EVERY SERVER.
EVERY DIFFERENCE.
FULLY DOCUMENTED.

SECP validates configuration parity between any two Windows servers — on-prem to AWS, dev to prod, or server to server. Run the PowerShell collector on each machine, upload the ZIP exports, and the engine automatically checks 26 categories spanning services, applications, network config, open ports, .NET versions, SQL instances, certificates, firewall rules, and more. Findings are ranked critical, warning, or informational — so your team knows exactly what must be fixed before go-live. Pre-register your server fleet in the registry for automatic environment detection and baseline tracking.

Launch App ⬇ Download Collector 🔍 Collector Overview See How It Works Learn More
26
Comparison Categories
25
Collector Modules
4
Report Types
PS1
Collector Format
Premier App v2.0.0 Auth Required 26 Comparison Categories AI Executive Summaries Scheduled Runs

Five steps. Zero guesswork.

From raw server to migration report in under an hour.

01
Download Collector
Get Invoke-ServerInventory.ps1 — a single PowerShell script that runs as Administrator and executes 25 collector modules covering every major area of server state.
02
Run on Each Server
Execute the script on each Windows server. It captures services, applications, network config, open ports, .NET versions, SQL instances, certificates, firewall rules, and more — packaging everything into a ZIP for upload. Optional SHA256 file hashing with -EnableSHA256.
03
Upload ZIPs
Drag-and-drop or browse to upload the ZIP. A live per-file status panel shows all expected inventory files being processed individually. Each server gets a nickname, environment type, and role. Unknown hostnames are auto-registered.
04
Create Profile
Pair one baseline server with one or more target servers. Optionally exclude specific services or apps that are expected to differ, and add ignored rules for known-intentional differences.
05
Run & Export
Click Run Comparison. The engine checks all 26 categories, scores severity, and generates reports — detailed HTML/PDF, remediation checklist, trend analysis, fleet overview, or executive summary with AI-generated plain-language interpretation.

26 categories. Full coverage.

Every comparison run checks all categories simultaneously. AWS-native services (SSM Agent, EC2Launch, CWAgent, etc.) are automatically excluded from service diffs.

✓ Services
✓ Applications
✓ Scheduled Tasks
✓ Scheduled Task Details
✓ IIS Sites & App Pools
✓ Filesystem
✓ Folder Structure
✓ Windows Features
✓ Environment Variables
✓ Certificates
✓ Firewall Rules
✓ Patches / Hotfixes
✓ Server Specs (CPU/RAM)
✓ Local Users & Groups
✓ Network Config
✓ Open / Listening Ports
✓ DNS Client Settings
✓ Time & NTP Config
✓ Hosts File Entries
✓ .NET Versions
✓ SQL Server Instances
✓ Startup Programs
✓ SMB Shares
✓ Local Security Policy
✓ Device Drivers
✓ Server Metadata

More than just comparison.

SECP includes a server registry, environment baselines, upload history, and 4 report types for every audience — from sysadmin checklists to AI-generated executive summaries.

📋
Server Registry
Pre-register all your servers by hostname across 5 SDLC environments (development, state_test, UAT, performance, production). When a ZIP is uploaded, the hostname is matched automatically — environment type and role are pre-filled. Seeded with 28 hostnames out of the box.
🏆
Environment Baselines
Designate one server per SDLC environment as the canonical baseline. Dashboard shows sync status per environment — how many servers are in-sync, out-of-sync, not yet compared, or not scanned.
📂
Upload History & Drift Tracking
Every upload is retained. View all inventory versions for a server over time, compare across uploads, and detect configuration drift. Auto-register unknown hostnames on upload.
🚫
Ignored Rules
Per-profile rules that suppress known-intentional differences so they don't pollute your critical findings list. Specify a category, match type, pattern, and reason for each suppression.
📄
PDF & HTML Reports
Full migration-ready PDF reports with severity-banded findings, per-category summaries, and executive overview. HTML export also available. Report export history is logged.
🔐
Certificate Expiry Warnings
Certificate comparisons include 30/60/90-day expiry banding so near-expiry certs are surfaced as warnings before go-live. Dedicated certificate-expiry dashboard.
📈
Trend Analysis
Track a server's match percentage across every comparison run. Identify slow drift before it becomes a critical issue. Fleet-wide trend history.
🌐
Fleet Overview
One page showing which categories cause the most findings fleet-wide, your top offending servers, and compliance distribution.
🔧
Remediation Checklist
Auto-generated action items from every finding, grouped by server and prioritised by severity. Hand it directly to your sysadmin for immediate action.
🤖
AI Executive Summary
Claude Haiku reads the severity/category digest from each run and writes a 2–3 sentence plain-language summary — ready to paste directly into a status update or management report.
Scheduled Reports
A cron scheduler (Kronos) re-runs your profiles automatically, always refreshing the stalest one first. Completed runs push a Telegram summary and a platform Herald alert — critical findings raise the alert level.
📥
Path Exclusions & CSV Export
Global filesystem exclusion rules (folder, extension, glob, file_exact, folder_exact) suppress noise from temp dirs and dynamic paths. Download findings or profiles as CSV for spreadsheets.

Every finding is ranked.

The engine assigns severity based on what's missing and what differs. You know at a glance what must be fixed before go-live versus what can be addressed post-migration.

⚠️
Critical
Required components missing from the target server. Must be resolved before go-live. Examples: missing apps, absent scheduled tasks, absent Windows features, missing services.
Warning
Differences that may cause issues. Should be reviewed before cutover. Examples: version mismatches, different service startup types, changed environment variable values.
ℹ️
Info
Informational differences that may be expected in a cloud environment. Review for awareness. Examples: firewall rules that differ between on-prem and AWS by design.

Ready to validate your migration?

Launch SECP to upload your first server inventory, or download the PowerShell collector to start gathering data from your servers today. No configuration required — just run and upload.

Launch App ⬇ Download Collector 🔍 Collector Overview Premier App — requires a MelTuc account