Skip to content

How does Denetta work?

Denetta works in four steps: the scope is set by the customer’s signed and stamped consent, data is collected through read-only paths that never write to a device, every category runs through its own expert rule set, and the result is reported as a 0-100 Infrastructure Health Score justified rule by rule.

What is the audit flow, step by step?

  1. 01

    Consent and scope

    No scan in which the core connects to a device starts until the customer’s signed and stamped written consent is uploaded and approved by the MSP owner. The consent document freezes the sites, IP blocks, excluded addresses, device addresses and domains; if the scope grows, a new signature is required.

  2. 02

    Read-only collection

    FortiGate has three paths: backup file upload, read-only access to the device’s REST API (GET only), or a collector in the customer segment. Network devices are read over SNMP/SSH through the collector; domains are read from the outside using public DNS/TLS information.

  3. 03

    Expert audit

    Every category runs through its own rule set. Rules are data, not code; every finding names the record that triggered it (which policy, which interface, which account).

  4. 04

    Score, report and monitoring

    Category scores and the composite score come with a rule-by-rule breakdown. With the monitoring module, scans run on a schedule; if an unannounced change opens a new critical or high risk, an email is sent.

What is installed on the customer network, and which ports are opened?

No inbound port is opened. The collector is a single-file service written in .NET 8; it collects inside its own segment and pushes data outbound only, over HTTPS with mTLS on 443. Credentials are never written to the collector’s disk.

A FortiGate audit can also start without a collector: a backup file upload or the device’s read-only API is enough. Layer-2 data from network devices (ARP, MAC, LLDP) can only be collected from inside the segment, so it requires the collector.

What happens to data that cannot be read?

Denetta never counts the unknown as “passed”. Every check in a report appears in one of four distinct states:

  • Passed — the data was read and the check is satisfied.
  • Visibility gap — the required data could not be collected or could not be seen because access was not granted; it doesn’t lower the score but is listed explicitly in the report.
  • Out of scope — the check does not apply to this device (e.g. HA rules on a standalone unit).
  • Not licensed — the module is not enabled for this site or company; it does not count towards the score.

How is the score calculated?

Every category starts at 100; each finding adds a penalty by severity. Penalties are applied along a saturation curve rather than subtracted linearly, so a score never sticks at 0 and hides progress, and every fix raises it. A serious finding cannot hide behind clean categories.

The composite score is weighted only across discovered and licensed categories: a company without cloud never loses points for a category it doesn’t have. With no licensed category, the score shows as “none”, not 0.

Let’s walk through it in your environment.

In a meeting we can show a sample FortiGate audit and report from start to finish.