Live engine · 150 deterministic checks · 0 network connections
Network security assurance · zero-trust readiness

Every config, every vendor,
measuredcited to the linefixed and verifieddefensible in audit.

Rakasec reads the running-config of every switch, router and firewall you own — sixteen platforms — and tells you what an auditor would: which control fails, on which line, on which device, and what happens if nobody fixes it. Then it can fix it, prove the fix took, and roll back if it didn't. And because it can see every segment, it measures your zero-trust readiness instead of asking about it.

Air-gapped & agentless Zero trust: 31 capabilities · measured reachability Evidence-cited, zero false positives*
rakasec · edge-01 · Cisco IOS-XE 17.9
CGT-CHK-008 mgmt open to Internet · CIS 2.3.2 · NIST AC-17(1) · PCI 1.3.1CGT-CHK-010 default SNMP · PCI 2.2.2CGT-CHK-P05 any/any rule · NIST SC-7(5)KEV exploited CVEs on your fleet
0
Deterministic checks
0
Vendor platforms + cloud
0%
False positives*
0
Zero-trust capabilities scored

Audits configuration across sixteen enterprise network platforms — and cloud / SASE posture

Cisco IOS-XECisco NX-OSCisco IOS-XRCisco ASA Juniper JunosArista EOSPalo Alto PAN-OSFortinet FortiOS Aruba AOS-CXHuawei VRPHPE ComwareMikroTik RouterOS Check Point GaiaSonicWall SonicOSExtreme EXOSUbiquiti EdgeOS ZscalerMerakiAWSAzureCisco ACICatalyst Center
Watch it work

Measured, not surveyed. Fixed, then proven.

Two things no spreadsheet audit does: Rakasec rebuilds each device's routing and policy from its config and measures which segments can reach which; and when you approve a fix, it pushes it, re-pulls the config, and only marks it fixed if the finding is actually gone.

Lateral reachability — measured from configs

Staff
Guest
Servers
Mgmt
Staff →
·
445
443
22
Guest →
445
·
3389
22
Servers →
445
any
·
22
Mgmt →
22
any
22
·
reachable on a lateral-movement portblocked by a rule the engine can cite
12 of 12 segment pairs reachable · lateral index 100 · risk index 100. Every red cell names the interface, the missing ACL, and the line to add.

Remediation push — verified, or rolled back

change #2 · edge-01
1

Stage from the finding

Management plane open to any source. The engine's diff becomes exact commands; the rollback is derived, not guessed.

ip access-list standard MGMT-ONLY
permit 10.9.99.0 0.0.0.255
ip http access-class ipv4 MGMT-ONLY
line vty 0 4 / access-class MGMT-ONLY in
2

Pre-flight on the stored config

Simulated and re-audited offline before anyone approves.

closes CGT-CHK-008 and CGT-CHK-005 · no new findings · 26 → 24
3

Four-eyes approval

The approver cannot be the requester. Dry run shows exactly what will be sent.

4

Push over SSH, save

Pinned host key. Output kept on the request.

sent 5 lines in 0.6s · write memory [OK]
5

Re-pull, re-audit

Finding gone → verified. Still there → rollback sent, request says so.

verify: re-pulled — management plane closed to any source
Zero trust readiness

A zero-trust score you can measure, not one you answered.

Every zero-trust "assessment" on the market asks your engineers what the policy is and grades the answer. Rakasec reads the configs, measures which segments can reach which, scores 31 capabilities across the CISA ZTMM 2.0 pillars on fleet coverage, and tells you the exact gap, the exact device, and the exact lines that close it. Below is the engine's own output for a 15-device, 15-platform sample fleet — before and after hardening.

Readiness — CISA ZTMM 2.0 pillars

4
readiness · Traditional
183risks in the register
30critical
51lateral index
Identity
Devices
Networks
Applications
Visibility & Analytics
Data · Automation · Governanceneeds inputs the config cannot show — named, not guessed
Worst in Networks: Guest segments reach Management segments on lateral-movement ports. Worst in Identity: root authentication uses a plaintext password. The verdict the engine writes: "30 critical risks outrank the maturity score — close them before any capability work."

What the score is made of

each traces to a line
31 capabilities, two domains. Campus segmentation (802.1X, MAB, CoA, dynamic ACLs, DHCP snooping, east-west filtering, default-deny…) and ZTNA (per-app access, MFA at the edge, split-tunnel, identity-based policy). Each is scored on fleet coverage — one switch running 802.1X in a campus of forty is a pilot, not "Initial".
Measured lateral reachability. Routing and policy are rebuilt from each config; every segment pair is asked whether SMB, RDP, SSH get through. Undetermined is reported as undetermined — a Check Point gateway whose rulebase lives on the management server is never scored as safe.
One risk register. Capability gaps, measured exposures, permissive rules, rulebase hygiene, hardening findings and missing inputs in one list, ranked, with the roadmap order the engine derives from dependencies (RADIUS before 802.1X before CoA).
Baseline compare. Every fleet assessment is saved; the next one says what moved and why — the number a segmentation programme is judged on.
Honest by construction. Identity-provider policy, NAC authorisation profiles and flow data are named required inputs, not assumed. Data, Automation and Governance pillars stay unscored until you supply them.
Explained, not decided, by AI. The narrative for the board cites the engine's fact ids for every sentence; the model cannot add a device, a number or a severity.
How it works

From running-config to a signed-off control, without a questionnaire.

01

Collect

02

Audit

03

Measure

04

Remediate

05

Prove

    Why Rakasec

    Compliance you can defend in an audit.

    Most config reviews are a spreadsheet and a long weekend. Rakasec makes them continuous, evidence-backed, and repeatable.

    Continuous compliance

    Re-audit on every change and get real-time visibility into where the fleet drifts out of policy — before an auditor finds it.

    Evidence, not opinions

    Every finding cites the exact offending lines and the control it violates. Deterministic — the same config always yields the same result.

    AI-assisted remediation

    Sentinel drafts the fix per platform with rollback, clusters related findings by root cause, and briefs leadership in plain English.

    The engine

    Deterministic audit, zero network access

    • You send configs — plain-text exports, one file per device or a whole folder. No credentials, ever.
    • 150 deterministic checks run across the management plane, AAA, crypto, SNMP, routing integrity, logging and software lifecycle.
    • Known-CVE & end-of-life flagging surfaces devices running unsupported code.
    Devices assessed17
    Checks executed150 / device
    Critical findings2
    End-of-life images3
    Network connections made0
    Sentinel AI

    An analyst layer that explains, never decides

    • Executive briefing — a leadership-ready summary of posture and top risks.
    • Ask questions in plain English about your own results.
    • Root-cause clustering groups related findings so systemic issues are fixed once.
    Which devices can be managed from the Internet?
    Two: fw-edge-01 and core-tlv. Both violate CIS 1.2.1 (critical). Want the remediation diff for each?
    Summarize posture for the CISO.
    Fleet at 84/100, up 4 this week. Risk concentrates at the edge — 2 criticals, both insecure management access. Fixing them raises posture to ~90.
    Software verification

    Verify every device runs safe, supported software

    • Baseline check — each running release is verified against a maintained baseline: recommended, minimum-safe, and end-of-life.
    • CVE correlation — versions are matched to known vulnerabilities, so you see exploitable exposure, not just "out of date."
    • Exact upgrade path — the target release per platform, and why, ready for your maintenance window.
    DeviceRunningStatusTarget
    core-iad-01IOS-XE 17.9.3Below-min17.12.4
    leaf-pdx-07NX-OS 9.3(2)End-of-life10.3(4a)
    fw-fra-01PAN-OS 11.1.3Recommended
    Threat coverage

    The misconfigurations attackers actually exploit.

    Rakasec maps every finding to the attack it enables and the control it breaks — the management plane, weak crypto, broken access control, routing integrity, segmentation, and known-CVE exposure.

    Exposed management plane

    Management reachable from 0.0.0.0/0, cleartext admin protocols, default credentials — the fastest path to full device takeover, and the first thing an attacker scans for.

    CIS 1.2NIST AC-17DISA STIG

    Weak & legacy cryptography

    SNMP v1/v2c communities, default "public/private", weak SSH ciphers & key exchange, no SNMPv3 auth+priv.

    PCI 2.2.2NIST SC-8CIS 2.8

    Broken access control

    Local-only accounts, no centralized AAA/TACACS+, missing least-privilege and VTY access-class ACLs.

    NIST AC-2NIST AC-6CIS 1.3

    Routing & control-plane integrity

    Unauthenticated OSPF/BGP adjacencies, missing control-plane policing (CoPP), IP source-routing enabled.

    NIST SC-5NIST SC-8

    Firewall segmentation gaps

    any/any/allow rules, permissive zones, and allow policies with no threat-prevention or SSL inspection.

    NIST SC-7PCI 1.2

    Known-CVE & end-of-life exposure

    Running releases correlated to known CVEs and the CISA KEV catalog, plus end-of-life images a config scan alone misses.

    NIST RA-5CISA KEV

    Logging & visibility gaps

    No remote syslog/NetFlow export and no NTP source — the blind spots that make an incident impossible to reconstruct.

    NIST AU-6NIST AU-8

    Cloud & SASE posture

    Zscaler, AWS, Azure, Meraki and Strata — open security groups, missing MFA, permissive policy — in the same report.

    CIS CloudNIST AC-3

    NAC & zero-trust readiness

    Access ports with no 802.1X, or NAC failing open in monitor mode — Rakasec proposes the zero-trust design: deny-by-default, per-identity VLAN/dACL/SGT, RADIUS CoA, east-west microsegmentation.

    NIST AC-4Zero TrustCMMC

    MPLS, multicast & route policy

    MPLS VRFs without route-targets (cross-VPN leak), PIM with no RP, and ACL / route-map / prefix-list hygiene — permit-any and accept-all filters that break segmentation.

    NIST SC-7SC-8

    Cisco ACI fabric & contracts

    APIC posture and any/permit-all contracts between EPGs — over-broad east-west policy that turns the fabric into a flat network.

    NIST SC-7ACI
    AI network-operations copilot

    Not just an auditor — a copilot for your network team.

    Rakasec reads your configs and reasons about them: it triages incidents, advises on designs, guards changes, and onboards devices — every answer grounded in the real config, so it's a true positive, not a guess.

    AI incident resolution

    Pull an incident from ServiceNow (or paste the symptoms) and Rakasec triages it against the device — likely causes, what to check, and the exact verification show-commands. Path-aware: it narrows "latency between rtr1 and rtr2" to the suspect hop.

    Design advisor

    Talk through a change — "route between me and my ISP", "segment PCI traffic", "set up MPLS VRFs" — and get design options tailored to the platform, with sample config and best practices.

    Change-window intelligence

    Before a change lands: blast-radius impact, a pre-flight "will this even apply?" check, ITSM validation, and alerts auto-muted for the device and its neighbours. Before/after diff surfaces only what the change actually broke.

    Zero-touch onboarding

    Onboard by vendor or auto-discovery. Test connection, pull the config, and get a first assessment — detected version and prioritized findings — in one guided flow. Credentials live in an encrypted vault, never typed inline.

    Beyond the checklist

    Advanced analysis, not just a config linter.

    Rakasec reasons about how the network actually behaves — reachability, drift, your own policy — well past pattern-matching for insecure keywords.

    Firewall path analysis

    Trace a flow hop-by-hop across the firewalls on its path — is it reachable, where is it blocked, and the exact rule to change. Deterministic, no packets sent.

    Configuration drift detection

    Snapshot every device and report the finding delta since last sweep — catch the risky change the moment it lands, not at the next audit.

    AI config review & golden-policy

    Describe a rule in plain English and Rakasec writes the regex or Lua. Or point it at a device — it reads your BGP/OSPF neighbours, ACLs, MPLS and NAC config and proposes the exact tests, each grounded in a real line.

    Change-window intelligence

    Before a change lands, the AI agent reads the rollout config, learns the affected neighbours and rates the blast radius. It validates your ITSM change number, mutes alerts for the device and its neighbours, and diffs the config before vs after — so only what the change actually broke ever pages you.

    CVE exposure mapping

    Correlates each device's platform and release to known CVEs, surfacing exploitable exposure a keyword-based config scan alone will always miss.

    Blast-radius scoring

    Findings are ranked by reach and role, not just severity — a critical on an internet-facing edge firewall outranks the same on an isolated lab switch.

    Air-gapped deployment

    Runs entirely on-prem inside your management VRF — bundled weights, no egress, no phone-home. FedRAMP-aligned for sovereign environments.

    Built for this decade

    Not another config-backup box with compliance bolted on.

    Legacy tools were built to archive configs and diff them. Rakasec is built to prove the network is secure — evidence-first, AI-native, and aware of the cloud your traffic actually crosses.

    Legacy config tools

    Backup-era, on-box scripting

    • Hand-write every compliance rule in regex or Lua
    • Keyword pattern-matching — false positives you can't defend
    • No CVE / end-of-life correlation
    • Device configs only — blind to Zscaler, AWS, Azure, Meraki
    • Backup-first; the audit is an afterthought

    Rakasec

    Evidence-first, AI-native, cloud-aware

    • Describe a check in plain English — Rakasec writes the rule (regex or Lua) for you
    • Deterministic, line-cited findings — 0% false positives on our validation suite
    • CVE + end-of-life + blast-radius scoring, not just keyword hits
    • Cloud & SASE posture — Zscaler, AWS, Azure, Meraki, ACI, Strata in the same report
    • Audit-first, air-gap ready, mapped to the frameworks your auditor already uses
    Alerting & workflow

    Only verified true positives reach your on-call.

    Rakasec re-evaluates every new finding and confirms it's a genuine true positive before it pages anyone. And during a maintenance window, alerts for the device under change — and its neighbours — are muted automatically, so planned work never pages on-call. Verified findings route straight into the tools you already run.

    1 New finding detected on a sweep
    2 Auto re-check & verify — confirm it's a true positive
    Verified → alert fires with evidence, control & remediation

    False positives and accepted-risk suppressions are filtered out before routing — no noise, no alert fatigue, an on-call queue you can trust.

    Routes verified findings to
    ServiceNowPagerDutyOpsgenie Grafana OnCallSlackMicrosoft Teams JiraEmail / SMTPWebhook
    Alert precisionverified true-positive only
    Payloadfinding + evidence + control + fix
    Severity routingcritical → page · else → ticket
    Operations & platform

    Enterprise-ready from day one — not just an engine.

    Everything an operations team needs to run Rakasec in production: access control, identity, reporting, team dashboards, and lifecycle management — on-prem, air-gap ready.

    RBAC & enterprise SSO

    Admin / Read-Write / Read-Only roles, per-user scoping, and directory group→role mapping. Authenticate with SAML, OIDC, TACACS+ or RADIUS — each with a built-in test-connection.

    Reports — predefined & custom

    Executive summary, full compliance, version-impact KPI and audit trail out of the box — or build your own by section and severity. Export PDF / CSV / JSON, or email to stakeholders.

    Team dashboards

    Per-user, drag-to-arrange widgets with role-based views — NOC, Engineering and Management — switchable from a dropdown so every team sees the signal that matters to them.

    Encrypted credential vault

    Device credentials live in a passphrase-locked, in-memory vault — devices reference them by name, never inline. Nothing sensitive is written to disk or persisted in the browser.

    Lifecycle & system management

    Backup-before-upgrade with release notes, NTP, and encrypted backup to S3 / SFTP / NFS / Azure / GCS — each with test-connection. Export appliance telemetry to SolarWinds, PRTG or Prometheus, read-only.

    Non-intrusive collection

    Rate-limited, off-hours-aware config collection that never overloads a device or its control plane — with an immutable audit trail of who changed what, exportable for compliance.

    Standards mapping

    Every finding maps to a control.

    Hand the report to your auditors as-is. Four framework packs are scored from findings — and each says exactly which controls it covers, because a config cannot decide a procedural control.

    CISBenchmarks · pack
    NIST800-53 Rev 5 · pack
    PCI DSSv4.0 · pack
    DISASTIG · SRG families
    CISAZTMM 2.0 · zero trust
    NISTSP 800-207 · zero trust
    CISAKEV · exposure
    NVDCVE 2.0 · exposure
    Engagements

    Start with one audit. Grow into continuous assurance.

    From a one-time assessment to always-on, air-gapped deployment. Tell us about your network and we'll scope it with you.

    Spot assessment

    Send us your configs — we return a full, auditor-ready report with prioritized remediation. Nothing to deploy.

    Continuous assurance

    Scheduled re-audit, drift alerting and change-window intelligence across the whole fleet.

    On-prem / sovereign

    Air-gapped appliance inside your management VRF — no egress, no phone-home, FedRAMP-aligned.

    Where it stands

    Five product categories, one platform.

    Today a network security programme buys a config-compliance suite, a policy manager for the firewalls, a digital-twin for path analysis, a consultant for the zero-trust assessment and a spreadsheet to tie it together. Rakasec does the parts of each that can be decided from configuration — offline, on one appliance — and says plainly where the incumbents are still ahead.

    CapabilityRakasecConfig compliance suitesFirewall policy managersDigital-twin / path toolsZT assessment (consultant / questionnaire)
    Assess
    Hardening findings cited to the line, published false-positive rate 150 checks · 0% FP on a ground-truth corpus*partialrule hits; FP rate not publishedmanual
    Multi-vendor, offline, agentless — no device access needed 16 platforms + cloud/SASE posturefar more device typesfirewalls onlyneeds live access / snapshots
    Fleet CVE exposure from CISA KEV, NVD and vendor PSIRTs, paged when new 30-min refresh · KEV always pagessomesome
    Zero trust
    Lateral reachability measured per segment pair, from configs undetermined never called safeper-firewallnot across the campustheir strength; needs a twinself-reported
    Zero-trust readiness scored on fleet coverage against CISA ZTMM 2.0 / NIST 800-207 31 capabilities · two domains · roadmapsurveyopinion, not measurement
    One ranked risk register: gaps + exposures + permissive rules + hygiene + findingsfindings onlyrules onlypaths onlyslide deck
    Baseline compare — what moved since last quarter, and whyconfig diffrule diff
    Remediate
    Push with pre-flight simulation, four-eyes, post-push re-audit and automatic rollback never marks fixed on trustpush, no verifyrule pushfirewalls only
    Exact commands and rollback derived from the finding's evidence push on 11 platforms; manual runbook on the resttemplates
    Operate
    Scheduled collection at fleet scale, classified failures, pinned host keys auth never retried · TOFU pinningmaturefirewallsagents / API
    Alerting to PagerDuty / Opsgenie / Slack / Teams / ServiceNow / syslog with dedupe
    RBAC, SSO (OIDC/SAML), HA on PostgreSQL, audit trail of every action SSO not yet validated against a customer IdP
    Hundreds of device types, decades of field validation 16 platforms; validate yours in the ledgertheir home groundfirewalls
    Prove
    CIS · NIST 800-53 · PCI DSS · STIG packs scored from findings, honest about coverage says exactly which controls it coversstrongest suitfirewall rulesself-attested
    AI that explains — grounded to engine facts, every sentence cited engine decides, model narratesemergingemergingemerging
    Air-gapped by default, no LLM in the audit path, configs deleted after deliveryvariesvariesmostly SaaS

    What we will say

    • 0% false positives, 100% recall on our ground-truth corpus — reproducible with cogent validate.
    • Every finding cites the line, the control, and the blast radius.
    • Reachability is computed, and "undetermined" is reported as such, never as safe.
    • A fix is only "verified" after a re-pull shows the finding gone.
    • The zero-trust score is measured from configs, and the pillars it cannot measure stay unscored until you supply the input.

    What we won't

    • That a pack score means you're "compliant with CIS" — it covers what a config can decide.
    • That we support your platform until a real pull of it succeeded on your appliance — the ledger says which.
    • That an AI reviewed your network — the engine did; the AI only explains it.
    • That we replace a digital twin for live-state path analysis, or a firewall policy manager for rule lifecycle at scale.
    • That nobody can beat it.

    See what an auditor would — before they do.

    Tell us about your network and we'll scope an assessment with you. Start with a free audit of five devices — no cost, no obligation.

    View sample report
    Offline analysis · configs deleted after delivery · NDA available on request · or e-mail hello@rakasec.com