Cisco Config Analyzer & Fleet Compliance Platform

See every misconfigured router before your auditor does.

Analyze Cisco configs, watch your whole fleet's compliance score in one dashboard, get alerted the moment a device drifts, and gate every CI/CD pipeline on it — mapped to ISO 27001, NIST SP 800-53, and live CVE data the whole way through.

Runs on your own infrastructure — nothing you analyze ever leaves your network.
IOS / IOS-XENX-OSASAIOS-XR ISO/IEC 27001NIST SP 800-53ITILLive CVE-DB
See It In Action

The dashboard, doing the actual work

Click through six real views from the app — this is exactly what you see after logging in, not a mockup of what we hope to build.

showrun-pro.local/dashboard
Analysis Overview
Fleet Dashboard
Network Discovery
Scheduled Monitoring
Custom Policies
CI/CD Gate
core-rtr01 — analyzed just now — 34 checks run
core-rtr01# show running-config | analyze --iso27001 --nist --cve
 
[CRITICAL] Telnet enabled on VTY 0 4 — CVE-2017-3881
[HIGH]     SNMP community 'public' (RO) — NIST AC-3, SC-8
[HIGH]     BGP neighbor 203.0.113.2 missing MD5 auth
[PASS]     OSPF area 0 authentication: message-digest

Compliance Report

33%
SeverityFindingISO 27001NIST 800-53
CRITICALTelnet enabled on VTY linesA.9.4.2AC-17, SC-8
HIGHSNMP default community stringA.9.4.1AC-3, SC-8
HIGHBGP neighbor missing MD5 authA.13.1.1IA-3, SC-8
PASSOSPF area 0 authentication enabledA.13.1.1IA-3, SC-8
12 devices selected from History — aggregated, nothing re-analyzed

Devices

12
in this rollup

Average Score

61%
across the fleet

Fleet Critical/High

17
9 critical · 8 high

Grade Spread

A:2 B:3 C:2 D:2 F:3

Findings Affecting the Most Devices

SeverityFindingDevices Affected
CRITICALTelnet enabled on VTY lines7 / 12
HIGHSNMP default community string5 / 12
MEDIUMNo NTP server configured4 / 12

Devices, Worst Score First

HostnameScoreCriticalHigh
edge-fw-0328% (F)43
access-sw0741% (D)23
core-rtr0288% (A)00
CDP/LLDP crawl from seed device core-rtr01, 2 hops
core-rtr01
access-sw02
access-sw03
core-rtr02
firewall-01

Discovered Devices

HostPlatform
core-rtr01Cisco IOS-XEseed
access-sw02Cisco IOS1 hop
access-sw03Cisco IOS2 hops
core-rtr02Cisco IOS-XE1 hop
firewall-01Cisco ASA1 hop
Any Cisco device found here can be pulled straight into the analyzer over SSH — credentials are used once and never written to disk.
Automated drift detection — pulls the config on schedule, diffs it, re-analyzes, alerts on change
NameHostIntervalStatusScore
Core Router Nightly10.0.0.1:221440mdrift58%
Edge Firewall Check10.0.0.5:2260mok91%
Access Layer Sweep10.0.1.12:22720mbaseline set76%
DMZ Router10.0.2.1:22360moff—
[webhook] Config drift detected: Core Router Nightly (10.0.0.1)
2 line(s) added, 0 removed. Compliance score 91% → 58%.
 
delivered to: Slack #netops-alerts · alerts@example.com
Your own golden-config rules, enforced on every analysis, Enterprise tier
PolicyRuleSeverityStatus
No HTTP server allowedmust_not_contain: ip http serverhighon
Hostname naming conventionregex_match (hostname): ^[A-Z]{3}-(RTR|SW|FW)-\d{2}$mediumon
Internal NTP requiredmust_contain: ntp server 10.0.0.100mediumon
VLAN 1 never assignedmust_not_contain: switchport access vlan 1criticaloff
A violated policy becomes a finding at exactly the severity you chose — same effect on the compliance score, same row in every export, indistinguishable from a built-in check.
tools/ci_check.py — gate a pipeline on a live compliance score, using a self-service API token
$ export SHOWRUN_TOKEN=srp_xxxxxxxxxxxxxxxxxxxxxxxxxxxx
$ python3 ci_check.py running-config.txt --min-score 70
 
SHOWRUN-PRO analysis: running-config.txt
  Score: 33% (grade F)
  Critical: 4  |  High: 7  |  Medium: 8  |  Low: 4
 
FAIL: score 33% is below the 70% threshold.
 
$ echo $?
1
Full Feature Set

Everything from a single scan to a monitored fleet

Nine capabilities, one tool — no stitching together separate scripts for parsing, compliance mapping, and monitoring.

Multi-Vendor Config Parsing

IOS, IOS-XE, NX-OS, ASA, and IOS-XR — interfaces, ACLs, routing, VPN/IPsec, QoS, and AAA normalized into one data model.

IOS/IOS-XENX-OSASAIOS-XR

Compliance Frameworks, Built In

Every finding maps to ISO/IEC 27001 Annex A, NIST SP 800-53 Rev. 5, and ITIL, plus a live-refreshable CVE database.

ISO 27001NIST 800-53CVE-DB

Network Discovery

Sweep a subnet over SNMP, crawl CDP/LLDP neighbor tables, then SSH into a discovered device and pull its config — in one flow.

SNMP scanCDP/LLDP crawlSSH pull

Fleet Dashboard

Pick devices from History and get one rollup: average score, worst performers, and which findings hit the most devices at once.

Bulk analysisWorst-first sort

Scheduled Monitoring

Periodically pull a config, diff it against the last known copy, re-analyze, and alert via webhook or email on drift or failure.

Drift detectionSlack/email alerts

Custom Policy Profiles

Layer your own golden-config rules on top of the built-in checks — naming conventions, required banners, forbidden commands.

Your own rulesEnterprise

API Tokens for CI/CD

Self-service personal access tokens gate a pipeline build on a live compliance score — a ready-to-use example script included.

Bearer tokensPipeline gating

Enterprise-Grade Access Control

Role-based access, signature-verified license keys, and credentials that are used once and never written to disk.

RBACSigned licensing

Reporting & Export

Branded PDF and editable Word (.docx) reports, plus JSON and CSV — side-by-side config diff and per-analyst history throughout.

PDF/DOCXDiff mode
How It Works

From config to fleet compliance in four steps

1

Get the config in

Paste it, upload a file, or discover the device and pull it live over SSH.

2

Run the analysis

35+ hardening checks plus ACL, routing, VPN, and QoS analysis run in seconds.

3

Watch the fleet

Schedule recurring checks, get alerted on drift, and roll many devices into one dashboard.

4

Export or gate

PDF, Word, JSON, CSV — or fail a CI/CD build automatically on score.

Built for Auditors, Not Just Engineers

Speak the language your compliance team already uses

No more translating "Telnet is enabled" into whatever control ID the auditor is asking about — it's already mapped.

35+
Hardening Checks
5
Cisco Platforms
3
Compliance Frameworks
Live
CVE Database
Plans

Pricing built around your team

Start free. Upgrade when discovery, fleet monitoring, and your own compliance rules become non-negotiable.

FREE
$0
For individual engineers kicking the tires on a single device.
  • ✓Analyze configs
  • ✓View full findings
  • —Export, diff, history
  • —Fleet dashboard & discovery
  • —Scheduled monitoring
Start Free
MOST POPULAR
PROFESSIONAL
Contact Sales / user / mo
For analysts who need to prove compliance and automate the pipeline.
  • ✓Everything in Free
  • ✓PDF/Word/JSON/CSV export, diff, history
  • ✓NIST 800-53 + CVE-DB mapping
  • ✓Network discovery, SSH pull, fleet dashboard
  • ✓API tokens for CI/CD
Start Free Trial
ENTERPRISE
Contact Sales
For teams that need RBAC, monitoring, and their own compliance rules.
  • ✓Everything in Professional
  • ✓Scheduled monitoring & alerting
  • ✓Custom policy profiles
  • ✓User & license management
  • ✓Live threat-intel feeds, priority support
Talk to Sales
Questions

Frequently asked questions

Which Cisco platforms does SHOWRUN-PRO support?

IOS, IOS-XE, NX-OS, ASA, and IOS-XR — interfaces, ACLs, routing protocols, VPN/IPsec, QoS, and AAA all normalized into one data model.

How is the Fleet Dashboard different from just analyzing devices one at a time?

It aggregates reports you've already run — average score, worst-performing devices, and which findings show up across the most devices at once — without re-analyzing anything, so the fleet numbers can never drift from the single-device reports they're built from.

What actually happens when Scheduled Monitoring detects drift?

It pulls the device's config, diffs it against the last known copy, re-runs the full analysis, and — only if something changed or the device stopped responding — sends an alert via webhook (Slack-compatible) and/or email. No change means no noise.

Can I gate a CI/CD pipeline on this?

Yes — create a self-service API token, then use the included ci_check.py example script (or call /api/analyze directly) to fail the build when a config's score falls below your threshold.

What are Custom Policy Profiles for?

Your own organization's standards that a generic tool can't know about — required banner text, naming conventions, forbidden commands. A violated policy becomes a finding at the severity you choose, with the same effect on the score as a built-in check.

Is my configuration data or discovery credentials ever sent anywhere?

No. SHOWRUN-PRO runs on your own infrastructure. Discovery credentials are used for one request and discarded; scheduled-monitoring credentials are encrypted at rest using this installation's own secret.

Ready When You Are

Stop auditing configs by hand.

Every minute spent grepping through a running-config for a Telnet line is a minute not spent fixing the network. Point SHOWRUN-PRO at your fleet and get a defensible report back before your coffee's cold.

$ pip install -r requirements.txt && python app.py  — ready in under 60 seconds