Rakasec reads the running-config of every switch, router and firewall you own — sixteen platforms — and tells you what an auditor would: which control fails, on which line, on which device, and what happens if nobody fixes it. Then it can fix it, prove the fix took, and roll back if it didn't. And because it can see every segment, it measures your zero-trust readiness instead of asking about it.
Audits configuration across sixteen enterprise network platforms — and cloud / SASE posture
Two things no spreadsheet audit does: Rakasec rebuilds each device's routing and policy from its config and measures which segments can reach which; and when you approve a fix, it pushes it, re-pulls the config, and only marks it fixed if the finding is actually gone.
Management plane open to any source. The engine's diff becomes exact commands; the rollback is derived, not guessed.
Simulated and re-audited offline before anyone approves.
The approver cannot be the requester. Dry run shows exactly what will be sent.
Pinned host key. Output kept on the request.
Finding gone → verified. Still there → rollback sent, request says so.
Every zero-trust "assessment" on the market asks your engineers what the policy is and grades the answer. Rakasec reads the configs, measures which segments can reach which, scores 31 capabilities across the CISA ZTMM 2.0 pillars on fleet coverage, and tells you the exact gap, the exact device, and the exact lines that close it. Below is the engine's own output for a 15-device, 15-platform sample fleet — before and after hardening.
Most config reviews are a spreadsheet and a long weekend. Rakasec makes them continuous, evidence-backed, and repeatable.
Re-audit on every change and get real-time visibility into where the fleet drifts out of policy — before an auditor finds it.
Every finding cites the exact offending lines and the control it violates. Deterministic — the same config always yields the same result.
Sentinel drafts the fix per platform with rollback, clusters related findings by root cause, and briefs leadership in plain English.
Rakasec maps every finding to the attack it enables and the control it breaks — the management plane, weak crypto, broken access control, routing integrity, segmentation, and known-CVE exposure.
Management reachable from 0.0.0.0/0, cleartext admin protocols, default credentials — the fastest path to full device takeover, and the first thing an attacker scans for.
SNMP v1/v2c communities, default "public/private", weak SSH ciphers & key exchange, no SNMPv3 auth+priv.
Local-only accounts, no centralized AAA/TACACS+, missing least-privilege and VTY access-class ACLs.
Unauthenticated OSPF/BGP adjacencies, missing control-plane policing (CoPP), IP source-routing enabled.
any/any/allow rules, permissive zones, and allow policies with no threat-prevention or SSL inspection.
Running releases correlated to known CVEs and the CISA KEV catalog, plus end-of-life images a config scan alone misses.
No remote syslog/NetFlow export and no NTP source — the blind spots that make an incident impossible to reconstruct.
Zscaler, AWS, Azure, Meraki and Strata — open security groups, missing MFA, permissive policy — in the same report.
Access ports with no 802.1X, or NAC failing open in monitor mode — Rakasec proposes the zero-trust design: deny-by-default, per-identity VLAN/dACL/SGT, RADIUS CoA, east-west microsegmentation.
MPLS VRFs without route-targets (cross-VPN leak), PIM with no RP, and ACL / route-map / prefix-list hygiene — permit-any and accept-all filters that break segmentation.
APIC posture and any/permit-all contracts between EPGs — over-broad east-west policy that turns the fabric into a flat network.
Rakasec reads your configs and reasons about them: it triages incidents, advises on designs, guards changes, and onboards devices — every answer grounded in the real config, so it's a true positive, not a guess.
Pull an incident from ServiceNow (or paste the symptoms) and Rakasec triages it against the device — likely causes, what to check, and the exact verification show-commands. Path-aware: it narrows "latency between rtr1 and rtr2" to the suspect hop.
Talk through a change — "route between me and my ISP", "segment PCI traffic", "set up MPLS VRFs" — and get design options tailored to the platform, with sample config and best practices.
Before a change lands: blast-radius impact, a pre-flight "will this even apply?" check, ITSM validation, and alerts auto-muted for the device and its neighbours. Before/after diff surfaces only what the change actually broke.
Onboard by vendor or auto-discovery. Test connection, pull the config, and get a first assessment — detected version and prioritized findings — in one guided flow. Credentials live in an encrypted vault, never typed inline.
Rakasec reasons about how the network actually behaves — reachability, drift, your own policy — well past pattern-matching for insecure keywords.
Trace a flow hop-by-hop across the firewalls on its path — is it reachable, where is it blocked, and the exact rule to change. Deterministic, no packets sent.
Snapshot every device and report the finding delta since last sweep — catch the risky change the moment it lands, not at the next audit.
Describe a rule in plain English and Rakasec writes the regex or Lua. Or point it at a device — it reads your BGP/OSPF neighbours, ACLs, MPLS and NAC config and proposes the exact tests, each grounded in a real line.
Before a change lands, the AI agent reads the rollout config, learns the affected neighbours and rates the blast radius. It validates your ITSM change number, mutes alerts for the device and its neighbours, and diffs the config before vs after — so only what the change actually broke ever pages you.
Correlates each device's platform and release to known CVEs, surfacing exploitable exposure a keyword-based config scan alone will always miss.
Findings are ranked by reach and role, not just severity — a critical on an internet-facing edge firewall outranks the same on an isolated lab switch.
Runs entirely on-prem inside your management VRF — bundled weights, no egress, no phone-home. FedRAMP-aligned for sovereign environments.
Legacy tools were built to archive configs and diff them. Rakasec is built to prove the network is secure — evidence-first, AI-native, and aware of the cloud your traffic actually crosses.
Backup-era, on-box scripting
Evidence-first, AI-native, cloud-aware
Rakasec re-evaluates every new finding and confirms it's a genuine true positive before it pages anyone. And during a maintenance window, alerts for the device under change — and its neighbours — are muted automatically, so planned work never pages on-call. Verified findings route straight into the tools you already run.
False positives and accepted-risk suppressions are filtered out before routing — no noise, no alert fatigue, an on-call queue you can trust.
Everything an operations team needs to run Rakasec in production: access control, identity, reporting, team dashboards, and lifecycle management — on-prem, air-gap ready.
Admin / Read-Write / Read-Only roles, per-user scoping, and directory group→role mapping. Authenticate with SAML, OIDC, TACACS+ or RADIUS — each with a built-in test-connection.
Executive summary, full compliance, version-impact KPI and audit trail out of the box — or build your own by section and severity. Export PDF / CSV / JSON, or email to stakeholders.
Per-user, drag-to-arrange widgets with role-based views — NOC, Engineering and Management — switchable from a dropdown so every team sees the signal that matters to them.
Device credentials live in a passphrase-locked, in-memory vault — devices reference them by name, never inline. Nothing sensitive is written to disk or persisted in the browser.
Backup-before-upgrade with release notes, NTP, and encrypted backup to S3 / SFTP / NFS / Azure / GCS — each with test-connection. Export appliance telemetry to SolarWinds, PRTG or Prometheus, read-only.
Rate-limited, off-hours-aware config collection that never overloads a device or its control plane — with an immutable audit trail of who changed what, exportable for compliance.
Hand the report to your auditors as-is. Four framework packs are scored from findings — and each says exactly which controls it covers, because a config cannot decide a procedural control.
From a one-time assessment to always-on, air-gapped deployment. Tell us about your network and we'll scope it with you.
Send us your configs — we return a full, auditor-ready report with prioritized remediation. Nothing to deploy.
Scheduled re-audit, drift alerting and change-window intelligence across the whole fleet.
Air-gapped appliance inside your management VRF — no egress, no phone-home, FedRAMP-aligned.
Today a network security programme buys a config-compliance suite, a policy manager for the firewalls, a digital-twin for path analysis, a consultant for the zero-trust assessment and a spreadsheet to tie it together. Rakasec does the parts of each that can be decided from configuration — offline, on one appliance — and says plainly where the incumbents are still ahead.
| Capability | Rakasec | Config compliance suites | Firewall policy managers | Digital-twin / path tools | ZT assessment (consultant / questionnaire) |
|---|---|---|---|---|---|
| Assess | |||||
| Hardening findings cited to the line, published false-positive rate | ✓ 150 checks · 0% FP on a ground-truth corpus* | partialrule hits; FP rate not published | ✗ | ✗ | manual |
| Multi-vendor, offline, agentless — no device access needed | ✓ 16 platforms + cloud/SASE posture | ✓far more device types | firewalls only | needs live access / snapshots | ✓ |
| Fleet CVE exposure from CISA KEV, NVD and vendor PSIRTs, paged when new | ✓ 30-min refresh · KEV always pages | some | ✗ | some | ✗ |
| Zero trust | |||||
| Lateral reachability measured per segment pair, from configs | ✓ undetermined never called safe | ✗ | per-firewallnot across the campus | ✓their strength; needs a twin | ✗self-reported |
| Zero-trust readiness scored on fleet coverage against CISA ZTMM 2.0 / NIST 800-207 | ✓ 31 capabilities · two domains · roadmap | ✗ | ✗ | ✗ | surveyopinion, not measurement |
| One ranked risk register: gaps + exposures + permissive rules + hygiene + findings | ✓ | findings only | rules only | paths only | slide deck |
| Baseline compare — what moved since last quarter, and why | ✓ | config diff | rule diff | ✓ | ✗ |
| Remediate | |||||
| Push with pre-flight simulation, four-eyes, post-push re-audit and automatic rollback | ✓ never marks fixed on trust | push, no verify | rule pushfirewalls only | ✗ | ✗ |
| Exact commands and rollback derived from the finding's evidence | ✓ push on 11 platforms; manual runbook on the rest | templates | ✓ | ✗ | ✗ |
| Operate | |||||
| Scheduled collection at fleet scale, classified failures, pinned host keys | ✓ auth never retried · TOFU pinning | ✓mature | firewalls | agents / API | ✗ |
| Alerting to PagerDuty / Opsgenie / Slack / Teams / ServiceNow / syslog with dedupe | ✓ | ✓ | ✓ | ✓ | ✗ |
| RBAC, SSO (OIDC/SAML), HA on PostgreSQL, audit trail of every action | ✓ SSO not yet validated against a customer IdP | ✓ | ✓ | ✓ | — |
| Hundreds of device types, decades of field validation | ✗ 16 platforms; validate yours in the ledger | ✓their home ground | firewalls | ✓ | — |
| Prove | |||||
| CIS · NIST 800-53 · PCI DSS · STIG packs scored from findings, honest about coverage | ✓ says exactly which controls it covers | ✓strongest suit | firewall rules | ✗ | self-attested |
| AI that explains — grounded to engine facts, every sentence cited | ✓ engine decides, model narrates | emerging | emerging | emerging | ✗ |
| Air-gapped by default, no LLM in the audit path, configs deleted after delivery | ✓ | varies | varies | ✗mostly SaaS | ✓ |
Tell us about your network and we'll scope an assessment with you. Start with a free audit of five devices — no cost, no obligation.