Avast Gold Partner Kaspersky Silver Partner
IT infrastructure health and security audit

Denetta — How healthy is your infrastructure?
One score, with the reasons.

Denetta audits your infrastructure without writing to a single device: today it starts with firewalls and network devices, and it is expanding to servers, mail and cloud. Expert rules produce findings and a 0-100 Infrastructure Health Score.

Reads only, never writesConnecting to a device requires signed consentHosted in Türkiye
Infrastructure Health ScoreSample view
67/ 100

14 findings · 1 critical · 4 high

Firewall58
Network devices81
Vulnerabilities64
Cloudout of scope

What is Denetta? Denetta is an IT infrastructure health and security audit platform developed by BilgiTek. Today it audits FortiGate firewalls and network devices by reading only, without writing to any device; expert rules produce concrete findings, which are combined into a single 0-100 Infrastructure Health Score. Server, mail and cloud modules are on the roadmap.

What Cardinal does for SQL Server, Denetta does for the rest of the infrastructure.

Denetta's audit engine does not use artificial intelligence: every finding rests on an explicit rule, and the same configuration always gives the same result.

140expert audit rules · FortiGate 126 + network devices 14
20vendor profiles
443outbound-only connection; no inbound port required from the customer
0write commands sent to devices
Findings

Findings, not metrics.

RMM watches endpoints, NMS watches the network, the CVE scanner watches vulnerabilities. Management asks one question: "How healthy is our infrastructure?" Denetta answers it with concrete findings, not charts.

CriticalUnrestricted management access from WANFirewall · management plane
HighSNMP community 'public'Network devices
CriticalFortiOS version is affected by an actively exploited vulnerabilityVulnerabilities · CISA KEV

Every finding names the record that triggered it: which policy, which interface, which account. The fix command is given in the device vendor's syntax and is only displayed, never executed.

Denetta.Findings › FW-002Sample view · demo tenant
Critical

Unrestricted management access from WAN

Firewall · management plane · FortiGate
Recordinterface: wan1
Open servicehttps · ssh
Source restrictionnone (trusthost empty)
# Suggested fix — displayed only, never executed config system interface edit "wan1" set allowaccess ping next end config system admin edit "<admin>" set trusthost1 <mgmt-net> 255.255.255.0 end
Vendor-specific commandSource: config backupScore impact: −12
Score: "Why 72?"

Every score, justified rule by rule

Every category starts at 100; findings deduct points by severity. The score is calculated so that it rises with every fix; even the first few fixes move it.

Why 72? · rule-by-rule breakdownSample view
RuleFindingStatus
FW-002Unrestricted management access from WANCritical
NET-001SNMP community 'public'High
FW-033No SSL inspectionMedium
FW-037Subscription status could not be readVisibility gap
+ other checksPassed
  • Categories you do not use do not lower the score

    They appear as "out of scope" in the report.

  • Unreadable data does not count as "passed"

    It is reported as a "visibility gap". Unknown does not mean clean.

  • Every fix moves the score

    The score is not a hard clamp; even the first few fixes move the number.

Denetta.Devices › FGT-DEMO-01Sample view · demo tenant

FGT-DEMO-01 · Head office

FortiOS 7.4 · HA pair · last scan today 06:00
67
Firewall58
Denetta.58Sample view · demo tenant
Network devices81
Denetta.81Sample view · demo tenant
Vulnerabilities64
Denetta.64Sample view · demo tenant
Cloudout of scope
14 findings · 1 critical · 4 high · 1 visibility gap
Last 8 scans
Capabilities

What does Denetta do?

One cross-domain score

Today firewalls, network devices and vulnerabilities; on the roadmap servers, storage, mail and cloud. All in a single 0-100 score.

CVE priority by real risk

Vulnerabilities are prioritised not only by CVSS score but by CISA KEV (actively exploited) and EPSS data. A fixed release on the same branch is suggested where one exists, otherwise a branch upgrade.

Vendor-specific fixes

The same check comes with a Cisco command on Cisco and a MikroTik command on MikroTik.

Change tracking

Periodic scanning. If an unannounced config change opens a new critical or high risk, you are notified by email; the email contains no config value, IP address or policy name.

Early access

Full config backup archive

The full backup your device produces itself is archived encrypted, with version history and the diff between any two versions. We set up the one-time on-device automation together. Denetta never restores a backup to the device.

Multi-tenant for MSPs

Company → site → device hierarchy, row-level isolation, role-based access, a read-only panel for the customer.

Denetta.CompaniesSample view · demo tenant
Company / siteScoreFindingsLast scan
Demo Logistics71
Denetta.71Sample view · demo tenant
22today
└ Head office67
Denetta.67Sample view · demo tenant
14today
└ Warehouse78
Denetta.78Sample view · demo tenant
8today
Demo Clinic84
Denetta.84Sample view · demo tenant
6yesterday
Demo Retail · 12 sites62
Denetta.62Sample view · demo tenant
51today
Read-only customer panel · role-based access
Read-only

It writes to no device.
That is not a feature; it is what the product is.

Denetta has no enforcement plane and never will. We also check whether the account used for the audit is read-only, and show the result in the report.

The auditor's own access is audited too.

  • Only show / get / display commands and SNMP GET/WALK; never SET
  • No active exploit attempts; vulnerabilities are detected by version ⇄ CVE matching
  • Fix instructions are only displayed
  • Credentials in an AES-256-GCM encrypted vault, with least privilege

The audit engine does not use artificial intelligence; every finding rests on an explicit rule.

How it works

Setup, with the least privilege

We never ask for a port to be opened in the customer network. Data flows one way, outbound.

01
Consent and scope

A scan that connects to a device starts only with the customer's signed and stamped written consent. Which site and which IP block may be scanned is limited by that signature.

02
Read-only access

A read-only API user on the FortiGate, restricted by source IP. The command set is generated for you in the panel.

03
Collection

From the core via read-only API, or through a collector in your network (outbound 443 only). You can also start with a single backup file, with nothing installed.

04
Score and report

Rule-by-rule breakdown, vendor-specific fix instructions and a PDF report you can leave with the customer.

Sample view · demo tenant
Denetta.
Infrastructure Audit Report

Demo Logistics · Head office
September 2026

67 / 100
Summary
Priority findings
WAN management accessCritical
SNMP 'public'High
No SSL inspectionMedium
Subscription unreadableVisibility gap

Pilot: A pilot on a real production FortiGate (FortiOS 7.6) produced 19 findings. Each was checked one by one with the field team; there were no false positives.

Who it is for

One score, four different needs

MSP

Manage 40 customers in one panel with a score per site; give each customer a read-only panel.

In-house IT manager

Take management the answer to "how healthy is our infrastructure" as a single number, with the reasons.

Auditor / consultant

Repeatable, config-based findings and evidence.

SMB

Get your first report from a single FortiGate backup, with nothing installed.

Modules and roadmap

What is available today, and what is next?

Today

Firewall audit

FortiGate: policy, management plane, VPN, HA, UTM

FortiOS vulnerabilities

CVE.org + CISA KEV + EPSS

Firewall monitoring

Scheduled scans, config drift, score trend, email; full backup archive in early access

Network devices

Cisco, Aruba, UniFi, MikroTik and 20 vendor profiles

Roadmap

Compliance packs

KVKK, 5651, ISO 27001, PCI DSS gap report

5651 access log archive

Audits 5651 readiness; does not replace statutory retention

Security event monitoring

First slice: VPN session report

Rule cleanup and access analysis

Windows / Active Directory

Servers, hardware, storage

Mail and cloud

IoT and cameras

Pricing

Per site, per module

Licensing is per site; we do not count devices. You pay only for the modules you use.

Recommended

Firewall Bundle

  • Firewall Audit
  • Periodic Scanning and Change Tracking
  • Vulnerability and Lifecycle
$35/ site · month$40 separately

Firewall Audit

$19/ site · month

FortiGate config audit (121 rules), 0-100 score, vendor-specific fix instructions, file upload and manual data intake, audit of Denetta's own access

Add-on to Firewall Audit

Periodic Scanning and Change Tracking

+$12/ site · month

Scheduled scans, config change alerts, score trend; full backup archive in early access

Add-on to Firewall Audit

Vulnerability and Lifecycle

+$9/ site · month

FortiOS version ⇄ CVE.org, CISA KEV, EPSS

Network Device Audit

$15/ site · month

Switches and routers at the site, 20 vendor profiles; access points, printers, cameras and IoT free

  • Prices in USD, excluding VAT
  • An HA pair at one site counts as one firewall
  • 15% discount for annual prepayment
  • Contact us for MSP and reseller pricing

Coming soon

Compliance Packs5651 Access Log ArchiveSecurity Event MonitoringRule CleanupAccess and Segmentation AnalysisChange PlanningWindows / Active DirectoryServers, hardware, storageMail and cloud

Pricing to be announced. Contact us for early access.

Positioning

It does not replace your RMM; it sits on top of it

Keep your Zabbix, keep your NinjaOne. Let them stay on real-time monitoring; Denetta adds a layer of periodic deep audit, scoring and expert analysis on top.

Specifications

Denetta — technical specifications

Supported firewallFortiGate, FortiOS 7.2 / 7.4 / 7.6
Network devices20 vendor profiles (Cisco, Aruba, UniFi, MikroTik …)
CollectionRead-only REST API (GET only), collector (SNMP GET/WALK, SSH show), backup file
Connection directionCollector outbound 443 only; no inbound port
Collector.NET 8, Windows service / Linux systemd
Vulnerability dataCVE.org, CISA KEV, FIRST EPSS
CredentialsAES-256-GCM encrypted vault, least privilege
Multi-tenancyCompany → site → device; PostgreSQL row-level isolation
HostingIn Türkiye
ConsentSigned and stamped written consent; scope limited by signature
Audit engineDeterministic JSON rules; no artificial intelligence
NotificationsEmail (Microsoft 365); carries no config value, IP or policy name
Frequently asked questions

Denetta, in detail

Denetta is an IT infrastructure health and security audit platform developed by BilgiTek. It audits firewalls, network devices and other infrastructure layers with read-only access, produces concrete findings with expert rules and combines them into a single 0-100 Infrastructure Health Score.
No. It only reads: show/get/display commands, SNMP GET/WALK and read-only API calls. It writes to no device and makes no active exploit attempts. The fix commands it suggests are only displayed.
Every category starts at 100; findings deduct points by severity. The score is calculated so that it rises with every fix, and comes with a rule-by-rule breakdown. Categories you do not use do not lower the score.
Today: 126 rules for FortiGate, FortiOS vulnerability matching, and network devices with 20 vendor profiles. Windows/AD, servers/storage, mail and cloud are on the roadmap.
No. The collector only talks outbound, over HTTPS on 443. You can also start with a single FortiGate backup file, with nothing installed.
No scan starts without signed and stamped written consent, and the scope is limited by that signature. Data is hosted in Türkiye, credentials are encrypted with AES-256-GCM, and each company is isolated at row level. Email notifications are sent via Microsoft 365 and carry no config value, IP address or policy name.
No. It is an expert audit layer that sits on top of your existing tools.
Licensing is per site; we do not count devices. Firewall Audit is $19 per site per month; Periodic Scanning and Change Tracking adds $12 and Vulnerability and Lifecycle adds $9. All three together are $35 as the Firewall Bundle. Network Device Audit is $15. Prices are in USD, excluding VAT; annual prepayment gets a 15% discount.
The full config backup archive is in early access. The full backup your device produces itself is archived encrypted; version history and the diff between two versions are shown. Denetta never restores a backup to the device.
No. The audit engine is deterministic: the rules are explicit JSON files and the same configuration always gives the same result. Your data is never sent to any AI platform.
Denetta

Your first report is free.

Let us prepare a one-off audit report from a FortiGate backup; we do not connect to your device and change nothing.

A backup file contains passwords and keys: do not send it by email. Write to us and we will arrange a secure transfer and your declaration that you are authorised for the device.