For managed service providers

Back up every customer’s fleet.
Each under its own key.Each one answerable.

Their firewalls, switches, routers and Linux servers. An agent you deploy at each site collects them, and every change becomes a version that nothing can overwrite afterwards.

Their firewalls, switches, routers and Linux servers. An agent you deploy at each site collects them, and every change becomes a record no one can alter after the fact.

Cisco IOS-XE · NX-OS · Meraki · FortiOS · PAN-OS · Panorama · BIG-IP · Junos · Linux servers

Fleet status for one customer: thirty devices, twenty-eight compliant, then the two needing attention — each with its platform, its last success and the reason it is being reported.

What the platform holds

A report that states the condition of the fleet, not a list of what ran.

A report that states whether you are covered, not a list of what ran.

The default view shows only the devices that need attention. The rest is one click away, for anyone who wants the full inventory.

The default view shows only what needs a decision. The full inventory is one click away, for the review that asks to see all of it.

Change detection Change control

A version is created only when the configuration really changed

A line in the change log means somebody changed something

Devices rewrite their timestamps, their counters and their encrypted passwords on every read. The platform sets those aside before comparing. You see only the changes an administrator made.

Devices rewrite their timestamps and counters every time they are read. The platform sets that noise aside before comparing. The change log then holds only what somebody decided.

Reports Reporting

For your customers, and for your tools

For your customers, and for their auditors

The daily report goes to the customer as a PDF. Your monitoring, your billing or an AI agent reads the same content as JSON.

The daily report reaches the customer as a PDF they can file. Your monitoring and your billing read the same statement as JSON.

Customer
report-2026-03-12.pdf
Machines
GET /api/reports/daily
Scheduling Cost control

How much storage will this schedule consume?

What this cadence will cost, before you sign for it

You type a cadence. The platform answers before you commit: the first month, the first year, then what it settles at once old versions start expiring. Nobody discovers the volume six months later.

You type a cadence. The platform answers straight away: the first month, the first year, then what it settles at once old versions start expiring. Storage stops being a figure discovered six months in.

Every night at 02:00
30 runs / month
After one year
2.7 GB accumulated
With retention
0.2 GB steady state
Device identity Authenticity

The platform checks who it is talking to before it connects

Nothing is collected from a device that cannot prove who it is

TLS certificates and SSH host keys are matched against the ones you approved. A device that presents a new fingerprint is not backed up until you decide. The cause may be a legitimate renewal, or an interception.

Certificates and host keys are matched against the ones you approved. A device whose identity changes is held back until someone decides, and the hold is logged. The cause may be a renewal, or an impersonation.

Fingerprint seen
SHA256:NRGPQi0x0+4jwOOU…
Decision
awaiting your approval
Restore Separation of duties

The platform hands you the file. Putting it back stays in your hands.

The platform hands you the file. Putting it back stays a decision.

The accounts used on your devices can stay read-only. By default the platform is not allowed to write to a firewall or a router. It cannot send a configuration back by mistake, and it cannot be made to under someone else’s control. You browse a snapshot, compare two dates and retrieve the configuration. An engineer re-applies it, knowingly. Every read is logged.

The accounts used on your devices can stay read-only. By default the platform holds no authority to write to a firewall or a router. It cannot push a configuration back by mistake, and nobody else can make it. An engineer browses a version, compares two dates, retrieves the configuration and re-applies it knowingly. Every retrieval is recorded against the customer it concerned.

One exception: Juniper Junos can be restored from the platform. It is in beta and off by default. Turning it on takes three separate switches — platform, customer, device — a permission no read-only or operator role holds, and the words LOAD OVERRIDE typed in full. The device then reverts on its own unless someone confirms it in time. Every request is recorded, with the version applied.

One exception: Juniper Junos can be restored from the platform. It is in beta and off by default. Turning it on takes three separate switches — platform, customer, device — a permission no read-only or operator role holds, and a form of words typed out in full. Nobody arrives there by clicking through. The change then reverts on its own unless someone confirms it in time. Every request is recorded, with the version applied.

Cloud-managed fleets

One API key describes a whole estate. You still say what enters.

One API key describes a whole estate. Nothing enters unapproved.

A Meraki organisation keeps its configuration in the vendor’s cloud, not on the box. Hand the platform the API key and it reads back the organisations that key opens, their sites, and every appliance, switch, access point and camera in them. Then it stops and waits for you.

A Meraki organisation keeps its configuration in the vendor’s cloud, not on the box. Hand the platform the API key and it reads back the organisations that key opens, their sites, and every appliance, switch, access point and camera in them. Then it stops and asks you.

  • Nothing is created behind your back. What you tick is imported; what you leave is left. You are billed per device, so a fleet that grows on its own is not a feature.
  • A fleet is a lasting object, not a one-off wizard. Scan it again next month and the access point installed since shows up unticked, beside what you already have.
  • Unticking a device stops backing it up. What you already have stays readable, and expires on its own schedule. Deleting for good is a separate decision.
  • A box enters once. Identity is the serial number, across the whole customer. Two fleets pointed at the same account do not make two devices out of one switch.
  • No silent growth. What you tick is imported; what you leave is left. Billing follows the device count, so a fleet that widens on its own is an unapproved cost.
  • A fleet is a standing record, not a one-off import. Scan it again next month and whatever was installed since appears unticked. That is how a gap is found.
  • Unticking a device stops backing it up. The history stays readable, and expires under the retention set for decommissioned devices. Destroying it is a separate decision.
  • A device enters once. Identity is the serial number across the whole customer. Two imports of the same account cannot inflate the count you are billed on.
A Meraki fleet after a scan: the kinds found — shared site configuration, security appliance, switch, access point — then each entry with its serial number, six already in the platform and one access point installed since, still unticked.

Fleet-wide search

One field, and the state arrives before the page does.

One field, and the answer arrives before the page does.

A device name, a partial address, a site, a service account, a customer name. Results arrive as you type, and tolerate typos. Each one carries the backup state, so “where does this one stand?” is answered without opening anything.

A device name, a partial address, a site, a service account, a customer name. Results arrive as you type, and tolerate typos. Each one already carries the backup state, so “is this one covered?” is answered without opening anything.

  • Ctrl K from any screen, arrows to browse, Enter to open.
  • Typo-tolerant: lis-croe finds lis-core-sw-01.
  • Act from the result: test a connection, or start a backup, without leaving the screen. Tab on a customer makes it your working scope.
  • Isolated: a customer account never sees another customer’s objects.
  • One keystroke from any screen, and nothing to learn to use it.
  • Typo-tolerant: a name half-remembered still finds lis-core-sw-01.
  • Act from the result: test a connection, or start a backup, without leaving the screen. One key sets the customer you are working inside.
  • Isolated: a customer account cannot see another customer’s objects.
Search opened on “lis-c”: six devices, each with its customer, address, platform, last success and state.

Scheduling

Schedules that do not move twice a year.

A backup window you can contract for.

Schedules are read in UTC, so nothing moves when the clocks change. The cost: 02:00 UTC is not 02:00 where you are. So the editor never shows an hour — it shows the next real runs, with their dates and weekdays.

Schedules are read in UTC, so the contracted window does not move when the clocks change. The cost: 02:00 UTC is not 02:00 where you are. So the editor never shows an hour, only the next real runs, with their dates and weekdays.

  • Read side by side in UTC, the platform’s zone, the customer’s and your own. A zone that repeats is shown once rather than filling a column with itself.
  • Where the clocks change, both readings are given: “03:00 in winter, 04:00 in summer”. That gap is otherwise discovered six months later.
  • The same panel answers what the cadence will cost: per run, per month, at a year, and what it settles at once old versions start expiring.
  • Read side by side in UTC, your zone, the customer’s and the reader’s own. What the customer was promised and what the platform will do are the same column.
  • Where the clocks change, both readings are given: “03:00 in winter, 04:00 in summer”. That gap is otherwise discovered six months later.
  • The same panel answers what the cadence will cost: per run, per month, at a year, and what it settles at once old versions start expiring.
Schedule editor on “0 2 * * 1”: the volume this cadence will add, then the next three occurrences read in UTC, in the platform’s zone, in the customer’s and in the reader’s — where the same instant falls on Sunday evening.

History

A question about backups is nearly always a question about a date.

Nearly every question put to you starts with a date, not a name.

“Big change between 11 and 12 March — what did we do that day?” A cell’s intensity follows the lines actually modified. What catches the eye is what moved.

“What changed on the night of the incident?” arrives after the incident. A cell’s intensity follows the lines actually modified. The day that matters catches the eye.

  • Successes, failures and changes counted per day, in the team’s time zone.
  • Click a date to pick its version, or choose among that day’s versions when there are several.
  • Largest changes ranked, per device or across the whole fleet.
  • Successes, failures and changes counted per day, in the team’s time zone.
  • Click a date to retrieve the version of that day, or choose among that day’s versions when there are several.
  • Largest changes ranked, per device or across the whole fleet.
Calendar view of backups: a monthly grid where each day carries its number of successful backups, failures and changes.

Device sheet

Everything that decides a backup, on one screen.

Everything one device commits you to, on one screen.

Transport and fallback, schedule and next run, credentials, TLS verification, authorised agents. Decommissioning and key destruction are set apart. They ask for a good deal more than a yes.

How it is reached, when, under which account, which agents are allowed to. Decommissioning and key destruction cannot be taken back. They are set apart, and ask for a good deal more than a yes.

  • One credential per access path: the API and SSH need not share an account.
  • TLS verification your way: chain verified, certificate pinned, or disabled. A disabled check shows on the sheet.
  • A connection test that takes the same path as a real backup, and fails where that backup would fail.
  • Which artifacts to collect, device by device. One PAN-OS firewall can be told to add its state archive, while the rest of the fleet keeps to the daily configuration it is compared on. That archive holds the configuration, the internal settings, the certificates and the licence binding. It is the only backup that rebuilds an appliance from nothing.
  • One credential per access path: no shared account to explain away.
  • TLS verification your way: chain verified, certificate pinned, or disabled. A disabled check is stated, not buried.
  • A connection test on the same path as a real backup: “configured” and “working” are not one claim.
  • What is collected is decided device by device. One PAN-OS firewall can be told to add its state archive, while the rest of the fleet keeps to the daily configuration it is compared on. That archive holds the configuration, the internal settings, the certificates and the licence binding. It is the only backup that rebuilds an appliance from nothing.
A device sheet: configuration, fingerprints, artifacts, snapshots and run history.

Failures

Alert discipline

Failed backups are retried automatically. You are only told when they keep failing.

Failed backups are retried automatically. Only a failure that persists is reported.

A reboot, a maintenance window, a saturated link: most failures repair themselves before anyone reads about them. A report full of problems that fixed themselves stops being read within a week. Then nobody is watching, and everyone believes someone is.

A reboot, a maintenance window, a saturated link: most failures repair themselves before anyone reads about them. A report full of problems that fixed themselves stops being read within a week. Then nobody is watching, and the supervision you attest to exists on paper only.

Retry settings on a customer: two fields left empty and inheriting the global strategy, under a sentence spelling out what the device will actually do.
Retries Retries

Replayed on its own, and counted once

Counted once, and not once per attempt

A failed backup is retried, spaced further apart each time. Only the last attempt counts as an incident. Set the retry policy once for the whole platform, override it for a customer, override it again for a single device. Each screen tells you which level a value came from.

A failed backup is retried, spaced further apart each time. Only the last attempt counts as an incident. Set the policy once for the whole platform, tighten it for a customer, tighten it again for a single device. Each screen tells you which level a value came from.

Judgement Triage

Not everything is worth retrying

A decision pending is not an outage

A fingerprint waiting for your approval is a decision, not an outage. So is a setting nobody filled in. Both are reported at once, rather than replayed to no effect. Unreachable, timed out, refused: those get their second chance.

A fingerprint waiting for approval is a decision, not an outage. So is a setting nobody filled in. Both are put in front of somebody at once, rather than replayed. Unreachable, timed out, refused: those get their second chance.

Credentials Account safety

A run of refusals stops before the account does

Backups that cannot lock out your customer

A rejected login is usually temporary, so it is retried too. After a few consecutive refusals, three by default, the device is suspended from its scheduled backups and you are told. The platform never walks your customer’s directory account into a lockout. Backing that device up by hand still works. Resuming the schedule is your call.

A rejected login is usually temporary, so it is retried too. After a few consecutive refusals, three by default, the device is suspended from its schedule and you are told. The platform never walks your customer’s directory account into a lockout. Backing that device up by hand still works. Resuming the schedule is a decision, not a timer.

Alerts Notification

Sent when the failure is real

Sent once the failure is established

Nothing goes out while a retry is still pending. Once the series is exhausted, the alert reaches the customer’s destinations and your own. It goes by email, or by webhook signed with HMAC-SHA256 so the receiving end can tell it came from you. Then one reminder per interval, for as long as the failure lasts.

Nothing goes out while a retry is still pending. Once the series is exhausted, the alert reaches the customer’s destinations and your own. It goes by email, or by webhook signed so the receiving end can prove it came from you. Then one reminder per interval, for as long as the failure lasts.

Isolation

One customer’s data does not leave its perimeter.

Isolation you can attest to, rather than take on trust.

The database itself enforces isolation, on every query. No screen has to remember to. Every customer holds their own key and their own repository.

The database itself enforces isolation, on every query. Good conduct does not come into it. Every customer holds their own key and their own repository.

Database Access control

Isolation enforced row by row

Enforced, not merely intended

Every query is bounded to the user’s customer by PostgreSQL itself. The application account it runs under holds no privileges of its own. If isolation is not active on every table, the platform refuses to serve traffic.

Every query is bounded to the user’s customer by PostgreSQL itself. The application account holds no privileges of its own. An installation whose isolation is not active refuses to serve traffic, rather than widening access.

Storage Confidentiality

One key and one repository per customer

What one customer holds says nothing about another

A customer’s backups are encrypted under a key that belongs to them alone. They are written to a space their service account cannot leave. Nothing is shared between customers, not even deduplication.

A customer’s backups are encrypted under a key that belongs to them alone, in a space their service account cannot leave. Nothing is shared between customers, not even the volume they occupy.

Immutability Integrity

Write-once, on two layers

Yesterday cannot be rewritten

Agents can only append, and the storage locks the objects. A compromised agent cannot erase what it wrote yesterday.

Agents may only add, and the storage itself locks what is written. Whoever takes an agent cannot destroy the history.

Erasure Right to erasure

Key destruction

Deletion you can attest to

“Delete my data today” meets “the lock forbids it for thirty days”. The key is destroyed, and the bytes become unreadable at once. The purge erases them once the lock allows it.

“Erase my data today” meets “the lock forbids it for thirty days”. The key is destroyed, and the bytes are unreadable from that moment on. The purge waits for the lock to expire.

Traceability Audit trail

Reads, not only writes

Who looked, not only who changed

Your teams reach the configurations of every customer. Every read is logged, with the customer concerned. That is what an auditor will ask for.

Your teams can reach every customer’s configurations. Every read is recorded, with the customer concerned. That is what makes the log matter.

Architecture Attack surface

No inbound flow towards your customers’ networks

Nothing to justify to a customer’s security team

The agent deployed at the customer listens on no port. It opens the outbound connection, receives its jobs, collects, and writes straight to storage. There is nothing to open on the customer’s firewall. Enrolment is by single-use token, with mutual certificate authentication. An agent serves one customer permanently. Its certificate renews itself well before expiry, over the channel it already authenticates on, with a fresh key each time. No token is handed out a second time. Deployment is containerised and storage is on-premise, so your backups never leave your own infrastructure.

The agent installed at the customer listens on nothing. It opens the connection outwards, takes its instructions, collects, and writes. There is no rule to add to the customer’s firewall, so the review that usually holds a rollout up never happens. It is admitted once, by a token good for a single use and a certificate each side checks. It serves one customer for its whole life. It replaces its own certificate before expiry, and nobody hands out a secret again. The platform and its storage run on your own infrastructure, so the backups do not go anywhere.

Device keys Informed consent

A BIG-IP archive, and a question most tools answer on your behalf

A question most tools answer on your behalf, and we put to you

A BIG-IP archive only restores onto the same appliance. The passwords inside it are sealed under a key held in that box: the monitor accounts, the directory bind account, the SSL passphrases. Load the archive onto a replacement and it is accepted without a word of complaint, then nothing authenticates. Collect that key as well and the archive works anywhere — but the key and the archive together open every secret in the configuration. So the platform asks you, rather than choosing.

A BIG-IP archive only restores onto the same appliance. The passwords and the directory account inside it are sealed under a key held in that box. Load the archive onto a replacement and it is accepted without complaint, then nothing authenticates: a recovery that appears to work and does not. Collect that key as well and the archive works anywhere — but the key and the archive together open every secret in the configuration. So this is put to you, rather than decided for you.

The option is off unless you tick it, and the warning stands beside the box. The key and the archive are fetched separately, and never packaged together. A copy of a backup handed to someone is not also a copy of everything it protects. Every key is kept, so an archive opens with the key of its own time and not the current one. Handing one back to an engineer takes a permission only a platform administrator holds, and is logged.

The option is off unless you turn it on, and what it costs is written beside the box. Key and archive are fetched separately, and never packaged together. A copy of a backup handed to somebody is not also a copy of everything it protects. Every key is kept, so an archive opens with the key of its own time and not the current one. Releasing one back to an engineer takes a permission only a platform administrator holds, and is recorded.

Reversibility

Exit and continuity

Nothing in the restore path belongs to us.

What happens to your backups if we disappear.

The platform runs on your own infrastructure, and so does its storage. It checks its licence offline, against a public key compiled into it. It contacts no server of ours to decide what you may do. Configurations are versioned in PostgreSQL. Binary archives go into a Kopia repository, an open and documented format.

Continuity does not depend on this company still being here. The platform and its storage both run on infrastructure you own. No server of ours decides what you may do. The formats underneath are open, documented, and not ours. Reversibility is a property of the arrangement, not a clause we promise.

Licence No kill switch

Verified offline, against an embedded key

Nobody, us included, can switch you off

The licence is a signed token, checked with a public key compiled into the platform. Nothing is called out, so a site with no outbound access is not penalised. A token that becomes unreadable grants nothing new. It still lets you read, download and restore everything already collected.

The licence is checked on your premises, with no call to us. A token that goes bad, overwritten or mistyped, grants nothing new. It still lets you read, download and restore everything already collected. A licence problem never becomes an access problem.

Formats No lock-in

PostgreSQL and Kopia, with nothing of ours in between

Your data stays in formats that outlive us

Configurations are versioned as text in PostgreSQL. Binary archives go straight into a Kopia repository, with no container of ours wrapped around them. Both stores are ones you deploy and hold. You host it. We hold nothing.

Configurations are versioned in PostgreSQL, archives in a Kopia repository. You deploy and hold both yourself. The formats are open, documented and not ours. What you keep does not become unreadable the day you leave us.

Support export Data minimisation

What we ask for when something goes wrong, and what it does not contain

What we ask for when something goes wrong, and what it does not contain

A support bundle is JSON. It carries shapes rather than names: counters, durations, ages, run states, typed failure reasons. Device names, addresses, sites, service accounts, hostnames and mail addresses are replaced by labels drawn for that one export. The mapping stays in your platform, so two bundles sent six months apart cannot be lined up against each other. Free text is scrubbed pattern by pattern, because an error message is exactly where an address hides. No configuration content, no credential, no repository key.

What we ask for in an incident is defined in advance. It is a page of measurements rather than a map of your network: counters, durations, ages, states and reasons for failure. Names, addresses, sites and accounts are replaced by labels drawn for that one export. The mapping never leaves your platform, so two bundles sent six months apart cannot be lined up against each other. Free text is scrubbed too, an error message being exactly where an address hides. No configuration content, no credential, no repository key.

Producing the bundle and sending it are two separate acts. It is built, stored and listed on screen. You download it and pass it on yourself. Nothing leaves on its own, and what you send is the bundle you looked at. When support reports a fault on a given label, you paste that label back into the platform and it names the host again. That lookup is recorded in the audit log in its own right.

Producing the bundle and sending it are two separate acts. It is built, stored and listed on screen. You send it yourself. Nothing leaves on its own, and what you review is what you send. When support reports a fault on a given label, you paste that label back into the platform and it names the host again. Pseudonymisation costs nothing in diagnosis.

Standards Frameworks

The clause, what the platform emits for it, and what we do not claim

The clause, what the platform emits for it, and what we do not claim

ISO/IEC 27001:2022 A.8.15 asks a log to cover reads, not only changes. This one does. PCI DSS expects you to produce immutable retention with a documented erasure path, and a traceable record of who reached which customer’s data. The platform emits that material. Leaving a provider is here a property of the deployment, not a document. The stack is yours, and so is everything under it.

ISO/IEC 27001:2022 A.8.15 asks a log to cover reads, not only changes. This one does. PCI DSS expects you to produce immutable retention with a documented erasure path, and a traceable record of who reached which customer’s data. The platform emits that material. Leaving a provider is here a property of the deployment, not a document. The stack is yours, and so is everything under it.

We hold no certification, and we will not imply one. InfraReplica is a young product. A page hinting at compliance already obtained is checked first by the very person it is meant to convince. The platform produces the evidence those frameworks ask for, on your own infrastructure. The certificate stays yours to obtain, and the audit yours to pass.

We hold no certification, and we will not imply one. InfraReplica is a young product. A page hinting at compliance already obtained is checked first by the very person it is meant to convince. The platform produces the evidence those frameworks ask for, on your own infrastructure. The certificate stays yours to obtain, and the audit yours to pass.

Settings that cascade

Policy that cascades

Three levels, and a screen that says where each value came from.

Three levels, and a screen that says which one a value came from.

Retention, the retry policy and the restore switch all resolve the same way. Set a value for the whole platform, override it for a customer, override it again for a single device. The most specific value that is actually set wins, field by field. An empty field is not zero. It means “as above”.

Retention, the retry policy and the restore switch all resolve the same way. Set a value for the whole platform, tighten it for a customer, tighten it again for a single device. The most specific value that is actually set wins, field by field. An empty field is not zero. It means “as above”.

  • A customer can tighten one field without inheriting a whole policy. “Why did this device only retry once?” is answered on the screen, not across three others.
  • Retention criteria add up: a version is kept if any one of them keeps it. None overrides another. Each is a floor.
  • The rule is translated into the storage engine’s own policy, never applied on top of it. Two retention engines running at once end up disagreeing.
  • A customer can be held to a stricter figure on one field without a policy of their own. “Why was this device treated that way?” is answered on the screen.
  • Retention criteria add up: a version is kept if any one of them keeps it. None overrides another. Each is a floor, the safe direction.
  • The rule is translated into the storage engine’s own policy, never applied on top of it. Two retention engines running at once end up disagreeing.
Retention screen: the effective rule field by field, with the level each value comes from — global, customer or device.

Pricing

One annual licence, everything included.

One annual licence, and one line on the budget.

Unlimited customers, agents and users. The price depends only on the number of devices backed up.

Unlimited customers, agents and users. The figure follows the device count alone. No volume billing, no per-seat surprise.

Up to 2,000 devices

€30,000/ year

The shape of a provider running the fleets of several dozen customers.

The shape of a provider answering for the fleets of several dozen customers.

  • Unlimited customers, agents and accounts
  • Every supported platform
  • PDF reports and API
  • Updates and fixes

From 2,000 to 4,000 devices

€40,000/ year

Same platform, same functional scope, a fleet twice as wide.

Same platform, same commitments, a fleet twice as wide.

  • Everything above
  • Support with storage sizing
  • Annual compliance review

Beyond that

Bespoke

Wider fleets, several storage sites, particular contractual requirements.

  • Sizing worked out together
  • Negotiated service commitments
  • Support in taking over an existing fleet

Perpetual licence on request. The storage stays with you: no transfer costs, no billing by volume.

Perpetual licence on request. The storage stays with you: nothing to migrate on exit, no volume billing.

Write to contact@infrareplica.com — a fleet inventory and the platforms in it are enough to size a quote.

Write to contact@infrareplica.com — the number of customers and devices under contract is enough to size a quote.

9platform families supported, modern API and legacy command lineplatform families covered by one licence and one contract
3levels — platform, customer, device — for retention, retries and restore, resolved field by fieldlevels of policy — platform, customer, device — one customer can be held to a stricter figure than the rest
30 dobject lock out of the box. No administrator deletes a version before term, and it can be set to yearsimmutability applied by default to every version, beyond the reach of any operator, and it can be set to years
0inbound flows towards your customers’ networksinbound rules to justify to a customer’s security team

Collectors

Cisco IOS-XEssh · restconf Cisco NX-OSssh · nx-api Cisco Merakidashboard api · network and device Fortinet FortiOSapi · ssh Palo Alto PAN-OSapi · ssh Palo Alto Panoramaapi F5 BIG-IPicontrol · ssh Juniper Junosnetconf · ssh Linux serversrsync · deduplication

Where a platform offers two ways in, both are supported. If one is unavailable the other takes over, and the report says which was used. Some offer only one: a Meraki organisation keeps its configuration in the cloud, and a Panorama exposes nothing restorable on its command line. The platform says so, rather than passing off a lesser artifact as a good one. Where a platform offers two ways in, both are supported. If one is unavailable the other takes over, and the report names the one that was used. Some offer only one: a Meraki organisation keeps its configuration in the cloud, and a Panorama exposes nothing restorable on its command line. The platform says so, rather than reporting a coverage it does not have.