Denetta modules
Denetta is licensed by module: each module audits one infrastructure area with its own expert rule set and enters the score as its own category. The modules available today are listed below; roadmap modules are neither sold nor priced until they are live and validated in the field.
Which modules are available today?
Firewall Audit
Expert-rule audit of FortiGate configuration: policy, management plane, VPN, HA, security profiles (121 rules).
FortiOS Vulnerability Matching
FortiOS version matched against CVE.org, CISA KEV and FIRST EPSS data; no exploit attempts.
Firewall Monitoring
Scheduled read-only scans, alerts on unannounced config changes and score trend; full backup archive in early access.
Network Device Audit
Read-only audit of switches and routers over SNMP/SSH; 19 vendor profiles, vendor-specific remediation text.
Domain and Email Security
Outside-in audit of SPF, DKIM, DMARC, MTA-STS, MX STARTTLS, web certificates, DNSSEC and domain registration.
Rule Cleanup
Unused rules and objects, shadowing, rule recertification workflow.
Microsoft 365 Tenant Audit
MFA enforcement, privileged roles, legacy authentication and external sharing, audited with read-only consent.
Compliance Packs
Gap report and evidence pack against KVKK, Law 5651, ISO 27001 and PCI DSS.
Access and Segmentation Analysis
Zone/segment access matrix and internet-exposed surface map.
Change Planning
Change request and approval workflow, verified on the next scan; nothing is sent to the device.
Law 5651 Access Log Archive
Tamper-evident archive of FortiGate access logs; does not replace the legal retention obligation.
Security Event Monitoring
FortiGate events; the first slice is VPN sessions and connected-time reporting.
Windows Server and Active Directory
FSMO, replication, DNS/DHCP consistency, patch compliance.
Servers, hardware and storage
Linux, iLO/iDRAC Redfish, RAID and SMART health.
Cloud
Azure, AWS and GCP audited through a read-only role.
IoT and cameras
Passive discovery, default-credential database matching and CVE matching.
How are modules licensed?
Firewall and network modules are licensed per site, domain and email security per company; devices are not counted. Checks from a module that is not licensed for a site do not count towards the score and appear as “not licensed” in the report — never as “passed”.
If a licence is switched off, open findings are neither deleted nor marked “resolved”; they return where they left off when the licence is switched back on.