One cross-domain score
Firewalls, network devices and vulnerabilities today; servers, storage, mail and cloud on the roadmap — all in a single 0-100 score. Categories you don’t use never lower your score.
IT infrastructure health & security audit
Denetta audits your infrastructure without writing to a single device: it starts today with firewalls and network devices and expands to servers, mail and cloud. Expert rule engines turn raw configuration into findings and a 0-100 Infrastructure Health Score.
Infrastructure Health Score
Sample view14 findings · 1 critical · 4 high
Categories you don’t use never lower your score.
140
expert audit rules
20
vendor profiles
443
outbound only — no inbound ports required
0
write commands sent to devices
RMM watches endpoints, NMS watches the network, CVE scanners watch vulnerabilities. Management has just one question: “How healthy is our infrastructure?”
Denetta answers it with concrete findings rather than charts:
Unrestricted management access open from the WAN
SNMP community 'public'
FortiOS version affected by an actively exploited vulnerability
We never ask you to open a port into your network. The collector only talks outbound, over 443.
Customer network
Collector
show · get · SNMP GET · API
No inbound ports opened
outbound 443
HTTPS · one way
Core
Denetta.
Expert rule sets · hosted in Türkiye
Score
Rule-by-rule breakdown
Scanning starts only with the customer’s signed and stamped written consent. Which sites and which IP blocks are scanned is limited by that signature.
The collector gathers data inside its own segment using show/get commands, SNMP GET and read-only APIs, then pushes it to the core over HTTPS.
Every category runs through its own expert rule set. Data that cannot be read is never counted as “passed”; it is reported as a “visibility gap”.
The composite score comes with a rule-by-rule breakdown. Remediation commands are shown in the device vendor’s syntax and are never executed.
Firewalls, network devices and vulnerabilities today; servers, storage, mail and cloud on the roadmap — all in a single 0-100 score. Categories you don’t use never lower your score.
Every score is justified rule by rule. Each finding names the exact record that triggered it: which policy, which interface, which account.
Vulnerabilities are prioritised by CISA KEV (actively exploited) and EPSS data, not by CVSS score alone.
The same check comes with a Cisco command on Cisco and a MikroTik command on MikroTik. Technicians never have to translate a command from another vendor’s syntax.
Scans run periodically; if an unannounced config change opens a new critical or high risk, you’re notified by email, and the email never contains config values. Early access: the full backup your device produces itself is archived encrypted (version history, diff between versions); we set up the one-time automation on your device together.
Company → site → device hierarchy, row-level isolation, role-based access and a read-only dashboard for your customers.
Denetta has no protection plane, and never will. We also check whether the account we audit with is truly read-only, and show the result in the report. The auditor’s access is audited too.
Only show / get / display commands, SNMP GET/WALK; never SET
No active exploit attempts; vulnerabilities are detected by version ⇄ CVE matching
Remediation text is only displayed, never sent to a device
Credentials held in an AES-256-GCM encrypted vault, with least privilege
We start broad and deepen with real device data from the field.
FortiGate: policy, management plane, VPN, HA, UTM (126 rules)
CVE.org + CISA KEV + EPSS matching
Scheduled scans, config drift, score trend, email alerts; full config backup archive in early access
Cisco, Aruba, UniFi, MikroTik and 20 vendor profiles
Gap report and evidence pack against KVKK, Law 5651, ISO 27001 and PCI DSS
Tamper-evident archive of FortiGate access logs; checks Law 5651 readiness, does not replace the legal retention obligation
FortiGate events; first slice is VPN sessions and connected-time reporting
Unused rules and objects, segment access matrix, change planning
FSMO, replication, patch compliance, BitLocker, Defender
Linux, iLO/iDRAC Redfish, RAID and SMART health
SPF/DKIM/DMARC, M365 Secure Score, Azure/AWS/GCP
Passive discovery, default credentials and CVE matching
Licensed per site; we don’t count devices. You pay only for the modules you use.
Recommended
$35/ site · month$40 separately
Firewall Audit + Scheduled Scans and Change Tracking + Vulnerability and Lifecycle. Full backup archive in early access.
$19/ site · month
FortiGate configuration audit (121 rules), 0-100 score, vendor-specific remediation text, file upload and on-demand pull, audit of Denetta’s own access.
Add-on to Firewall Audit
+$12/ site · month
Daily/weekly scheduled scans, alerts for unannounced config changes (email when a new critical/high risk opens), score trend. Early access: encrypted archive of the device’s own full backup.
Add-on to Firewall Audit
+$9/ site · month
FortiOS version matched against CVE.org, CISA KEV and EPSS; the fixed version on the same branch where one exists, otherwise a branch upgrade; no exploit attempts against the device.
$15/ site · month
The site’s switches and routers: read-only collection over SNMP/SSH, 20 vendor profiles. Access points, printers, cameras and IoT are free.
Pricing to be announced. Contact us for early access.
Keep your Zabbix and NinjaOne. Let them handle real-time monitoring; Denetta adds a layer of periodic deep audits, scoring and expert analysis on top.
Denetta. audit + score
periodic · deep audit · expert analysis
RMM / NMS / Zabbix
real-time monitoring
firewall · switch · server · mail
Denetta is an IT infrastructure health and security audit platform developed by BilgiTek. It audits firewalls, network devices and other infrastructure layers with read-only access, produces concrete findings with expert rules, and combines them into a single 0-100 Infrastructure Health Score.
No. It only reads: show/get/display commands, SNMP GET/WALK and read-only API calls. It never writes to a device and never attempts an active exploit. The remediation commands it suggests are only displayed.
Every category starts at 100, and findings deduct points by severity. The score is built to rise with every fix and comes with a rule-by-rule breakdown. Categories you don’t use never lower the score.
Today: 126 rules for FortiGate, FortiOS vulnerability matching, and network devices across 20 vendor profiles. Windows/AD, servers/storage, mail and cloud are on the roadmap.
No. The collector only talks outbound, over HTTPS on port 443. You can also start with a single FortiGate backup file, with nothing to install.
No scan that connects to your device starts without signed and stamped written consent, and the scope is limited by that signature. Data is hosted in Türkiye, credentials are encrypted with AES-256-GCM, and every company is isolated at row level. E-mail notifications are sent via Microsoft 365 and carry no configuration values, IP addresses or policy names.
No. It is an expert audit layer that sits on top of your existing tools.
Per site, per month; devices are not counted. Firewall Audit is $19, the Firewall Bundle (audit + scheduled scans + vulnerability matching) is $35, Network Device Audit is $15; prices are in USD, excluding VAT. Your first report is free.
Denetta does not take the backup by reading your device; your device sends the full backup it produces itself. The file is encrypted with AES-256-GCM. A new version is kept when the configuration changes, and at least weekly even if it doesn’t; each version is retained for 1 year after it was last seen on your device, or destroyed earlier on request. Denetta never restores a backup to your device. This feature is in early access.
We’ll prepare a one-time audit report from a FortiGate backup; we don’t connect to your device or change anything. Your backup contains passwords and keys, so please don’t email it. Get in touch and we’ll agree a secure transfer and confirm you’re authorised for the device.