Denetta — How healthy is your infrastructure?
One score, with the reasons.
Denetta audits your infrastructure without writing to a single device: today it starts with firewalls and network devices, and it is expanding to servers, mail and cloud. Expert rules produce findings and a 0-100 Infrastructure Health Score.
What is Denetta? Denetta is an IT infrastructure health and security audit platform developed by BilgiTek. Today it audits FortiGate firewalls and network devices by reading only, without writing to any device; expert rules produce concrete findings, which are combined into a single 0-100 Infrastructure Health Score. Server, mail and cloud modules are on the roadmap.
What Cardinal does for SQL Server, Denetta does for the rest of the infrastructure.
Denetta's audit engine does not use artificial intelligence: every finding rests on an explicit rule, and the same configuration always gives the same result.
Findings, not metrics.
RMM watches endpoints, NMS watches the network, the CVE scanner watches vulnerabilities. Management asks one question: "How healthy is our infrastructure?" Denetta answers it with concrete findings, not charts.
Every finding names the record that triggered it: which policy, which interface, which account. The fix command is given in the device vendor's syntax and is only displayed, never executed.
Unrestricted management access from WAN
Firewall · management plane · FortiGateEvery score, justified rule by rule
Every category starts at 100; findings deduct points by severity. The score is calculated so that it rises with every fix; even the first few fixes move it.
| Rule | Finding | Status |
|---|---|---|
FW-002 | Unrestricted management access from WAN | Critical |
NET-001 | SNMP community 'public' | High |
FW-033 | No SSL inspection | Medium |
FW-037 | Subscription status could not be read | Visibility gap |
+ other checks | Passed |
- Categories you do not use do not lower the score
They appear as "out of scope" in the report.
- Unreadable data does not count as "passed"
It is reported as a "visibility gap". Unknown does not mean clean.
- Every fix moves the score
The score is not a hard clamp; even the first few fixes move the number.
FGT-DEMO-01 · Head office
FortiOS 7.4 · HA pair · last scan today 06:00| Firewall | 58 |
| Network devices | 81 |
| Vulnerabilities | 64 |
| Cloud | out of scope |
What does Denetta do?
One cross-domain score
Today firewalls, network devices and vulnerabilities; on the roadmap servers, storage, mail and cloud. All in a single 0-100 score.
CVE priority by real risk
Vulnerabilities are prioritised not only by CVSS score but by CISA KEV (actively exploited) and EPSS data. A fixed release on the same branch is suggested where one exists, otherwise a branch upgrade.
Vendor-specific fixes
The same check comes with a Cisco command on Cisco and a MikroTik command on MikroTik.
Change tracking
Periodic scanning. If an unannounced config change opens a new critical or high risk, you are notified by email; the email contains no config value, IP address or policy name.
Full config backup archive
The full backup your device produces itself is archived encrypted, with version history and the diff between any two versions. We set up the one-time on-device automation together. Denetta never restores a backup to the device.
Multi-tenant for MSPs
Company → site → device hierarchy, row-level isolation, role-based access, a read-only panel for the customer.
| Company / site | Score |
|---|---|
| Demo Logistics | 71 |
| └ Head office | 67 |
| └ Warehouse | 78 |
| Demo Clinic | 84 |
| Demo Retail · 12 sites | 62 |
It writes to no device.
That is not a feature; it is what the product is.
Denetta has no enforcement plane and never will. We also check whether the account used for the audit is read-only, and show the result in the report.
The auditor's own access is audited too.
- Only
show / get / displaycommands and SNMP GET/WALK; never SET - No active exploit attempts; vulnerabilities are detected by version ⇄ CVE matching
- Fix instructions are only displayed
- Credentials in an AES-256-GCM encrypted vault, with least privilege
The audit engine does not use artificial intelligence; every finding rests on an explicit rule.
Setup, with the least privilege
We never ask for a port to be opened in the customer network. Data flows one way, outbound.
show · get · SNMP GET · API
HTTPS · one way
Expert rule sets
Rule-by-rule breakdown
A scan that connects to a device starts only with the customer's signed and stamped written consent. Which site and which IP block may be scanned is limited by that signature.
A read-only API user on the FortiGate, restricted by source IP. The command set is generated for you in the panel.
From the core via read-only API, or through a collector in your network (outbound 443 only). You can also start with a single backup file, with nothing installed.
Rule-by-rule breakdown, vendor-specific fix instructions and a PDF report you can leave with the customer.
Infrastructure Audit Report
Demo Logistics · Head office
September 2026
Summary
Priority findings
Pilot: A pilot on a real production FortiGate (FortiOS 7.6) produced 19 findings. Each was checked one by one with the field team; there were no false positives.
One score, four different needs
Manage 40 customers in one panel with a score per site; give each customer a read-only panel.
Take management the answer to "how healthy is our infrastructure" as a single number, with the reasons.
Repeatable, config-based findings and evidence.
Get your first report from a single FortiGate backup, with nothing installed.
What is available today, and what is next?
Today
FortiGate: policy, management plane, VPN, HA, UTM
CVE.org + CISA KEV + EPSS
Scheduled scans, config drift, score trend, email; full backup archive in early access
Cisco, Aruba, UniFi, MikroTik and 20 vendor profiles
Roadmap
KVKK, 5651, ISO 27001, PCI DSS gap report
Audits 5651 readiness; does not replace statutory retention
First slice: VPN session report
Per site, per module
Licensing is per site; we do not count devices. You pay only for the modules you use.
Firewall Bundle
- Firewall Audit
- Periodic Scanning and Change Tracking
- Vulnerability and Lifecycle
Firewall Audit
FortiGate config audit (121 rules), 0-100 score, vendor-specific fix instructions, file upload and manual data intake, audit of Denetta's own access
Periodic Scanning and Change Tracking
Scheduled scans, config change alerts, score trend; full backup archive in early access
Vulnerability and Lifecycle
FortiOS version ⇄ CVE.org, CISA KEV, EPSS
Network Device Audit
Switches and routers at the site, 20 vendor profiles; access points, printers, cameras and IoT free
- Prices in USD, excluding VAT
- An HA pair at one site counts as one firewall
- 15% discount for annual prepayment
- Contact us for MSP and reseller pricing
Coming soon
Pricing to be announced. Contact us for early access.
It does not replace your RMM; it sits on top of it
Keep your Zabbix, keep your NinjaOne. Let them stay on real-time monitoring; Denetta adds a layer of periodic deep audit, scoring and expert analysis on top.
Denetta — technical specifications
| Supported firewall | FortiGate, FortiOS 7.2 / 7.4 / 7.6 |
|---|---|
| Network devices | 20 vendor profiles (Cisco, Aruba, UniFi, MikroTik …) |
| Collection | Read-only REST API (GET only), collector (SNMP GET/WALK, SSH show), backup file |
| Connection direction | Collector outbound 443 only; no inbound port |
| Collector | .NET 8, Windows service / Linux systemd |
| Vulnerability data | CVE.org, CISA KEV, FIRST EPSS |
| Credentials | AES-256-GCM encrypted vault, least privilege |
| Multi-tenancy | Company → site → device; PostgreSQL row-level isolation |
| Hosting | In Türkiye |
| Consent | Signed and stamped written consent; scope limited by signature |
| Audit engine | Deterministic JSON rules; no artificial intelligence |
| Notifications | Email (Microsoft 365); carries no config value, IP or policy name |
Denetta, in detail
Your first report is free.
Let us prepare a one-off audit report from a FortiGate backup; we do not connect to your device and change nothing.
A backup file contains passwords and keys: do not send it by email. Write to us and we will arrange a secure transfer and your declaration that you are authorised for the device.
