INTERACTIVE DEMO · SAMPLE DATA
Someone changed the switch at 3am. This is what you would see.
This is the ConfigWatch window with a sample device list loaded — the same layout and
the same stylesheet as the installed app. The management ACL was opened up, telnet came
back, and a privilege-15 account appeared. Click any device on the left, or any
version in the middle, to see that backup’s diff. Nothing to install, and
nothing here is saved anywhere.
The diff is the product
A backup you never read is just disk usage. ConfigWatch keeps the versions so it can
show you the three lines that differ from last night — grouped by the section they
landed in, so permit ip any any reads as an access-control change and not as
line 812.
Read-only, on the device’s own terms
It logs in over SSH with an account that can run show running-config and
nothing else, reads, and disconnects. No agent, no write access, no TFTP server to stand
up. ConfigWatch never changes a device.
Secrets are redacted before they hit the disk
Passwords, community strings and pre-shared keys are masked as the config is stored, so
the backup folder is not a credential dump. That is also why the rollback above refuses to
restore the account — the original secret is genuinely gone.
Free covers three devices
All of your devices are backed up on the free tier; three of them show their history.
Pro unlocks the rest, plus scheduled backups, the generated rollback commands, and the CSV and PDF audit reports.