Tufin: Enterprise Corporate Overview and Product Portfolio
Company Overview
Tufin (Tufin Software Technologies Ltd.) is a prominent cybersecurity software company focused on Network Security Posture Management (NSPM), security policy orchestration, and automated risk compliance. Founded in 2005 by Ruvi Kitov and Reuven Harrison, the company establishes operational headquarters in Boston, Massachusetts, alongside primary research and development facilities in Tel Aviv, Israel. Tufin serves thousands of enterprise customers globally, including Fortune 500 companies, large financial institutions, telecommunications providers, and managed security service providers (MSSPs).
The core operational function of Tufin is to simplify network complexity and eliminate security fragmentation. As enterprise infrastructures migrate into multi-vendor hybrid models?combining on-premises traditional firewalls, cloud-native environments, Secure Access Service Edge (SASE) platforms, and microsegmentation technologies?security teams experience visibility gaps and policy drift. Tufin addresses this by serving as a centralized, vendor-agnostic control plane. The software acts as an analytics and governance layer that continuously maps physical and virtual topography, tracks compliance infractions, and automates necessary rule alterations across complex IT ecosystems.
Continue…
Core Operational Platform: The Tufin Orchestration Suite (TOS)
The company?s flagship commercial product is the Tufin Orchestration Suite (TOS). Offered across distinct scalable tiers (including SecureTrack+ and SecureChange+), this centralized suite continuously collects configuration logs, policies, and traffic rules directly from active infrastructure components. By running these inputs through its proprietary Dynamic Network Connectivity Graph, the suite constructs an interactive topology map of the enterprise network, identifying active communication paths and misconfigurations.
The suite is segmented into dedicated modules, each designed to tackle specific components of security change management, audit preparation, and risk mitigation:
1. SecureTrack+ (Network Posture & Compliance Monitoring)
SecureTrack+ functions as the primary visibility, auditing, and real-time compliance validation layer within the Tufin suite. It provides firewall administrators and risk officers with a single pane of glass to observe the total network attack surface.
- Real-Time Firewall Policy Management: Monitors structural adjustments to next-generation firewalls (NGFWs), routers, switches, and load balancers across all major market vendors.
- Continuous Compliance Engine: Instantly compares newly implemented configuration rules against an established enterprise security policy baseline. It flags overly permissive access, shadowing rules, or insecure pathways that violate regulations such as PCI DSS, HIPAA, NERC CIP, SOX, and NIST frameworks.
- Policy Cleanup & Optimization: Analyzes historical traffic logs to uncover stale, unused, or redundant firewall rules. It provides actionable recommendations to decommission dead policies, tightening the corporate perimeter and maximizing firewall processing performance.
2. SecureChange+ (Network Change Process Automation)
SecureChange+ addresses the human error, administrative friction, and long Service Level Agreements (SLAs) associated with manually updating firewall access rules. It transforms security change workflows from a series of disjointed tickets into risk-aware, policy-driven automated processes.
- Automated Risk Analysis: When a network modification or new access request is submitted, the system automatically checks the proposed path against the security baseline. It alerts engineers to potential lateral movement vulnerabilities or compliance breaches before the change goes live.
- The Designer and Verifier Tools: The automated "Designer" component creates the precise command-line interface (CLI) or API code required to execute the approved access change across the relevant multi-vendor hardware devices. Following execution, the "Verifier" tool cross-checks live device states to guarantee the change matches the approved ticket and is documented cleanly for future IT auditors.
- ITSM Integration (Workflow Integrator): Connects natively with mainstream IT Service Management (ITSM) systems like ServiceNow, Jira, and Remedy, synchronizing data fields, approval states, and verification logs without manual re-entry.
3. SecureApp (Application Connectivity Management)
SecureApp introduces an application-centric approach to managing network policies. Rather than expecting application developers to understand complex IP addresses or underlying network topography, this module bridges the gap between infrastructure teams and software deployments.
- Application Dependency Mapping: Graphically traces how corporate applications communicate across the hybrid architecture. It defines application requirements based on connectivity logic rather than hardcoded infrastructure coordinates.
- Lifecycle Management: When an application is deployed, updated, or decommissioned, SecureApp interfaces with SecureChange to automatically open the required network tickets, modify firewall rules, or safely run server decommissioning workflows without disrupting unrelated services.
Embedded Technology: TufinAI
To address the challenges introduced by highly dynamic modern networks and the emergence of fast-moving cyber threats, the platform embeds TufinAI, a specialized machine learning and artificial intelligence engine. TufinAI is designed to scale operational outputs and lower technical barriers across the security lifecycle:
- Natural-Language Control Plane: Allows network engineers, corporate auditors, and compliance analysts to query intricate security configurations using natural language. Staff can locate specific rules, active access paths, or compliance deviations without needing advanced scripting knowledge.
- Predictive Posture Modeling: Assists security teams in visualizing how potential topology changes, SASE rollouts, or cloud migrations will interact with existing boundaries, mitigating unexpected downtime or unintended exposures.
Supported Infrastructure & Integrations
Tufin operates as a strictly vendor-neutral overlay, avoiding lock-in and allowing enterprises to orchestrate unified guardrails across heterogeneous environments. The platform integrates with major technologies across several categories:
- Traditional & Next-Gen Firewalls: Palo Alto Networks, Fortinet, Check Point, Cisco, Juniper Networks.
- Cloud & SDN Ecosystems: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), VMware NSX, Cisco ACI.
- SASE & Security Edge Providers: Zscaler, Palo Alto Prisma Access, Cisco Secure Connect.