---|
| No HTTP server allowed | must_not_contain: ip http server | high | on |
| Hostname naming convention | regex_match (hostname): ^[A-Z]{3}-(RTR|SW|FW)-\d{2}$ | medium | on |
| Internal NTP required | must_contain: ntp server 10.0.0.100 | medium | on |
| VLAN 1 never assigned | must_not_contain: switchport access vlan 1 | critical | off |
Everything from a single scan to a monitored fleet
Nine capabilities, one tool — no stitching together separate scripts for parsing, compliance mapping, and monitoring.
Multi-Vendor Config Parsing
IOS, IOS-XE, NX-OS, ASA, and IOS-XR — interfaces, ACLs, routing, VPN/IPsec, QoS, and AAA normalized into one data model.
Compliance Frameworks, Built In
Every finding maps to ISO/IEC 27001 Annex A, NIST SP 800-53 Rev. 5, and ITIL, plus a live-refreshable CVE database.
Network Discovery
Sweep a subnet over SNMP, crawl CDP/LLDP neighbor tables, then SSH into a discovered device and pull its config — in one flow.
Fleet Dashboard
Pick devices from History and get one rollup: average score, worst performers, and which findings hit the most devices at once.
Scheduled Monitoring
Periodically pull a config, diff it against the last known copy, re-analyze, and alert via webhook or email on drift or failure.
Custom Policy Profiles
Layer your own golden-config rules on top of the built-in checks — naming conventions, required banners, forbidden commands.
API Tokens for CI/CD
Self-service personal access tokens gate a pipeline build on a live compliance score — a ready-to-use example script included.
Enterprise-Grade Access Control
Role-based access, signature-verified license keys, and credentials that are used once and never written to disk.
Reporting & Export
Branded PDF and editable Word (.docx) reports, plus JSON and CSV — side-by-side config diff and per-analyst history throughout.
From config to fleet compliance in four steps
Get the config in
Paste it, upload a file, or discover the device and pull it live over SSH.
Run the analysis
35+ hardening checks plus ACL, routing, VPN, and QoS analysis run in seconds.
Watch the fleet
Schedule recurring checks, get alerted on drift, and roll many devices into one dashboard.
Export or gate
PDF, Word, JSON, CSV — or fail a CI/CD build automatically on score.
Speak the language your compliance team already uses
No more translating "Telnet is enabled" into whatever control ID the auditor is asking about — it's already mapped.
Pricing built around your team
Start free. Upgrade when discovery, fleet monitoring, and your own compliance rules become non-negotiable.
- ✓Analyze configs
- ✓View full findings
- —Export, diff, history
- —Fleet dashboard & discovery
- —Scheduled monitoring
- ✓Everything in Free
- ✓PDF/Word/JSON/CSV export, diff, history
- ✓NIST 800-53 + CVE-DB mapping
- ✓Network discovery, SSH pull, fleet dashboard
- ✓API tokens for CI/CD
- ✓Everything in Professional
- ✓Scheduled monitoring & alerting
- ✓Custom policy profiles
- ✓User & license management
- ✓Live threat-intel feeds, priority support
Frequently asked questions
Which Cisco platforms does SHOWRUN-PRO support?
IOS, IOS-XE, NX-OS, ASA, and IOS-XR — interfaces, ACLs, routing protocols, VPN/IPsec, QoS, and AAA all normalized into one data model.
How is the Fleet Dashboard different from just analyzing devices one at a time?
It aggregates reports you've already run — average score, worst-performing devices, and which findings show up across the most devices at once — without re-analyzing anything, so the fleet numbers can never drift from the single-device reports they're built from.
What actually happens when Scheduled Monitoring detects drift?
It pulls the device's config, diffs it against the last known copy, re-runs the full analysis, and — only if something changed or the device stopped responding — sends an alert via webhook (Slack-compatible) and/or email. No change means no noise.
Can I gate a CI/CD pipeline on this?
Yes — create a self-service API token, then use the included ci_check.py example script (or call /api/analyze directly) to fail the build when a config's score falls below your threshold.
What are Custom Policy Profiles for?
Your own organization's standards that a generic tool can't know about — required banner text, naming conventions, forbidden commands. A violated policy becomes a finding at the severity you choose, with the same effect on the score as a built-in check.
Is my configuration data or discovery credentials ever sent anywhere?
No. SHOWRUN-PRO runs on your own infrastructure. Discovery credentials are used for one request and discarded; scheduled-monitoring credentials are encrypted at rest using this installation's own secret.
Stop auditing configs by hand.
Every minute spent grepping through a running-config for a Telnet line is a minute not spent fixing the network. Point SHOWRUN-PRO at your fleet and get a defensible report back before your coffee's cold.