Stop worrying about
zero days

Lock your VPN, remote support, RMM, web applications, and more down to your own devices. A lightweight agent keeps your firewall's allow list synced to your team's current IPs — scanners, bots, and the next zero-day never even see a login page, and the time that buys you is the difference between a scheduled patch and a breach.Allow what's needed. Deny everyone else.

Start for free → See how it works
allowist — live heartbeat
12:00:01 203.0.113.45KG-workstation · unchanged 4 entries active
12:01:01 203.0.113.45 → .99IP changed · allow list updated ✓ allowed
12:01:03 firewall pollPalo Alto EDL refreshed · 4 IPs 200 OK
Why it matters

Shrink your
attack surface

Every IP that can reach your VPN or admin portal is a potential entry point — and when a zero-day hits, exposed services get hit first. Allowist keeps your allow list current automatically, so unknown IPs never reach the service at all.

Zero-days can't reach youAn exploit can't fire from an IP the firewall never lets through.
No stale rules, no lockoutsIP changed? The list already knows. No tickets.
Your existing firewallWorks with anything that reads an external IP list.
How it works

Three steps,
zero manual work

Allowist reduces attack surface Trusted devices check in with Allowist to update their IPs. Approved traffic is allowed through the policy line while unknown internet traffic is blocked below it. TRUSTED DEVICES UNTRUSTED SOURCES PROTECTED SERVICES Allowist ALLOW BLOCK APPROVED TRAFFIC 0.0.0.0/0 · ::/0
Device check-in / IP update Policy-approved traffic Unknown or unwanted traffic
agents report IPs → your traffic passes the green Allowist list → everything else bounces off the wall
Point your firewall at one URL, and only your people get in. The Allowist agent on each device reports its current IP; your firewall allows inbound traffic exclusively from your Allowist list. Scanners, bots, and attackers never get past the wall — your VPN, remote-support tools, and web apps simply aren't reachable from anywhere else.
01REPORT
Agents report their current IP

A lightweight agent checks the device's public IP and reports only when it changes. No user action, no open inbound ports.

02UPDATE
Allowist updates the allowlist

Old IPs are removed, new IPs are added, and every change is logged automatically. Your manual entries are never touched.

03ENFORCE
You configure your firewall

Point your firewall at the Allowist feed and allow only traffic from that list. Allowist provides the source IPs — your firewall enforces them.

Built for security. Designed for simplicity.
No more stale IPs
Old addresses are removed automatically after a TTL, or the moment a device checks in from a new location.
Temporary access
Grant contractor or vendor access that expires on its own. No cleanup, no forgotten holes in the wall.
Audit-ready
Every IP change, feed fetch, and member action is logged with actor, timestamp, and source IP. Exportable to CSV.
Default deny by design No inbound ports Works anywhere Set up in minutes
Firewall support

Every major platform
natively supported

Allowist generates the exact format each vendor expects. Point your firewall at a URL and you're done.

paloalto
Palo Alto Networks
Panorama & NGFW EDL
fortinet
Fortinet FortiGate
External Connector feed
cisco_acl
Cisco IOS / IOS-XE
Named extended ACL
cisco_asa
Cisco ASA
object-group network
juniper
Juniper SRX
prefix-list policy-options
checkpoint
Check Point
Bulk host object JSON
f5
F5 BIG-IP
iRule data-group class
iptables / nftables
Linux firewall
bash script · nft config
Pricing

Simple,
transparent plans

All plans include all 12 firewall formats and full audit logging. Billed monthly via PayPal.

Free
$0
forever
1 EDL
5 agents
1 user · single IPs only
All 12 formats
Audit log (30 days)
Team members
Email notifications
Starter
$19.99
/ month
2 EDLs
100 agents
Unlimited team members
IP subnets (CIDR)
CSV import
Email notifications
Email support
Most popular
Pro
$49.99
/ month
5 EDLs
300 agents
Everything in Starter
Feed authentication (Basic Auth)
Feed IP restriction
Business
$99.99
/ month
10 EDLs
1,000 agents
Everything in Pro
Custom audit retention
Data export (audit + org)
Enterprise
$299.99
/ month
25 EDLs
10,000 agents
Everything in Business
SAML SSO (Okta / Microsoft)
API keys & webhooks
Start Enterprise
Need more capacity? Contact us

Payments via PayPal · Cancel anytime · No card required for free tier

FAQ

Common
questions

How does this reduce my attack surface?
Your VPN or admin portal is only reachable from IPs on your allow list. When a zero-day drops, it can't be exploited from an IP that was never allowed through the firewall to begin with.
Do agents need elevated privileges or open ports?
No. Agents only make outbound HTTPS calls to detect their IP and send heartbeats. They run as a standard system service — no open ports, no admin rights after install.
What happens if an agent goes offline?
Its last known IP stays in the allow list and the agent shows offline in your dashboard. You can remove it manually, get an email alert, or set a stale-TTL policy that sweeps it automatically.
Can I import an existing list of IPs?
Yes — any allow list supports CSV import. Upload a file with an ip column and optional label column. Duplicates are skipped automatically.
How does payment work?
All plans billed monthly via PayPal. Upgrade, downgrade, or cancel anytime. Enterprise customers can arrange annual invoicing — [email protected].
Is there anything to install server-side?
No. Allowist is a fully managed cloud platform. Just sign up, create an allow list, and install the lightweight agent on each workstation.
Get started

Expose nothing.
Allow only your own.

The free plan is permanent. Your first allow list can be live in about 10 minutes.

Create free account → Talk to us