MenuPhoneSearch

NOW AVAILABLE in Mutiny Version 8.1

Automated Configuration Backup, Change Tracking & Recovery

Always know what changed — and be ready to roll back

Mutiny ConfigVault™ provides full visibility and control over your device configurations, automatically retrieving and securely storing them as part of your Mutiny platform.

Whether you are troubleshooting an issue, auditing changes, or recovering from a failure, ConfigVault ensures you always have access to the configuration history you need.


What is ConfigVault™?

Mutiny ConfigVault™ connects to supported network devices and retrieves their configuration data on a scheduled or on-demand basis.

Each configuration is securely stored and versioned, allowing you to track changes over time and download any revision instantly. This creates a reliable, centralised configuration archive across your entire estate.


Key Features

Automated Configuration Collection
Regularly retrieve configurations from network devices without manual effort.

Version History and Change Visibility
Maintain a complete historical record of configuration changes over time.

Secure Central Storage
All configuration data is stored securely within your Mutiny system, with no external dependencies.

On-Demand Access and Download
Access and download current or previous configurations at any time.

Rapid Rollback Support
Recover quickly from misconfigurations by restoring known-good versions.

Lightweight and Scalable
Designed to operate efficiently across large estates without additional infrastructure.


Why ConfigVault™ Matters

Configuration drift and undocumented changes are a common cause of outages and instability.

With Mutiny ConfigVault™, you can:

  • Identify exactly what changed and when
  • Reduce mean time to resolution during incidents
  • Maintain a clear audit trail for compliance
  • Protect against accidental or unauthorised changes
  • Improve operational resilience across your infrastructure

Built into the Mutiny Platform

ConfigVault™ is fully integrated into the Mutiny ecosystem:

  • Uses stored device credentials and discovery data
  • Requires no additional servers, databases, or integrations
  • Works alongside monitoring, alerting, topology mapping, and Active IPAM™
  • Managed through the same web-based interface

Typical Use Cases

  • Backup of router, switch, and firewall configurations
  • Audit and compliance reporting
  • Troubleshooting configuration-related issues
  • Detecting and managing configuration drift
  • Disaster recovery and rollback planning

A Complete Operational Picture

Monitoring shows you what is happening.
ConfigVault™ helps you understand why.

By combining configuration intelligence with Mutiny’s monitoring, alerting, and topology mapping, you gain a more complete and actionable view of your environment.


ConfigVault™ Security Architecture

Designed for Real-World Security

ConfigVault™ has been engineered to protect sensitive device credentials and configuration data without compromising the operational simplicity that Mutiny is known for.

Rather than enforcing a one-size-fits-all security model, ConfigVault™ introduces a tiered security architecture, allowing organisations to balance protection and usability according to their own risk profile.

At the heart of this approach is the StorageVault, a secure container used to encrypt and manage credentials and other sensitive data within the Mutiny platform.


The StorageVault

The StorageVault is responsible for:

  • Securely storing credentials (e.g. SNMPv3, API, WinRM)
  • Encrypting configuration backups retrieved from network devices
  • Isolating sensitive data from standard system processes
  • Providing controlled access based on system state and policy

All sensitive data within ConfigVault™ is encrypted at rest and is never exposed in plaintext outside of controlled runtime use.


Three-Tier Security Model

ConfigVault™ provides three configurable security modes, allowing organisations to select the level of protection appropriate to their environment.


🔓 Appliance Mode (Default)

Designed for simplicity and continuous operation

  • StorageVault unlocks automatically on system boot
  • Encryption key is securely stored on the appliance
  • No manual intervention required during normal operation

This mode is ideal for:

  • Standard enterprise IT environments
  • Remote or unattended deployments
  • Organisations prioritising operational continuity

Key Benefit:
Zero operational overhead while maintaining encryption at rest.


🔐 Secure Mode

Balanced protection for most organisations

  • StorageVault remains unlocked during normal operation
  • Unlock required only after a system restore
  • Encryption key is not included in backups

This mode is ideal for:

  • Organisations with backup security concerns
  • Managed service environments
  • Security-conscious enterprises

Key Benefit:
Protects against backup compromise without impacting day-to-day usability.


🔒 High Security Mode

Maximum protection for sensitive environments

  • StorageVault must be unlocked after every system reboot
  • Encryption key is stored only in volatile memory
  • No persistent storage of the unlock code

This mode is suitable for:

  • Government and defence environments
  • Highly regulated industries
  • Air-gapped or high-assurance systems

Key Benefit:
Eliminates persistent key storage, ensuring credentials are never recoverable from disk.


Operational Resilience

ConfigVault™ is designed to maintain system visibility even under restricted conditions.

If the StorageVault is locked:

  • Mutiny continues monitoring where credentials are not required
  • Affected checks are clearly identified within the interface
  • Administrators are notified through visible warnings and alerts

This ensures that security controls do not result in silent monitoring failures.


Secure by Design

ConfigVault™ follows a number of key security principles:

  • Encryption at rest for all sensitive data
  • Separation of secrets from core system processes
  • No key exposure in backups (Secure Mode and above)
  • Configurable security posture aligned to organisational risk
  • Minimal attack surface through appliance-based deployment

Built for the Mutiny Platform

Unlike bolt-on credential stores, ConfigVault™ is fully integrated into the Mutiny architecture, ensuring:

  • Consistent handling of credentials across all monitoring methods
  • Seamless use with agentless protocols (SNMP, APIs, WinRM)
  • Centralised management without external dependencies

Summary

ConfigVault™ delivers enterprise-grade credential protection without sacrificing the simplicity and reliability expected from a monitoring appliance.

By combining strong encryption with a flexible, tiered security model, it allows organisations to:

  • Maintain operational continuity
  • Protect sensitive configuration data
  • Adapt security controls to their specific environment