Skip to content

Security: read-only by design

Denetta’s security model fits in one sentence: it never writes to a target device, under any circumstances. Only read commands, SNMP GET/WALK and read-only API scopes are used; no active exploit is attempted; remediation text is only displayed. This is not a phase limitation but the product’s identity, and it is checked automatically on every code change.

What is never done?

  • Writing to a device or changing its configuration: SNMP SET, config-mode commands, PowerShell Set-*/New-*/Remove-*, Redfish PATCH/POST/DELETE.
  • Active exploit attempts: vulnerabilities are detected by version ⇄ CVE matching only, default credentials by database comparison only; credentials are never tried.
  • Applying fixes: commands are shown on screen and in the report, never executed.
  • Scanning without consent: every scan in which the core connects to a device requires signed and stamped written consent and an approved scope.

How is this proven?

Every code change passes an automated read-only gate that looks for any code path able to write to a device; a change that could produce a write command cannot be merged. The forbidden command patterns in vendor profiles are tested in the same gate for both validity and behaviour.

The FortiGate REST API is used with GET only. The endpoint that returns the configuration as a single file is a POST request, so it is deliberately not used; staying without exceptions is what makes the guarantee auditable.

How is the audit account’s access restricted?

Denetta has you create a least-privilege, read-only account and shows as a finding in your own report whether that account is restricted by source IP and whether its access profile is truly read-only. The source of that check is the device’s configuration, not our statement.

How are credentials and tenant data protected?

  • Credentials are held in an AES-256-GCM encrypted vault and cannot be read back through any endpoint.
  • Every company is isolated in PostgreSQL with row-level security (RLS); privilege escalation is locked at database level.
  • The collector talks outbound only, over mTLS on 443, and leases credentials only for devices in its own segment, for a short time.
  • The sign-in endpoint is rate-limited against brute force; accounts are disabled, never deleted — the answer to “who accepted this risk” is preserved.