Skip to content

IT infrastructure health & security audit

How healthy is your infrastructure?One score, fully explained.

Denetta audits your infrastructure without writing to a single device: it starts today with firewalls and network devices and expands to servers, mail and cloud. Expert rule engines turn raw configuration into findings and a 0-100 Infrastructure Health Score.

  • Read-only, never writes
  • Device access requires signed consent
  • Hosted in Türkiye

Infrastructure Health Score

Sample view
67/100

14 findings · 1 critical · 4 high

  • Firewall58
  • Network devices81
  • Vulnerabilities64
  • Cloudout of scope

Categories you don’t use never lower your score.

140

expert audit rules

20

vendor profiles

443

outbound only — no inbound ports required

0

write commands sent to devices

Findings, not metrics.

RMM watches endpoints, NMS watches the network, CVE scanners watch vulnerabilities. Management has just one question: “How healthy is our infrastructure?”

Denetta answers it with concrete findings rather than charts:

  • Critical

    Unrestricted management access open from the WAN

    Firewall · management plane

  • High

    SNMP community 'public'

    Network devices

  • Critical

    FortiOS version affected by an actively exploited vulnerability

    Vulnerabilities · CISA KEV

How it works

We never ask you to open a port into your network. The collector only talks outbound, over 443.

Customer network

Collector

show · get · SNMP GET · API

No inbound ports opened

Core

Denetta.

Expert rule sets · hosted in Türkiye

67

Score

Rule-by-rule breakdown

  1. 01

    Consent and scope

    Scanning starts only with the customer’s signed and stamped written consent. Which sites and which IP blocks are scanned is limited by that signature.

  2. 02

    Read-only collection

    The collector gathers data inside its own segment using show/get commands, SNMP GET and read-only APIs, then pushes it to the core over HTTPS.

  3. 03

    Expert audit

    Every category runs through its own expert rule set. Data that cannot be read is never counted as “passed”; it is reported as a “visibility gap”.

  4. 04

    Score and remediation

    The composite score comes with a rule-by-rule breakdown. Remediation commands are shown in the device vendor’s syntax and are never executed.

Why Denetta

0–100

One cross-domain score

Firewalls, network devices and vulnerabilities today; servers, storage, mail and cloud on the roadmap — all in a single 0-100 score. Categories you don’t use never lower your score.

why 72?

An answer to “Why 72?”

Every score is justified rule by rule. Each finding names the exact record that triggered it: which policy, which interface, which account.

CVSS · KEV · EPSS

CVE priority by real-world risk

Vulnerabilities are prioritised by CISA KEV (actively exploited) and EPSS data, not by CVSS score alone.

Cisco · MikroTik

Vendor-specific remediation

The same check comes with a Cisco command on Cisco and a MikroTik command on MikroTik. Technicians never have to translate a command from another vendor’s syntax.

config drift · backup

Change tracking and full backup

Scans run periodically; if an unannounced config change opens a new critical or high risk, you’re notified by email, and the email never contains config values. Early access: the full backup your device produces itself is archived encrypted (version history, diff between versions); we set up the one-time automation on your device together.

company → site → device

Multi-tenant for MSPs

Company → site → device hierarchy, row-level isolation, role-based access and a read-only dashboard for your customers.

Never writes to a device.This isn’t a feature; it’s the product’s identity.

Denetta has no protection plane, and never will. We also check whether the account we audit with is truly read-only, and show the result in the report. The auditor’s access is audited too.

  • 01

    Only show / get / display commands, SNMP GET/WALK; never SET

  • 02

    No active exploit attempts; vulnerabilities are detected by version ⇄ CVE matching

  • 03

    Remediation text is only displayed, never sent to a device

  • 04

    Credentials held in an AES-256-GCM encrypted vault, with least privilege

Coverage and modules

We start broad and deepen with real device data from the field.

Available today
  • Firewall audit

    FortiGate: policy, management plane, VPN, HA, UTM (126 rules)

  • FortiOS vulnerabilities

    CVE.org + CISA KEV + EPSS matching

  • Firewall monitoring and backup

    Scheduled scans, config drift, score trend, email alerts; full config backup archive in early access

  • Network devices

    Cisco, Aruba, UniFi, MikroTik and 20 vendor profiles

  • Compliance packs

    Gap report and evidence pack against KVKK, Law 5651, ISO 27001 and PCI DSS

  • Law 5651 access log archive

    Tamper-evident archive of FortiGate access logs; checks Law 5651 readiness, does not replace the legal retention obligation

  • Security event monitoring

    FortiGate events; first slice is VPN sessions and connected-time reporting

  • Rule cleanup and access analysis

    Unused rules and objects, segment access matrix, change planning

  • Windows / Active Directory

    FSMO, replication, patch compliance, BitLocker, Defender

  • Servers, hardware, storage

    Linux, iLO/iDRAC Redfish, RAID and SMART health

  • Mail and cloud

    SPF/DKIM/DMARC, M365 Secure Score, Azure/AWS/GCP

  • IoT and cameras

    Passive discovery, default credentials and CVE matching

Pricing

Licensed per site; we don’t count devices. You pay only for the modules you use.

Recommended

Firewall Bundle

$35/ site · month$40 separately

Firewall Audit + Scheduled Scans and Change Tracking + Vulnerability and Lifecycle. Full backup archive in early access.

Firewall Audit

$19/ site · month

FortiGate configuration audit (121 rules), 0-100 score, vendor-specific remediation text, file upload and on-demand pull, audit of Denetta’s own access.

Add-on to Firewall Audit

Scheduled Scans and Change Tracking

+$12/ site · month

Daily/weekly scheduled scans, alerts for unannounced config changes (email when a new critical/high risk opens), score trend. Early access: encrypted archive of the device’s own full backup.

Add-on to Firewall Audit

Vulnerability and Lifecycle

+$9/ site · month

FortiOS version matched against CVE.org, CISA KEV and EPSS; the fixed version on the same branch where one exists, otherwise a branch upgrade; no exploit attempts against the device.

Network Device Audit

$15/ site · month

The site’s switches and routers: read-only collection over SNMP/SSH, 20 vendor profiles. Access points, printers, cameras and IoT are free.

  • Prices are in USD, excluding VAT.
  • An HA pair at one site counts as a single firewall.
  • 15% off with annual prepayment.
  • Contact us for MSP and reseller pricing.

Pricing to be announced. Contact us for early access.

  • Compliance Packs
  • Law 5651 Access Log Archive
  • Security Event Monitoring
  • Rule Cleanup
  • Access and Segmentation Analysis
  • Change Planning
  • Windows / Active Directory
  • Servers, hardware, storage
  • Mail and cloud

It doesn’t replace your RMM. It sits on top of it.

Keep your Zabbix and NinjaOne. Let them handle real-time monitoring; Denetta adds a layer of periodic deep audits, scoring and expert analysis on top.

Denetta. audit + score

periodic · deep audit · expert analysis

RMM / NMS / Zabbix

real-time monitoring

firewall · switch · server · mail

Frequently asked questions

What is Denetta?

Denetta is an IT infrastructure health and security audit platform developed by BilgiTek. It audits firewalls, network devices and other infrastructure layers with read-only access, produces concrete findings with expert rules, and combines them into a single 0-100 Infrastructure Health Score.

Does Denetta make changes to my devices?

No. It only reads: show/get/display commands, SNMP GET/WALK and read-only API calls. It never writes to a device and never attempts an active exploit. The remediation commands it suggests are only displayed.

How is the Infrastructure Health Score calculated?

Every category starts at 100, and findings deduct points by severity. The score is built to rise with every fix and comes with a rule-by-rule breakdown. Categories you don’t use never lower the score.

Which devices are supported?

Today: 126 rules for FortiGate, FortiOS vulnerability matching, and network devices across 20 vendor profiles. Windows/AD, servers/storage, mail and cloud are on the roadmap.

Do I need to open ports on the customer network?

No. The collector only talks outbound, over HTTPS on port 443. You can also start with a single FortiGate backup file, with nothing to install.

How do you handle KVKK (Türkiye’s data protection law) and data security?

No scan that connects to your device starts without signed and stamped written consent, and the scope is limited by that signature. Data is hosted in Türkiye, credentials are encrypted with AES-256-GCM, and every company is isolated at row level. E-mail notifications are sent via Microsoft 365 and carry no configuration values, IP addresses or policy names.

Does Denetta replace my RMM or Zabbix?

No. It is an expert audit layer that sits on top of your existing tools.

How is Denetta priced?

Per site, per month; devices are not counted. Firewall Audit is $19, the Firewall Bundle (audit + scheduled scans + vulnerability matching) is $35, Network Device Audit is $15; prices are in USD, excluding VAT. Your first report is free.

How is my config backup stored?

Denetta does not take the backup by reading your device; your device sends the full backup it produces itself. The file is encrypted with AES-256-GCM. A new version is kept when the configuration changes, and at least weekly even if it doesn’t; each version is retained for 1 year after it was last seen on your device, or destroyed earlier on request. Denetta never restores a backup to your device. This feature is in early access.

Your first report is free.

We’ll prepare a one-time audit report from a FortiGate backup; we don’t connect to your device or change anything. Your backup contains passwords and keys, so please don’t email it. Get in touch and we’ll agree a secure transfer and confirm you’re authorised for the device.

Request your free report