Compare rConfig editions
See what each edition includes and choose the right level for your network.
Features by category
Comparing Standard with Enterprise / MSP
| CoreNo device limitInstall V8 | Starterup to 300 devicesRequest a Demo | Standard, selectedup to 1,000 devicesRequest a Demo | Enterprise / MSPbeyond 1,000 devicesRequest a Demo |
Keep a current copy of every configuration and restore it when something goes wrong.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Configuration backupsBackup copy of the configuration or state output for every device you manage. | Included | Included | Included | Included |
| Scheduled backupsRun backups automatically on the schedule you set. | Included | Included | Included | Included |
| Devices and vendors supportedWorks with any network vendorUse a ready-made profile, import your own, or ask us to make one for free. | All vendors supported | All vendors supported | All vendors supported | All vendors supported |
| Restore a previous configurationRestore all or part of a past configuration. | Not included | Included | Included | Included |
| Trigger backups from the APIAPI-triggered backupsUse the rConfig API to back up a device from your own tooling. | Not included | Included | Included | Included |
| Back up over FTP, SFTP and TFTPxFTP backupsBack up any file type over FTP, SFTP or TFTP, in addition to SSH. | Not included | Included | Included | Included |
| Back up via REST APIREST API backupsBack up any device that exposes a REST API. | Not included | Not included | Included | Included |
| Encrypted backupsAES-256 encryptionAll backups are encrypted with AES-256. | Included | Included | Included | Included |
- Configuration backupsBackup copy of the configuration or state output for every device you manage.Standard: IncludedEnterprise / MSP: Included
- Scheduled backupsRun backups automatically on the schedule you set.Standard: IncludedEnterprise / MSP: Included
- Devices and vendors supportedWorks with any network vendorUse a ready-made profile, import your own, or ask us to make one for free.Standard: All vendors supportedEnterprise / MSP: All vendors supported
- Restore a previous configurationRestore all or part of a past configuration.Standard: IncludedEnterprise / MSP: Included
- Trigger backups from the APIAPI-triggered backupsUse the rConfig API to back up a device from your own tooling.Standard: IncludedEnterprise / MSP: Included
- Back up over FTP, SFTP and TFTPxFTP backupsBack up any file type over FTP, SFTP or TFTP, in addition to SSH.Standard: IncludedEnterprise / MSP: Included
- Back up via REST APIREST API backupsBack up any device that exposes a REST API.Standard: IncludedEnterprise / MSP: Included
- Encrypted backupsAES-256 encryptionAll backups are encrypted with AES-256.Standard: IncludedEnterprise / MSP: Included
See what changed, when it changed and how two versions differ.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Search across all configurations | Included | Included | Included | Included |
| Compare configuration versionsConfiguration diff | Included | Included | Included | Included |
| See what changed and whenChange detection and history | Included | Included | Included | Included |
| One view of every changeChange PulseReal-time visibility of configuration activity across every device, in one place. | Not included | Included | Included | Included |
| Get told the moment something changesChange alertsA detected change raises an alert. Core sends it by email, every other edition adds your own channels. | Email only | Included | Included | Included |
| AI drift detection and narrationNewAI change narrationDrift is flagged and explained in plain language, not only as a diff. | Not included | Not included | Included | Included |
- Search across all configurationsStandard: IncludedEnterprise / MSP: Included
- Compare configuration versionsConfiguration diffStandard: IncludedEnterprise / MSP: Included
- See what changed and whenChange detection and historyStandard: IncludedEnterprise / MSP: Included
- One view of every changeChange PulseReal-time visibility of configuration activity across every device, in one place.Standard: IncludedEnterprise / MSP: Included
- Get told the moment something changesChange alertsA detected change raises an alert. Core sends it by email, every other edition adds your own channels.Standard: IncludedEnterprise / MSP: Included
- AI drift detection and narrationNewAI change narrationDrift is flagged and explained in plain language, not only as a diff.Standard: IncludedEnterprise / MSP: Included
Check configurations against your policies and show the result.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Policy checks and compliance statusCompliance rules and policiesRun policies against your configurations and review the result by device. | Not included | Included | Included | Included |
| Check compliance continuouslyScheduled compliance checksRun your policies on a schedule, the same way you run backups. | Not included | Not included | Included | Included |
| Evidence you can hand to an auditorCompliance reports and exportsScheduled report emails, plus results exported to CSV or Excel. | Not included | Not included | Included | Included |
| Skip writing rules from scratchNewAI-assisted policy creationGenerate CIS and NIST aligned rules from a real device configuration, including the hardening gaps it is missing. | Not included | Not included | Not included | Included |
- Policy checks and compliance statusCompliance rules and policiesRun policies against your configurations and review the result by device.Standard: IncludedEnterprise / MSP: Included
- Check compliance continuouslyScheduled compliance checksRun your policies on a schedule, the same way you run backups.Standard: IncludedEnterprise / MSP: Included
- Evidence you can hand to an auditorCompliance reports and exportsScheduled report emails, plus results exported to CSV or Excel.Standard: IncludedEnterprise / MSP: Included
- Skip writing rules from scratchNewAI-assisted policy creationGenerate CIS and NIST aligned rules from a real device configuration, including the hardening gaps it is missing.Standard: Not includedEnterprise / MSP: Included
Push changes, schedule work, run scripts and use AI to understand configurations.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Connect your own AI assistantNewFull MCP supportQuery your devices, configurations, diffs and compliance status from Claude or any MCP client. | Not included | Not included | Not included | Included |
| Ask AI about your configurationsNewBuilt-in AIBring your own provider, or run a local model so nothing leaves your network. Every request is logged. | Not included | Not included | Included | Included |
| Keep AI on your own infrastructureNewLocal and private AI modelsRun against a local model, or any OpenAI-compatible endpoint. No configuration data leaves your network. | Not included | Not included | Included | Included |
| Push configuration changesConfiguration pushSingle, bulk and scheduled device configuration changes. | Not included | Included | Included | Included |
| Push firmware to devicesFirmware pushPush firmware images to devices, on the same task engine as configuration changes. | Not included | Not included | Included | Included |
| Run your own scriptsRun scripts in any languageScript-based backups and automations run through this engine. | Not included | Not included | Included | Included |
| Automate anything from your own toolingRESTful APIThe whole product is addressable over the API. The rConfig interface is built on the same endpoints. | Included | Included | Included | Included |
- Connect your own AI assistantNewFull MCP supportQuery your devices, configurations, diffs and compliance status from Claude or any MCP client.Standard: Not includedEnterprise / MSP: Included
- Ask AI about your configurationsNewBuilt-in AIBring your own provider, or run a local model so nothing leaves your network. Every request is logged.Standard: IncludedEnterprise / MSP: Included
- Keep AI on your own infrastructureNewLocal and private AI modelsRun against a local model, or any OpenAI-compatible endpoint. No configuration data leaves your network.Standard: IncludedEnterprise / MSP: Included
- Push configuration changesConfiguration pushSingle, bulk and scheduled device configuration changes.Standard: IncludedEnterprise / MSP: Included
- Push firmware to devicesFirmware pushPush firmware images to devices, on the same task engine as configuration changes.Standard: IncludedEnterprise / MSP: Included
- Run your own scriptsRun scripts in any languageScript-based backups and automations run through this engine.Standard: IncludedEnterprise / MSP: Included
- Automate anything from your own toolingRESTful APIThe whole product is addressable over the API. The rConfig interface is built on the same endpoints.Standard: IncludedEnterprise / MSP: Included
Connect rConfig to the systems and credential stores you already use.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Migrate from your current toolImport from Oxidized, RANCID, NetMRI and SolarWindsBring your existing device inventory across without rebuilding it. | Included | Included | Included | Included |
| Alerts in the tools you already useSlack and Microsoft TeamsSend backup, change and compliance alerts to your channels. | Not included | Included | Included | Included |
| Sync inventory with your systemsDevice syncLoad devices from NetBox, Nautobot, Zabbix or ServiceNow and keep them in step, instead of adding them by hand. | Not included | Not included | Included | Included |
| Store credentials in your vaultKey-vault integrationDevice credentials stay in your vault. rConfig holds none of them. | Not included | Not included | Included | Included |
- Migrate from your current toolImport from Oxidized, RANCID, NetMRI and SolarWindsBring your existing device inventory across without rebuilding it.Standard: IncludedEnterprise / MSP: Included
- Alerts in the tools you already useSlack and Microsoft TeamsSend backup, change and compliance alerts to your channels.Standard: IncludedEnterprise / MSP: Included
- Sync inventory with your systemsDevice syncLoad devices from NetBox, Nautobot, Zabbix or ServiceNow and keep them in step, instead of adding them by hand.Standard: IncludedEnterprise / MSP: Included
- Store credentials in your vaultKey-vault integrationDevice credentials stay in your vault. rConfig holds none of them.Standard: IncludedEnterprise / MSP: Included
Control who can see and change your network, and keep a record of what they do.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Local user accounts | Included | Included | Included | Included |
| Single sign-onSSO with SAML and OIDCMicrosoft Entra, Okta, Google, SAML 2.0 and Shibboleth. | Included | Included | Included | Included |
| LDAP and Active DirectoryDirectory sign-in | Not included | Included | Included | Included |
| RADIUS authenticationRADIUS | Not included | Included | Included | Included |
| Role-based access controlRBACGive each role only the permissions it needs. | Not included | Included | Included | Included |
| Limit who sees which devicesDevice and tag level accessScope a role to specific devices or tags so engineers only see the estate they manage. | Not included | Not included | Included | Included |
| Start from a ready-made roleRole templatesRead-Only, Read-Only plus Device Edit and Standard User, ready to assign. | Not included | Included | Included | Included |
| Control machine accessAPI access tokensIssue and revoke tokens for external tooling, stored encrypted. | Included | Included | Included | Included |
| User audit logAudit logging | Not included | Included | Included | Included |
- Local user accountsStandard: IncludedEnterprise / MSP: Included
- Single sign-onSSO with SAML and OIDCMicrosoft Entra, Okta, Google, SAML 2.0 and Shibboleth.Standard: IncludedEnterprise / MSP: Included
- LDAP and Active DirectoryDirectory sign-inStandard: IncludedEnterprise / MSP: Included
- RADIUS authenticationRADIUSStandard: IncludedEnterprise / MSP: Included
- Role-based access controlRBACGive each role only the permissions it needs.Standard: IncludedEnterprise / MSP: Included
- Limit who sees which devicesDevice and tag level accessScope a role to specific devices or tags so engineers only see the estate they manage.Standard: IncludedEnterprise / MSP: Included
- Start from a ready-made roleRole templatesRead-Only, Read-Only plus Device Edit and Standard User, ready to assign.Standard: IncludedEnterprise / MSP: Included
- Control machine accessAPI access tokensIssue and revoke tokens for external tooling, stored encrypted.Standard: IncludedEnterprise / MSP: Included
- User audit logAudit loggingStandard: IncludedEnterprise / MSP: Included
Run rConfig at the size and shape your network needs.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Device allowanceLicensed device count | No licence limit | Up to 300 | Up to 1,000 | Custom, beyond 1,000 |
| Manage every rConfig instance centrallyVector Central ManagerVector Central Manager is included with Enterprise. Vector MSP is the service-provider offer. | Not included | Not included | Not included | Included |
| Container deploymentContainers | Included | Included | Included | Included |
| Air-gapped deployment | Included | Included | Included | Included |
| Distributed collectorsMulti-tier architecture | Not included | Not included | Not included | Included |
| High availabilityHA | Not included | Not included | Not included | Included |
- Device allowanceLicensed device countStandard: Up to 1,000Enterprise / MSP: Custom, beyond 1,000
- Manage every rConfig instance centrallyVector Central ManagerVector Central Manager is included with Enterprise. Vector MSP is the service-provider offer.Standard: Not includedEnterprise / MSP: Included
- Container deploymentContainersStandard: IncludedEnterprise / MSP: Included
- Air-gapped deploymentStandard: IncludedEnterprise / MSP: Included
- Distributed collectorsMulti-tier architectureStandard: Not includedEnterprise / MSP: Included
- High availabilityHAStandard: Not includedEnterprise / MSP: Included
See who helps you, how quickly they respond and what extra help is available.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Included supportSupport response | Community | 5 business days | 8x5, next business day | 24x7, four-hour response |
| Named customer success manager | Not included | Not included | Not included | Included |
| Implementation servicesProfessional services | Not included | Not included | Available as a paid service | Available as a paid service |
| Training | Not included | Not included | Available as a paid service | Available as a paid service |
| Custom developmentCustomisation | Not included | Not included | Available as a paid service | Available as a paid service |
- Included supportSupport responseStandard: 8x5, next business dayEnterprise / MSP: 24x7, four-hour response
- Named customer success managerStandard: Not includedEnterprise / MSP: Included
- Implementation servicesProfessional servicesStandard: Available as a paid serviceEnterprise / MSP: Available as a paid service
- TrainingStandard: Available as a paid serviceEnterprise / MSP: Available as a paid service
- Custom developmentCustomisationStandard: Available as a paid serviceEnterprise / MSP: Available as a paid service
More features, in depth
The engineering detail behind the summary above, in the same four editions.
| CoreNo device limitInstall V8 | Starterup to 300 devicesRequest a Demo | Standard, selectedup to 1,000 devicesRequest a Demo | Enterprise / MSPbeyond 1,000 devicesRequest a Demo |
How backups are triggered, collected, reported on and kept over time.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Back up the moment a change happensEvent-triggered backups (SNMP trap)A trap from the device starts a backup straight away, with a cooldown per filter so a burst cannot flood the queue. | Not included | Not included | Included | Included |
| Collect remote sites without a VPN back to coreDistributed collector agentsBind tasks and devices to a remote agent, so branch and customer networks are collected locally. | Not included | Not included | Not included | Included |
| Know whether last night's backup ranBackup success and failure reportingEvery task records what succeeded and what failed, device by device. | Included | Included | Included | Included |
| Scheduled reports and failure alertsVerbose reporting and email notificationDownloadable reports and per-task email when a backup fails. | Not included | Included | Included | Included |
| Backups keep working when a protocol is disabledAutomatic protocol fallbackSSH falls back to Telnet with port probing, and the preferred protocol is re-checked periodically. | Included | Included | Included | Included |
| Retention limits that stop the archive filling the diskRetention policy and automatic purgeSet how many days of history each target keeps, then scheduled cleanup does the rest. | Included | Included | Included | Included |
| TL1 device backupsTL1 over Telnet or SSHCollect from TL1 managed equipment over either transport. | Not included | Included | Included | Included |
| Secrets masked in stored configurationsSecrets masking and config obfuscationPasswords and community strings are obscured in the stored configuration, so the archive is safe to share. | Included | Included | Included | Included |
| Device credentials held in your own vaultHashiCorp Vault integrationDevice passwords stay in the vault and are never stored in rConfig. | Not included | Not included | Included | Included |
| Search the content of every stored backupConfiguration content searchFind every device that ever carried a given line, such as an ACL entry, across the whole archive. | Included | Included | Included | Included |
- Back up the moment a change happensEvent-triggered backups (SNMP trap)A trap from the device starts a backup straight away, with a cooldown per filter so a burst cannot flood the queue.Standard: IncludedEnterprise / MSP: Included
- Collect remote sites without a VPN back to coreDistributed collector agentsBind tasks and devices to a remote agent, so branch and customer networks are collected locally.Standard: Not includedEnterprise / MSP: Included
- Know whether last night's backup ranBackup success and failure reportingEvery task records what succeeded and what failed, device by device.Standard: IncludedEnterprise / MSP: Included
- Scheduled reports and failure alertsVerbose reporting and email notificationDownloadable reports and per-task email when a backup fails.Standard: IncludedEnterprise / MSP: Included
- Backups keep working when a protocol is disabledAutomatic protocol fallbackSSH falls back to Telnet with port probing, and the preferred protocol is re-checked periodically.Standard: IncludedEnterprise / MSP: Included
- Retention limits that stop the archive filling the diskRetention policy and automatic purgeSet how many days of history each target keeps, then scheduled cleanup does the rest.Standard: IncludedEnterprise / MSP: Included
- TL1 device backupsTL1 over Telnet or SSHCollect from TL1 managed equipment over either transport.Standard: IncludedEnterprise / MSP: Included
- Secrets masked in stored configurationsSecrets masking and config obfuscationPasswords and community strings are obscured in the stored configuration, so the archive is safe to share.Standard: IncludedEnterprise / MSP: Included
- Device credentials held in your own vaultHashiCorp Vault integrationDevice passwords stay in the vault and are never stored in rConfig.Standard: IncludedEnterprise / MSP: Included
- Search the content of every stored backupConfiguration content searchFind every device that ever carried a given line, such as an ACL entry, across the whole archive.Standard: IncludedEnterprise / MSP: Included
How a detected change is filtered, ranked and signed off before anyone acts on it.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Diff noise exclusionsDiff exclusion rulesIgnore the lines that change on every backup, so a real change stands out. | Not included | Not included | Included | Included |
| Severity and tagging for triageChange severity and tagsRank and tag changes so the important ones are dealt with first. | Not included | Not included | Coming soon | Coming soon |
| Change review and sign-off workflowReview and approvalRoute a detected change for review and record who signed it off. | Not included | Not included | Coming soon | Coming soon |
- Diff noise exclusionsDiff exclusion rulesIgnore the lines that change on every backup, so a real change stands out.Standard: IncludedEnterprise / MSP: Included
- Severity and tagging for triageChange severity and tagsRank and tag changes so the important ones are dealt with first.Standard: Coming soonEnterprise / MSP: Coming soon
- Change review and sign-off workflowReview and approvalRoute a detected change for review and record who signed it off.Standard: Coming soonEnterprise / MSP: Coming soon
How policies are written, applied across the fleet and accounted for.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Apply policies across your fleetPolicy assignment by tag, category or groupAssign a policy to a device, tag, category or device group. Write the rule once. | Not included | Included | Included | Included |
| Advanced rule logicAny, all and not conditionsBuild rules from any, all and not conditions, not just keyword matching. | Not included | Not included | Included | Included |
| Policy audit trailRule change historySee who created or changed a compliance rule, and when. | Not included | Not included | Not included | Included |
- Apply policies across your fleetPolicy assignment by tag, category or groupAssign a policy to a device, tag, category or device group. Write the rule once.Standard: IncludedEnterprise / MSP: Included
- Advanced rule logicAny, all and not conditionsBuild rules from any, all and not conditions, not just keyword matching.Standard: IncludedEnterprise / MSP: Included
- Policy audit trailRule change historySee who created or changed a compliance rule, and when.Standard: Not includedEnterprise / MSP: Included
Which AI features are on, who may push a change, and what gets recorded.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| AI usage audit logNewAI request loggingEvery AI request logged with user, feature, provider, model and token count. | Not included | Not included | Not included | Included |
| Control which AI features are enabledNewPer-feature AI switchesTurn each AI capability on or off independently. | Not included | Not included | Included | Included |
| Role-controlled configuration pushSnippet permissions by roleSnippets must be granted to a role before anyone can push them. | Not included | Included | Included | Included |
- AI usage audit logNewAI request loggingEvery AI request logged with user, feature, provider, model and token count.Standard: Not includedEnterprise / MSP: Included
- Control which AI features are enabledNewPer-feature AI switchesTurn each AI capability on or off independently.Standard: IncludedEnterprise / MSP: Included
- Role-controlled configuration pushSnippet permissions by roleSnippets must be granted to a role before anyone can push them.Standard: IncludedEnterprise / MSP: Included
What rConfig listens for, what it publishes, and how people sign in.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Receive SNMP traps from your devicesTrap receiver and filtersListen for traps, filter the ones that matter and act on them. | Not included | Not included | Included | Included |
| Stream events to your message busRabbitMQ publishingPublish rConfig events to RabbitMQ. | Not included | Not included | Not included | Included |
- Receive SNMP traps from your devicesTrap receiver and filtersListen for traps, filter the ones that matter and act on them.Standard: IncludedEnterprise / MSP: Included
- Stream events to your message busRabbitMQ publishingPublish rConfig events to RabbitMQ.Standard: Not includedEnterprise / MSP: Included
How finely access is cut, who is let in, and what the record shows afterwards.
| Feature | Core | Starter | Standard | Enterprise / MSP |
|---|---|---|---|---|
| Permissions for every module and actionPer-module CRUD permissionsFine-grained control over create, read, update and delete across the product. | Not included | Included | Included | Included |
| Change history on recordsRecord-level auditSee who edited a policy, device or snippet, and when. | Not included | Not included | Included | Included |
| Approve SSO users before first sign-inNew user approvalNew identity-provider users need approval before they get access. | Not included | Included | Included | Included |
| Audit log retention and archivingAudit retention policy | Not included | Not included | Included | Included |
- Permissions for every module and actionPer-module CRUD permissionsFine-grained control over create, read, update and delete across the product.Standard: IncludedEnterprise / MSP: Included
- Change history on recordsRecord-level auditSee who edited a policy, device or snippet, and when.Standard: IncludedEnterprise / MSP: Included
- Approve SSO users before first sign-inNew user approvalNew identity-provider users need approval before they get access.Standard: IncludedEnterprise / MSP: Included
- Audit log retention and archivingAudit retention policyStandard: IncludedEnterprise / MSP: Included