How PaSBaT Works

In short: prepare snapshot → anonymize locally → analyze → receive report.

Overview

  • PaSBaT is a privacy-first workflow for non-invasive network snapshot assessments.
  • The focus is not live access, but prepared configuration snapshots.
  • The analysis produces topology, security findings, evidence and compliance-oriented reports.

Target Workflow

1) Prepare snapshot

The customer or a service provider exports the required network configurations according to a clear request list.

2) Anonymize locally

Sensitive values are replaced or removed locally before analysis. The mapping remains with the customer.

3) Start analysis

The anonymized bundle is analyzed remotely, passed through a partner/broker or processed offline on-site.

4) Receive report

PaSBaT provides a structured HTML/PDF report with findings, evidence, priorities and recommendations.

Operating Modes

On-Prem Offline

For highly sensitive environments, analysis runs fully offline at the customer site. No data leaves the environment.

Assisted Remote

The customer anonymizes locally and provides only the anonymized bundle.

Brokered Blind

As a target model, a neutral broker can handle identity, payment and transfer while PaSBaT only sees tokens and anonymized data.

What the Public Demo Shows

The demo uses synthetic test data to make the effect visible: original and anonymized topology can be compared, reports can be opened and analysis artifacts are shown in a traceable way. The demo is intentionally broader than a typical first engagement and serves as technical proof, not as disclosure of the internal method.

Data and Trust Principles

  • No active scans and no direct access to production systems.
  • Original data and mappings are intended to remain with the customer.
  • Public demos contain synthetic test data only.
  • Internal mapping artifacts are not provided as part of the public demo.
  • Legal, tax and data protection roles must be reviewed carefully for platform and broker models.

Input Quality

Report quality strongly depends on the quality of the provided configuration snapshots. Therefore, tutorials, checklists and request forms are part of the target process.

  • Which vendors and device types are included?
  • Which export commands or file formats are required?
  • Which files are mandatory and which are optional?
  • Which metadata and filenames should be cleaned before handover?
  • Which limitations apply to the selected scope?

What the Report Proves

  • Technical view of topology and structure
  • Security findings with evidence and recommendations
  • Indicators of operational and compliance risks
  • Documented limitations of the analysis
  • Basis for remediation, audit preparation and technical reviews

Frequently Asked Questions

Is PaSBaT an active scanner?

No. The target workflow is based on prepared configuration snapshots.

Does PaSBaT need to know the customer?

For direct projects, yes. For a future brokered model, PaSBaT is intended to see only tokens and anonymized data.

Is the demo the same as production?

No. The demo is a synthetic proof-of-concept. Production focuses on prepared customer snapshots and clearly defined scope.

Which vendors are supported?

The PoC focuses on Cisco. Additional vendors are expanded modularly and must be validated.

Next Steps