Home About
About Bonsai Security
We run firewalls that MSPs have already sold, under the MSP's own brand. This page covers who that makes us, why an operator publishes vendor-neutral comparisons, and the standards those comparisons are written to.
What we do
Bonsai Security provides white-label managed firewall operations to managed service providers.
An MSP sells a firewall to their customer. We run it: monitoring, patching, rule changes, incident response and out-of-hours cover, under the MSP's brand rather than ours. The customer's relationship stays with the MSP, and the reports, tickets and change notices carry the MSP's name.
We work across Fortinet, Palo Alto, Cisco, SonicWall, Sophos, Meraki, Check Point and Juniper. The services page sets out what each coverage model includes.
Why channel-only
We take no direct end-customer business. That is a structural commitment rather than a current preference.
An operator that also sells direct is a competitor to the MSPs it serves, and every customer environment it touches is a prospect list. Refusing direct business is the only version of this arrangement an MSP can safely hand a customer to. It also means we have no reason to prefer one platform over another, which is what makes the next section possible.
Why a firewall operator publishes vendor-neutral comparisons
We sell operations rather than hardware. Our side of the arrangement stays the same whichever platform a customer selects, so we have no commercial reason to favor either answer in a comparison.
That is an unusual position in this subject area. Vendor material argues for its own product. Reseller material argues for the line it carries. Affiliate roundups are paid by the click. We are none of those, and the resource library exists because that gap is worth filling.
The commercial interest we do have is stated plainly on every page that has one: once the platform decision is made, somebody has to operate the thing, and we would like that to be us. That is the only ask in the library, it appears once per page, and it never sits in the middle of the analysis.
How pages get written
The library follows a written editorial standard. The summary is here; the full version governs every page.
Every claim is one of three kinds
- Datasheet. A vendor figure, cited with the vendor's own test conditions and the date we checked it.
- Operator. Something we have seen running these platforms, marked as ours and bounded.
- Judgement. A view, labelled as one, with the reasoning shown.
We run no lab
Every throughput, latency and capacity figure in the library is a vendor figure, cited as one. We publish no benchmark of our own, because we have not run one. Where a page would be stronger with a number we do not have, it ships without the number.
The same rule applies to our own operational statistics. If a sentence would be better with a ticket volume in it, and that figure has not come out of our own records, the sentence ships without it.
Both vendors get named weaknesses
On every comparison page. A page that reads as advocacy for one platform contradicts the service we sell and would be worth less to the reader, so neutrality is a product requirement here rather than a stylistic preference.
Dates are load-bearing
Specs, SKU names, licence bundles and lifecycle dates all move, and a stale spec quoted in a customer meeting embarrasses the person who trusted it. So each page carries a visible checked date, every volatile claim is logged in a review register with the source it came from, and the register is walked quarterly. Where a claim cannot be re-verified, the claim comes out rather than staying up with an old date attached.
The visible date, the structured data and the sitemap all read from the same field, so they cannot drift apart.
How we use AI
Pages in the library are drafted with AI assistance and published under the standards above.
What that means in practice: the drafting is assisted, and the claims are checked against primary sources before they go up. Vendor behaviour is verified against the vendor's own current documentation rather than against a model's recollection, which is why the source lines name specific documents and carry the date they were checked. Where documentation contradicted what we expected, the page says what the documentation says.
We are telling you this because it is a reasonable thing to want to know, and because a page that claims operating experience should be clear about how it was produced. It changes nothing about who is accountable for what is written here. If something on this site is wrong, it is ours.
When we get it wrong
Some of this will be wrong. Vendor documentation changes, our reading of it can be off, and the products move faster than any page about them.
Tell us and we will fix it. Corrections that change the meaning of a page get made on the page and the checked date moves with them. We would rather be corrected in public than be confidently wrong in a customer meeting somebody walked into on our say-so.
Reaching us
Email partners@bonsaisecurity.com. That address reaches a firewall engineer rather than a sales sequence, and it is the right one for a correction, a question about a page, a security disclosure, or a request to remove data we hold about you.
How we handle anything you send is set out in the privacy notice.
You advise. We operate.
If the library is useful, the service behind it is the part that runs the estate after the decision is made. Fortinet, Palo Alto and six other platforms, under your brand, from $29 per firewall per month.
Become a partner