Swiss-Made by NordfoldIn enterprise production
Solutions

Build security tools your team will actually use.

Kona is an on-premises platform where security and network engineers connect systems, build task and service automation, and create internal tools — governed by one runtime with SSO, RBAC, quotas and tamper-evident audit already wired in.
What teams build

What teams build on Kona.

The platform provides the foundation. What you build on it depends on your environment and your priorities — and inherits SSO, RBAC, audit, multi-tenancy and auto-generated APIs automatically. Concrete examples follow below.

01Unified Visibility

Aggregated data, no system-hopping

Build a tool that pulls firewall rules, asset owners, change tickets, and monitoring data into one view. Engineers get their answers from one place instead of logging into scattered systems.

02Workflow Automation

Streamlined ticket resolution

Build a workflow where the engineer sees the complete picture when a change ticket arrives: current state from the firewall, related rules, asset ownership, open vulnerabilities. Review, apply, done.

03Governed Self-Service

Granular access for other teams

Build a tool once and share it through a governed API or web UI. Colleagues get read-only policy access. An infrastructure team consumes an API. A compliance officer runs a report. RBAC ensures each person sees exactly what they should.

04Cross-System Orchestration

Cross-system workflows that didn't exist

Recertification that cross-references firewall rules with asset owners and traffic logs. Compliance checks combining vulnerability data with policy state. Possible for the first time because the platform connects everything.

How teams get started

Platform on day one. Custom tools from week one.

Every tool on the platform — whether built by Nordfold or your team — gets the same security model, the same audit trail, the same governed access.

01

Deploy the platform

Install Kona on your container infrastructure. Full foundation: SSO, RBAC, audit trails, multi-tenancy, API management, hardened runtime. No platform to build first.

02

Nordfold builds the base

Included professional services hours cover the first integrations and applications tailored to your environment. Working tools and connected systems from day one.

03

Your team builds

With Kona AI Skills, network engineers with scripting experience can build task automation and service automation tailored to your environment. The platform handles the enterprise layer.

Kona AI Skills

Kona fully supports AI-assisted development.

Engineers describe what they need. Kona AI Skills provide the platform and integration knowledge so any AI coding assistant can turn that into a governed, production-ready service.

Engineer prompt
Build me an app that integrates {system A} and {system B} and {performs task} whenever the user {trigger}. The app should contain {UI description}
Company AI
enriched with Kona AI Skills

Kona Platform Skills

ArchitectureFrontend & UIWeb Components

"What components work for this UI?"

Kona Integration Skills

Auth FlowsRate LimitsPaginationObject Models

"How does the Tufin API work?"

WorkflowProcess

Policy Recertification

SAP HRM. Koch
SalesforceS. Brunner
Jenkins CIL. Weber
ConfluenceT. Meier
DashboardMonitor

SOC Portal

fw-core-013 alerts
sw-dmz-021 alert
vpn-gw-03healthy
GovernanceControl

Compliance Validator

Rulefw-corefw-dmz
HTTPS-INallowallow
SSH-MGTdenydeny
TELNETdenyallow
RDP-EXTdenydeny
Kona

Everything your team builds inherits the platform's full security model.

AI is entirely optional. The Skills work just as well as structured documentation for engineers building directly against the platform APIs.

Migrating existing scripts

Turn existing scripts into governed services.

Most teams have scripts that already do useful work but run on individual workstations with no access control or logging. Kona AI Skills guide engineers through turning that logic into a backend service with a defined API. Once registered on the platform, the service inherits SSO, RBAC, audit trails, and is accessible via web UI and REST API.

Before

Python script

Runs on laptopShared credentialsNo loggingSingle user
Kona AI Skills
After

Governed service

Runs on KonaManaged credentialsFull audit trailSSO & RBAC
A closer look

Tools built on Kona.

From violation heat maps to router config diffs — real tools teams build and operate daily, all governed by one runtime.

kona.internal / apps / violations
Violation Heat Map — Matrix of policy violations from one zone to another.
Unified Rule Viewer — Search and explore firewall rules across all vendors and sites in one governed view.
Unified Group Viewer — Firewall groups from all vendors and sites, with the details of one group open.
Router Config Manager — Configure all router configurations directly from one place.
Router Config Manager / Diff Mode — Compare configuration versions side by side.
01
Violation Heat MapMatrix of policy violations from one zone to another.
Example tools teams build

Policy Recertification

Periodically recertify firewall policies. Assign owners, collect sign-off, retire rules no longer justified, and maintain a full audit trail of every recertification cycle.

SOC Portal

A governed interface for SOC analysts to query policy state, check rule context, and validate changes — without direct firewall access or waiting on the network team.

Compliance Validator

Continuously check policy state against internal standards and regulatory requirements. Flag violations, generate evidence for audits, and track remediation.

Certificate Automation

Inventory, rotation and renewal of certificates across the estate. Surface what's expiring, where it's used, and who owns it before it breaks.

Policy Sync Manager

Keep rule sets and shared objects consistent across vendors, regions and tenants. Detect drift, propose merges, apply with approval.

Device Monitor

Health, version and status summary for every firewall, proxy and VPN gateway in scope. Failures and drift surface before tickets do.

Zone Lookup Tool

Resolve any IP, subnet or hostname to the security zone it lives in — across vendors and sites. Stops the “which zone is this?” e-mails.

Proxy Policy Manager

A single, governed view of proxy access lists. Edit, review and audit them with the same RBAC and approval flow as everything else.

See what Kona connects to.

Explore the systems Kona integrates with — firewalls, proxies, VPN gateways, ticketing, monitoring and more.