Skip to main content
I

Invariant

Invariant provides a network security access policy verification platform that ensures policy invariants across multi‑vendor, cloud, and on‑premise environments before any change is applied. Leveraging the Batfish offline digital twin, it predicts the impact of modifications to ACLs, OSPF, BGP, VLANs, and more using only up‑to‑date device configuration files, without requiring any network access. The tool integrates with existing config collection scripts and can be run directly from the command line for rapid onboarding and continuous compliance checks.

Updated 1 month ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Network operators often lack a safe, automated way to verify that changes to ACLs, routing protocols, VLANs, and other configurations will not violate security policies or disrupt connectivity across heterogeneous, multi‑vendor environments. Manual review is time‑consuming, error‑prone, and typically requires direct access to live devices.

Solution

Invariant provides a command‑line driven platform that builds an offline digital twin of a network from up‑to‑date configuration files. Using the Batfish engine, it simulates proposed configuration changes and evaluates their impact on connectivity, policy compliance, and security invariants before any deployment. The analysis runs without any network access or agents, supporting on‑premise, cloud, and hybrid infrastructures across a wide range of vendors. Results are presented as policy‑violation reports and flow validation outcomes, enabling engineers to catch issues early and maintain consistent security posture. The tool integrates with CI/CD pipelines, version‑controlled config repositories, and can be invoked programmatically via its SDK or API for continuous compliance monitoring.

Target Audience

Primary users are network engineers, security operators, and DevOps teams responsible for managing multi‑vendor, hybrid network environments.

Features

  • Offline digital twin creation from plain configuration files (no network access or agents required)
  • Batfish‑powered simulation of ACL, OSPF, BGP, VLAN and other configuration changes
  • YAML‑based policy definition and automated violation detection across the entire network
  • Command‑line interface, SDK, and REST API for integration into CI/CD workflows and git‑based config repositories
  • Vendor‑agnostic support including Cisco, Juniper, Palo Alto, AWS, and other common network devices
  • Historical analysis of configuration snapshots to track compliance trends over time
This profile is AI-generated and may contain inaccuracies.